H
HidePDF
Redact PDFs in your browser. Nothing leaves your device.
100% local · fully local

Keeping the Redacted and Unredacted Versions of a PDF Straight

Redacting does not replace a document. It creates a second one that looks almost exactly like the first, lives in the same folder, and sorts next to it in every list you will ever pick from. A perfect redaction still discloses everything if the wrong file gets attached.

PDF
Drop a PDF here, or click to choose
Your file never leaves your device.
Burning in redactions…
Preparing pages…

Almost every guide on this site asks a question about one file. Is the text really gone under the black box. Can OCR pull it back. Does the metadata name you. Will the covering survive being emailed, printed, flattened, or opened by a screen reader. Every one of those is a question about whether the redaction worked.

This page is about what happens when the redaction worked perfectly and the disclosure happens anyway, because the file that went out was the other one. That failure has nothing to do with black boxes or text layers. It is a filing and handling problem, and it is the reason a lot of redaction incidents happen to people who did the redaction competently.

The moment you export a redacted copy you own a pair: an original that must not leave, and a derivative that must. From that point on the two documents are in competition for every "choose a file" dialog you open. They have the same page count, the same page dimensions, nearly the same name, and thumbnails that differ only by a few small black rectangles that are invisible at thumbnail size. Nothing about the way computers present files makes this pair easy to tell apart. Almost everything about it makes them easy to confuse.

Why the pair is so easy to mix up

The names differ at the end. Conventional suffixes — -redacted, _clean, -public — are appended, and the end of a file name is exactly the part that gets truncated in a narrow column, an attachment chip, a mobile file picker, or a dropdown. Two names that differ only after thirty characters of shared prefix can render identically in the one place where you are actually making the choice.

They sort adjacently. A shared prefix means the two files land next to each other in alphabetical order, so the wrong one is always one row away from the right one. Sort by date modified instead and they are still adjacent, because you made them minutes apart.

The thumbnails look the same. A redaction usually covers a small fraction of a page. At preview size, a name blacked out on page four is a few dark pixels. Cover-page thumbnails are frequently identical between the two versions, because you rarely redact the cover page.

Page count and dimensions match. A well-behaved redaction does not change the shape of the document, and that is a feature — but it removes the most obvious at-a-glance discriminator. You cannot glance at "12 pages" and know which file you have.

File size does not tell you. People reach for size as a tiebreak and it is not dependable. Redaction can make a file larger or smaller depending on what the tool does to the page content, so a size difference tells you the files are different and nothing about which is which.

Recent-files lists erase the distinction entirely. "Recent documents", the attach menu's recents, and the operating system's jump lists show a short truncated name and no folder context. This is where wrong-version attachments overwhelmingly come from, because it is the fastest path and the fastest path is what people use when they are finishing an email at the end of the day.

A handling protocol for the pair

  1. Decide up front which copy leaves. Before you draw a single box, be explicit with yourself: this original stays, that export goes. Making the decision consciously once is worth more than checking carefully five times later.
  2. Separate by location, not by name. Put the outbound copy in its own folder — an "outbound", "for release", or "produced" folder — rather than leaving both versions side by side with different suffixes. Location is a much stronger signal than a suffix, because it survives truncation and it changes the path you take to reach the file.
  3. Rename the copy that leaves, and rename it at the front. If you use a marker, put it where it cannot be cut off: RELEASE-schedule-b.pdf rather than schedule-b-release.pdf. Name the outbound copy for the recipient, not for your own filing habits.
  4. Never attach from a recents list. Navigate to the outbound folder every time. The extra four seconds is the control.
  5. Open the file you are about to send, from the place you are sending it. Not a copy of it, not the one still open in another tab — the actual attachment. Page through it and confirm the redactions are visibly there.
  6. Check the attachment once more in the compose window. Click the attachment and look at it in the preview, after it has been attached and before you send. Many wrong-file incidents are caught here by people who made a habit of it.
  7. Keep the original, and restrict it. Do not delete it; you may need it to justify a redaction, to produce a less-redacted version to a different party, or to redo the job. Move it somewhere the outbound path never touches, and narrow who can open it.
  8. In a shared drive, never overwrite the original with the redacted copy. Uploading the redacted file over the top of the original keeps the original retrievable through version history for anyone with access. Upload the redacted copy as a new file in a different location instead.
  9. Record which version went where. A short note of the date, the recipient, and which copy they received turns "did they get the redacted one?" from a memory test into a lookup, and it is what you will want if the question is ever asked in earnest.
  10. Always re-redact from the original. If a reviewer finds a missed item, go back to the unredacted source and produce a fresh export. Working forward from the redacted copy means you are editing a document whose content is already destroyed, and you will produce an inconsistent pair.

Where the tool on this page fits

Three specifics are worth knowing if you use HidePDF to produce the outbound copy.

First, the download name is built from the file you opened, with -redacted appended — feed it board-minutes-march.pdf and you get board-minutes-march-redacted.pdf. That is the near-identical-name situation by default, and it arrives in your downloads folder rather than anywhere you have organised. Moving and renaming it before you do anything else is the highest-value habit on this page.

