H
HidePDF
Redact PDFs in your browser. Nothing leaves your device.
100% local · fully local

Why a QR Code or Barcode Can Undo Your PDF Redaction

You can proofread text. You cannot proofread a QR code. When a document prints the same data twice — once for the reader and once for a scanner — covering the half you can read leaves the half you cannot.

PDF
Drop a PDF here, or click to choose
Your file never leaves your device.
Burning in redactions…
Preparing pages…

Most redaction failures described on this site are failures you could have caught by looking. The black box was a drawing sitting on top of live text you could still select. An OCR layer survived underneath the image. The metadata still named the author. Even the subtler ones — a figure recoverable from a visible total, a name implied by an unredacted job title and date — are things a careful human reading the page can reason about.

Machine-readable marks are different in kind, and that is why they deserve their own page. A QR code, a striped barcode, a stacked rectangular block, a dot-matrix square, a strip of tall and short postal bars: every one of these is printed data. It is on the page, in the open, at full contrast, and it is completely opaque to the person doing the redaction. You can stare at a QR code for an hour and learn nothing about what it says. So the usual method — read the page, decide what is sensitive, cover it — silently skips over the one region of the document that a recipient can read fastest.

The result is a specific and fairly common failure: the printed reference number is neatly blacked out, and eight centimetres away sits a symbol that encodes the same reference number, still perfectly scannable. Nothing went wrong with the redaction. The data was simply printed twice, and only one copy was in a form you could see.

Where these marks turn up, and what they tend to carry

Machine-readable marks are far more widespread in everyday paperwork than people expect, because they are added by the system that generated the document rather than by its author. Shipping and return labels, courier waybills, event tickets and boarding passes, appointment and test-result letters, invoices and utility bills with a scan-to-pay code, government and tax forms, court or agency filing stamps applied on receipt, scanned ID and licence cards, membership and loyalty cards, warehouse and records-management stickers, and the tracking codes some document systems stamp into a footer on every page.

What a given code contains varies by the system that produced it, so the honest instruction is to decode yours rather than assume. Broadly, though, they fall into two categories, and both matter.

Codes that carry the data directly. Some symbols hold the payload in plain form: a name, an address, a date of birth, an account or document number, a payment amount and destination account. The two-dimensional code on the back of many identity documents and the machine-readable zone on a passport page — those two monospaced lines full of chevrons — generally restate the identity details printed on the front. A scan-to-pay code on a bill commonly encodes the payee account and the amount. If you redact the printed version and leave the symbol, you have redacted nothing.

Codes that carry a handle. The larger category holds a reference: a URL, a tracking number, a case or envelope identifier, a customer number. It is tempting to treat these as harmless because the string itself looks meaningless. They often are not. A handle is dangerous exactly to the degree that the recipient can resolve it — a tracking number typed into a carrier site may return the delivery address; a per-document URL may open the original, unredacted file; a case reference may pull the full record for anyone with portal access. The question is never just "what does the code say" but "what does the code let this particular recipient look up".

A check to run before you export

  1. Inventory the marks first, on every page. Before drawing a single box, scan the pages visually for anything machine-readable: square QR-style codes, striped linear barcodes, stacked rectangular blocks, small dot-matrix squares, postal bar strips, and the chevron-filled monospaced lines of a machine-readable zone. Check headers, footers, margins, address windows, the reverse side of scanned forms, and remember that document systems often stamp a code onto every page rather than just the first.
  2. Decode each one and read it literally. A phone camera or any scanner app will show you the decoded string. Read what it actually says instead of inferring from where it sits. If the value is a web address, read the address rather than opening it — opening a per-document link may register a visit, and for a file you are handling carefully that is itself a disclosure.
  3. Ask the resolution question. For each code, decide whether it contains, or can be used to retrieve, anything you are covering elsewhere in the document. If the answer is yes or you cannot tell, cover it.
  4. Cover the whole symbol and its quiet zone. Draw the box over the entire code plus the blank margin around it, generously. Do not try to disable a code with a small mark across a corner or a stripe through the middle.
  5. Treat a machine-readable zone as text, because it is. Those chevron lines are readable by a person with a little patience and by software instantly. They get covered on the same basis as the printed fields they duplicate.
  6. Decide what the code was for before removing it. Sometimes the symbol is load-bearing — a ticket that must scan at a gate, a payment code the recipient needs, a filing stamp a clerk checks. Covering it may be correct, but it is a decision to make deliberately, and occasionally the right answer is to send a different document rather than a crippled one.
  7. Re-scan the finished file. Open your exported PDF and point a phone at each place a code used to be. If nothing decodes, you are done. This is the only check that actually proves the result, and it takes a few seconds.

Why partial covering does not work

The instinct to nick a corner off a code comes from thinking of it as a picture that stops making sense when damaged. It is closer to the opposite. Two-dimensional codes such as QR are built with error correction precisely so they survive real-world abuse — printed on a crumpled label, scuffed, rained on, or with a logo deliberately dropped into the middle. Depending on the correction level chosen when the code was generated, a meaningful share of the symbol can be missing and a scanner will still reconstruct the payload. A mark that looks destructive to you may be well within the code's designed tolerance.

