You've got a document that needs to be shared — but it contains sensitive information. A client's name, a bank account number, a patient's date of birth. The instinct is to cover it with a black box in whatever editor is open and call it done. That instinct is the single most common redaction mistake there is, and it's worth understanding exactly why before you send anything out.
Redaction vs. simply covering text
- Covering (overlay): A black shape is drawn on top of the text in a PDF editor. Visually it looks gone — but the text object itself is still sitting in the file underneath, at its original coordinates. Select-all, copy-paste, or a basic text extraction script can pull it straight out from under the box.
- Real redaction: The underlying content is actually deleted — not hidden, not covered, gone from the file's data. There is nothing left to select, search, or extract.
This isn't a theoretical distinction. It's the reason "redacted" documents have made the news more than once — court filings, government reports, and leaked case files where someone drew a box, saved the PDF, and moved on, not realizing the sentence underneath was still fully intact and extractable.
Everywhere sensitive content can hide in a PDF
Visible body text is only one place information lives in a PDF. A thorough redaction pass has to consider all of the following:
- Hidden or off-page text: Layers, invisible text boxes, or content positioned outside the visible page area can still be present and extractable.
- OCR text layers: A scanned document that's been through OCR often has an invisible, searchable text layer sitting behind the image of the page. Blacking out the image doesn't touch that hidden text layer underneath — it can still be selected and copied even though the box looks solid.
- Annotations and comments: Sticky notes, highlights, and comment threads can contain the exact information you're trying to remove from the body of the document, and are easy to forget about.
- Document metadata: Author name, company name, and other properties set in the file's metadata (Title, Author, Subject, Keywords) are separate from the page content entirely — redacting what's on the page does nothing to metadata. Use a dedicated metadata editor to check and clear it separately.
- Embedded files and attachments: Some PDFs carry attached files or embedded objects that a visual review of the pages won't surface at all.
How PDFly's Redact PDF tool actually removes content
PDFly's Redact PDF tool works by rendering: you draw a box over each piece of sensitive content, on every page it appears. When you apply the redactions, the tool converts each page into a flattened image with the boxes baked directly into the pixels, then rebuilds an entirely new PDF from those images. The original text objects, any hidden OCR layer, and the source page data are not carried into the new file at all — there's no text layer left underneath to copy or extract, because the output pages are images, not text.
The trade-off is exactly what you'd expect: because the output pages are images, the redacted PDF is no longer text-searchable or selectable anywhere, not just in the redacted areas. That's the mechanism that guarantees the content is actually gone rather than a limitation to work around.
How to redact a PDF
- Open PDFly's Redact PDF tool.
- Upload your PDF.
- Click and drag on the page to draw a black box over each area you want to redact — repeat on every page it appears.
- Apply the redactions. The tool flattens each page to an image with the boxes permanently baked in.
- Before sending it anywhere, verify the result (see below), then download the redacted PDF.
How to verify a redaction actually worked
Don't take any redaction tool's word for it — including this one. Before you share a redacted PDF:
- Try to select text over and around the redacted areas. If nothing highlights anywhere in the document, the flattening worked as expected.
- Search the document (Ctrl/Cmd+F in your PDF reader) for the specific words you redacted. A real redaction returns zero results, because there's no text to find.
- Check the document's metadata separately — redacting page content does not touch Title, Author, or other metadata fields.
- Check for comments or attachments in your PDF reader's sidebar, since these live outside the page content that got flattened.
Common redaction mistakes
- Drawing a box in a general PDF editor and saving: without flattening, the underlying text is still there.
- Missing an occurrence: the same sensitive detail (a name, an account number) often appears more than once across a document — a header, a footer, a signature block. Every occurrence needs its own box.
- Forgetting metadata: redacting the visible page content while the document's Author or Company field still names the sensitive party.
- Skipping verification: sending the file without checking whether it's actually searchable or selectable where it shouldn't be.
- Redacting a copy that isn't the one you send: keeping the redacted file and the original in similarly named files invites sending the wrong one.
When to redact — and limitations to keep in mind
Redaction is appropriate whenever a document needs to be shared more broadly than the sensitive details inside it should be — legal filings with client or case details, financial statements with account numbers, records containing personal information, or internal documents before external distribution.
Keep the limitations in mind too: PDFly's tool is manual — you decide what to redact, it doesn't automatically detect names, account numbers, or other sensitive data for you, so a careful read-through of every page is still your responsibility. And redaction on this tool is one-way — once you've downloaded the flattened result, the black-boxed content cannot be recovered from that file, so always keep the unredacted original somewhere safe until you're sure the redacted version is correct. For documents involved in litigation, regulatory filings, or other formal compliance processes, treat this tool as a practical way to remove content — not as a substitute for legal review of what needs to be redacted and how.
Need to remove sensitive information from a PDF?
Redact your PDF in seconds — no uploads, no signup.
Open Redact PDF ToolFrequently Asked Questions
Can redacted text be recovered from the file PDFly produces?
No. The tool flattens every page to an image before applying the redaction boxes, so there's no text layer left in the output file to select, search, or extract. Always keep your original file safe, since the flattened result can't be reversed.
Does redacting a PDF also clear its metadata?
No — redacting page content and clearing metadata are separate steps. Check the document's Title, Author, and other properties with a metadata editor if that information also needs to be removed.
Will my redacted PDF still be searchable?
No, and that's intentional. Because every page becomes an image, the whole document loses text search and selection — not just the redacted areas. That's what guarantees nothing was left recoverable underneath.
Does this tool automatically find sensitive information for me?
No — redaction here is manual. You draw a box over each piece of sensitive content yourself; the tool doesn't scan for names, account numbers, or other data automatically. A careful page-by-page read-through is still necessary.