Second, the export deliberately preserves structure: one output page per input page, at the original page dimensions. So page count and page size will never help you tell the pair apart. That is the right trade — a redaction that silently changed the pagination of a document would cause worse problems — but it means you need a different discriminator.

Third, there are two discriminators that do work. The export rebuilds every page as an image, so the finished file has no selectable or searchable text anywhere in it: if you can drag-select a line of text, you are looking at the original. And the export writes a generic internal document title of "Redacted Document", with the producer and creator both set to "HidePDF", so the document properties panel gives you an unambiguous answer in two clicks. Either check is faster and more reliable than squinting at a file name.

All of this runs locally in your browser tab, with no upload required, which is worth noting for the protocol above: producing the outbound copy does not put the unredacted original through anything, so the only copies that exist are the ones on your own machine and the ones you deliberately hand over.

Common mistakes and misconceptions

Deleting the original to remove the risk. It removes the ability to answer questions about your own redaction, and it rarely removes the file — trash folders, sync histories and backups keep it around, so you lose the usefulness without gaining the certainty.

Overwriting the original in place. Replacing a file in a shared drive with its redacted version feels like the tidiest possible fix and is one of the most reliable ways to leave the unredacted content available to everyone who can reach the file's history.

Trusting the preview thumbnail. Thumbnails render the first page, and the first page is usually the one you did not redact.

Using "final" as the marker. Every document acquires a final, then a final-v2, then a FINAL-actual. The word marks how you felt about the file, not what is in it. Mark the audience instead.

Letting someone else pick the file. If you ask a colleague to "send them the redacted one", they are choosing between two nearly identical names in a folder they did not organise, without knowing what was redacted or why. Hand them a single file, or a folder that contains only the file you want sent.

Counting on unsend. Recall and undo-send features work within a short window and only before the message has actually been delivered or read; across organisations they generally do nothing at all. Treat the send button as final and do the checking before it.

Sending a zip or a folder link instead of a file. A shared folder link grants access to whatever is in the folder now and whatever lands in it later. If the unredacted original is ever filed there by anyone, the link you already sent covers it.

Assuming the pair only exists once. Each round of review usually produces another export. Three rounds means four documents with confusingly similar names, and the risk goes up with every one. Delete superseded exports as you go so the outbound folder holds exactly one candidate.

Related guides

Explore more ways to redact PDFs privately, or use the redaction tool above:

Frequently asked questions

Should I just delete the original once I have a redacted copy?

Usually not, and deleting is a worse answer than it looks. You frequently need the original later: to answer a challenge about whether a redaction was justified, to produce a fuller version to a party entitled to more, to re-do the redaction when someone points out a page you missed, or to prove what the document said before you touched it. Redacting from an already-redacted copy is not possible in any useful sense, because the covered content is gone. Deletion also tends to be incomplete — a file removed from a synced folder often survives in a trash folder, a version history, a backup, or on a colleague's machine, so you get the loss without the certainty. The better move is separation and access control: keep the original, put it somewhere the outbound copy is never picked from, and restrict who can open it.

How can I tell quickly which of two similar PDFs is the redacted one?

Do not rely on the file name, the thumbnail, or the file size — none of them are reliable. With a HidePDF export there are two quick checks that are. First, try to select text on any page: the exported file rebuilds every page as an image, so there is no selectable or searchable text anywhere in it. If your cursor selects a line of text, you are looking at the original. Second, open the document properties: the export sets the internal document title to "Redacted Document" and the producer and creator to "HidePDF", which the original will not say. Page count and page size are deliberately preserved, so those tell you nothing. If the redacted copy came from some other tool, the text-selection test may not apply, and the honest answer is to open the file and look at the pages you redacted.

Is renaming the file enough to keep the two versions apart?

It helps, but on its own it is the weakest control of the set, because a suffix sits at the end of the name — exactly where narrow file lists, attachment chips and email clients truncate. Two files called contract-schedule-b-2026-confidential.pdf and contract-schedule-b-2026-confidential-redacted.pdf can display identically in the place where you actually choose between them. Separation by location is stronger than separation by name: put the outbound copy in its own folder and attach only from there. If you do rename, rename the copy that leaves rather than the one that stays, and put the distinguishing word at the front of the name where it cannot be cut off.

Does HidePDF keep the two versions separate for me?

No, and it could not — everything happens locally in your browser tab, with no upload required, so the tool never has any view of your folders or your outgoing mail. What it does do is produce a download named after the file you opened with "-redacted" appended, so a file called board-minutes-march.pdf comes back as board-minutes-march-redacted.pdf. That naming is convenient but it is the near-identical-name situation by default, and it lands in your downloads folder next to whatever else is there. Moving the export to a dedicated outbound folder, and giving it a name written for the recipient rather than for you, takes a few seconds and is the step that actually prevents the mix-up.