Linear barcodes fail your expectations in a different way. Their information lives in the widths of the bars and spaces, not in the height; the height exists only so a scanner can find the symbol and sweep across it. Covering the top half of a barcode, or cropping it, typically leaves a fully readable code. Cutting vertically through the middle is more disruptive, but "more disruptive" is not a standard worth relying on when covering the whole thing costs the same effort.

Two related assumptions are worth retiring at the same time. The first is that blurring or pixelating a code is enough; degraded symbols are often still decodable, and the amount of degradation needed is not something you can eyeball. The second is that converting or re-rendering the document will quietly destroy the codes. It will not. HidePDF's export rebuilds each page as an image at a fixed higher resolution, which means codes come through sharp and scannable. That is the right behaviour for a redaction tool — it should not silently damage parts of your document — but it does mean the format change gives you nothing here.

What this tool does and does not do here

HidePDF draws manual boxes and nothing else. It does not read, search, parse, or interpret your PDF, and it contains no barcode or QR decoder, so it cannot find these marks for you, cannot tell you what they contain, and will not warn you that you left one uncovered. Every step above is a human step performed before you click download.

What the tool handles is the mechanical part. On export it rebuilds every page of the file as an image with your boxes burned into those images, so the covered pixels are genuinely gone rather than hidden beneath a shape that could be moved or deleted — which matters for a code just as much as for text, since a code sitting under a removable rectangle is simply a code. All of that processing happens inside your browser, on your own device, with no upload required. The trade-off of the image-based export is that the finished document is no longer selectable or searchable text anywhere, including the parts you kept, so decide in advance whether your recipient needs to search the file.

Common mistakes and misconceptions

"It's just a link to their website." Sometimes true, often not. Marketing codes and per-document codes look identical. Decoding takes a second and removes the guess entirely.

Redacting the printed number but not the symbol beside it. The most common version of this failure, and the reason inventorying the marks before you start matters more than catching them as you go.

Assuming a meaningless-looking string is harmless. Reference numbers are handles. Judge them by what the recipient can resolve them against, not by how they read.

Covering a corner of a QR code. Error correction is a design feature of the format. Cover the whole symbol.

Covering the top band of a striped barcode. The data is in the bar widths. Height is just a target for the scanner.

Checking only page one. Document management and filing systems frequently stamp a code into the footer of every page.

Ignoring the machine-readable zone on an ID scan. It is plain text that restates the fields you just covered, and it is trivially readable.

Trusting a copy-paste or text-search verification to catch it. Those checks are worth running for other reasons, but a barcode is graphics. It will pass every text-based test cleanly while remaining entirely readable to a scanner.

Related guides

Explore more ways to redact PDFs privately, or use the redaction tool above:

Frequently asked questions

Can a QR code or barcode really give away something I blacked out elsewhere on the page?

Yes, and it is one of the easier leaks to miss, because you cannot read a code by eye. Many documents print the same data twice: once as human-readable text and once as a machine-readable symbol placed in a margin, header, or address block. Shipping labels, tickets, appointment letters, scanned ID cards, payment slips, and filing stamps are common examples. If you cover the printed reference number but leave the symbol that encodes it, anyone can point a phone at the page and read it back in a second. A code also does not have to contain the secret directly to cause harm: a code holding a URL, an envelope ID, a tracking number, or a case reference is a lookup handle, and if the recipient can resolve it against a system they have access to, it retrieves what you were trying to withhold.

If I black out part of the code, is that enough?

Usually not, and you should not rely on it. Two-dimensional codes such as QR are designed with error correction so they still scan when partly dirty, creased, torn, or covered by a logo, and depending on the correction level chosen when the code was generated, a meaningful portion of the symbol can be missing and it will still decode. Linear striped barcodes fail differently but just as unhelpfully: the information sits in the widths of the bars, not their height, so covering the top or bottom band of a barcode typically leaves it perfectly readable. The reliable approach is to cover the entire symbol plus the blank quiet zone around it, rather than trying to break a code with a small mark. Then confirm by trying to scan the exported file.

How do I check what a code on my document actually contains?

Decode it and read the result as text. Most phone cameras and scanner apps will show you the decoded string, and reading it literally is the whole point, because guessing from context is how people conclude a code is just a link to the company website when it is not. If the decoded value is a web address, read the address itself rather than opening it, since opening it may register a visit and, for a per-document link, may signal that the file has been handled. If a code will not decode from the screen, zoom in and try again before assuming it is unreadable. Worth remembering too that the two chevron-filled monospaced lines at the bottom of a passport or ID page are machine-readable data in plain text form, and they usually restate the name, document number, and dates printed above them.

Does HidePDF find or decode barcodes for me?

No. HidePDF does not read, search, parse, or interpret the contents of your PDF, and it has no barcode or QR decoder of any kind. You draw the boxes yourself, by hand, over whatever you decide needs covering, and the tool covers exactly that region and nothing more. Finding the codes and deciding what to do about them is entirely a human step. What the tool does handle is permanence: on download it rebuilds every page as an image with your boxes burned in, so the covered pixels are genuinely gone rather than hidden under a shape that can be moved or deleted. All of that happens in your browser, with no upload required. Note that the export is rendered at a fixed higher resolution, so any code you leave uncovered will stay crisp and scannable — the format change is not a substitute for covering it.