Permanent Redaction

Remove selected visible regions by rebuilding supported pages as verified image-only output.

Local processing boundary

Current workflows process document bytes in this browser. AO-PDF records only the selected tool, outcome, duration, and coarse browser/runtime information—never filenames or document-derived data.

Selected source bytes remain separate and unchanged. Generated outputs are new files. Session history stores operation metadata only in this browser tab and never stores source filenames, document text, or hashes.

This release supports Chromium on desktop and mobile. Firefox and Safari/WebKit are unverified and unsupported.

Operating limits

1–1 file; 100 MiB per file; 250 MiB aggregate; 50 pages; 1,024 MiB estimated working-memory limit; 120-second timeout.

  • Supported inputs are reconstructed as image-only pages at 144 DPI before redaction rectangles are burned into the pixels.
  • Annotations, attachments, forms, JavaScript, incremental revisions, encryption, and malformed PDFs are rejected.
  • The output loses selectable text, accessibility structure, links, forms, signatures, attachments, and metadata.

Select files to begin.

Session-local workspace history

Metadata only; cleared when this browser tab session ends.

No completed operations in this tab session.