H
HidePDF
Redact PDFs in your browser. Nothing leaves your device.
100% local · fully local

Can Sensitive Data Hide in PDF Comments, Bookmarks, or Attachments?

The page is not the whole file. Sticky notes, review comments, bookmark titles, embedded spreadsheets, and file attachments live in PDF structures most people never open. A perfect blackout on the body text leaves a comment thread that still names the client.

PDF
Drop a PDF here, or click to choose
Your file never leaves your device.
Burning in redactions…
Preparing pages…

PDF is a container format, not a single picture. Page content streams are one layer. Annotation dictionaries hold comments, highlights, stamps, and redaction marks that failed to remove text. The outline tree powers bookmarks. Embedded files (/EmbeddedFiles name tree) can carry Excel budgets, email .eml exports, or source Word docs. Redacting visible paragraphs while leaving those structures intact is a partial job.

Metadata-plus-text awareness is redact PDF metadata and text together. Verification habit: how to verify a PDF is redacted. This page is the non-page surface area.

Comments and annotations

Review workflows accumulate sticky notes with attorney-client strings, suggested edits with SSNs, or highlight anchors pointing at confidential rows. Export to PDF often includes them. Some viewers hide annotations by default — recipients who enable comments see everything. Flattening annotations into the page without removing content can bake notes into the image; deleting annotations without burning page text leaves live text. You need both page burn-in and annotation hygiene.

Bookmarks (document outline)

Bookmarks are not metadata fluff — they are user-visible navigation labels stored as structured text. ‘Exhibit B — Smith Settlement 482,000’ in the outline survives black boxes on page images if nobody cleared /Outlines. Clear or rewrite outlines in a sanitizer when titles carry secrets.

Embedded file attachments

PDF allows attaching arbitrary files — the report PDF might include the raw .xlsx source as an attachment icon on page one or invisible in the structure tree. Opening attachments bypasses every redaction rectangle on page pixels. Remove embedded files or rebuild PDF without the name tree entry.

A complete redaction pass

  1. Burn in visible secrets with HidePDF boxes on every page.
  2. Search and paste-test the download.
  3. In Acrobat, Foxit, or a CLI sanitizer: remove comments, JavaScript, embedded files, hidden layers — per org checklist.
  4. Clear or genericize bookmark titles.
  5. Inspect Document Properties for Author, Title, Custom XMP — see metadata guide.
  6. Re-verify the final artifact.

Scenarios

Law firm production PDF with paralegal comments. Comments name witnesses not redacted on pages.

Financial PDF exported from Excel with source workbook attached. Attachment has unredacted tabs.

Training manual with bookmark per client codename. Outline leaks client list.

JavaScript and hidden layers

Some PDFs ship with document-level JavaScript — auto-open actions, form calculations referencing hidden fields. Redacting visible table rows while a script still reads hidden field values fails compliance reviews. Sanitization profiles often include ‘remove JavaScript’ alongside annotation removal.

Optional content groups (layers) can hide a ‘Attorney Eyes Only’ layer that recipients enable in Acrobat. Flatten layers or remove optional content in preflight before publishing a redacted copy.

Checklist before external share

Open Comments pane — resolve or delete all. Open Attachments panel — remove embedded files. Open Bookmarks — genericize titles. Document Properties — clear Author/Title/Subject if sensitive. Run HidePDF burn-in on body content. Search final PDF. Paste test. Only then attach.

Why page-only redaction fails eDiscovery

Load files and productions include linked objects beyond page content. A privilege log might reference bookmark titles you forgot. Attachment icons on page one signal ‘there is more in this PDF’ — opposing counsel requests the embedded xlsx. Production hygiene treats PDF as a bundle, not a picture.

HidePDF’s burn-in addresses page pixels recipients see in the main reading view. Pair it with sanitizer steps for everything else in the PDF envelope — same way you strip email thread headers when the body looks clean. Comments and attachments are the thread headers of PDF.

Redaction vendors publish sanitizer profiles — use them after HidePDF burn-in when your industry requires a named checklist (legal, healthcare, finance). HidePDF covers the visible page; sanitizer covers the envelope.

Related guides

See also:

Frequently asked questions

Will HidePDF remove comments I don't see on the page?

HidePDF burns boxes into page raster images. It does not automatically delete annotation objects, bookmarks, or embedded attachments elsewhere in the PDF structure. Inspect and remove those in a full PDF sanitizer or editor before sharing, or confirm your export pipeline strips them.

How do I find hidden comments?

Open the PDF in a desktop reader’s comments pane, or use a preflight/sanitize tool that lists annotations. Some ‘hidden’ comments are off-page or collapsed.

Can bookmark labels leak names?

Yes. Outlines (/Outlines) store visible titles in the navigation tree — chapter names, client codenames, exhibit labels.

Does HidePDF send the PDF to scan for attachments?

No. Local processing in this tab only.