BlurThis

Processed in your browser · never sent to our servers

Blur text in a screenshot (passwords, account numbers, keys)

Cover a password, API key, account number, bank detail, one-time code, or card number with a black bar in your browser, then download a PNG. The file never leaves this tab.

Use a black bar, not a blur. Short strings survive a smear. There is no account and no watermark on the export.

Drop a screenshot or photo here

Choose a screenshot or photo that shows a password, account number, or key. Editing stays in this browser tab. Nothing is sent to BlurThis.

How to hide sensitive text in three steps

  1. 1

    Add the screenshot or photo

    Drop the file onto this page, tap to choose it from your phone or computer, or paste it with Ctrl / Cmd + V. There is no upload step: the file opens in this browser tab and is never sent to BlurThis servers.

  2. 2

    Select black bar (not blur)

    Pick Black bar, then Box for a rectangle or Draw for an irregular shape. Short strings survive a smear: passwords, recovery codes, API keys, IBANs, card digits, and one-time codes. Blur keeps the original pixels in a degraded form. A black bar replaces them with flat colour.

  3. 3

    Drag over the secret, then download PNG

    Click and drag across the password, key, account number, or other private text. Add a little padding so no character peeks out. Tap Download PNG and share that new file instead of the original.

I could still read a blurred six-digit code

I typed a fake OTP into a notes app, screenshotted it, and tried a moderate blur. At 100% zoom I could still name four of the six digits from the leftover shapes. A black bar on the same region left a flat slab. That is why this page starts you on the bar, not a smear.

Pixelate at a large tile size is a middle option if a solid rectangle looks too harsh in a ticket. It is still weaker than a bar. Do not use a light blur on passwords, keys, IBANs, or card digits.

Why blur fails on short secrets

A face can survive a smear because you only need “not identifiable at a glance.” A password cannot. The original pixels are still in the file, just spread. With a known font, a small alphabet, and a string that is six to nineteen characters long, that leftover shape is often enough.

Number plates have the same physics, which is why the plate tool tells you to pixelate rather than blur. Passwords, keys, and account numbers are the same class of object: high contrast, even spacing, short enough to brute-force by eye. A black bar replaces the pixels with flat colour. Nothing is left to recover.

Crop is better still when the secret sits in a corner. Pixels that are no longer in the file cannot be guessed back. Paint over what you must keep in frame; cut off what you do not.

What usually needs covering

  • Passwords and recovery codes, including the line a password manager or “show password” eye left visible.
  • API keys, personal access tokens, session cookies, and .env values in a terminal, editor, or browser query string.
  • IBANs, account numbers, routing numbers, and the balance on a banking screen.
  • Card PAN, expiry, CVV, and the last four when they sit next to a name or address.
  • One-time codes from SMS, WhatsApp, or an authenticator app. They expire, but they are short enough that a light blur does not hide them.
  • Salary figures, tax IDs, and employee or customer account numbers in a spreadsheet snip.

Phone numbers and email addresses belong on the same list when the screenshot is going to anyone who should not have them. The phone and email guide covers that case.

Bug reports and bank support

Two situations produce most of the leaks, and they look like “being helpful.”

A bug report wants the error. It does not need the token in the URL, the customer hostname in the stack, or the Authorization header in the dumped request. Cover those, then attach the export. The walkthrough is hide an API key before you file a bug.

Bank support wants the error code or the failed transfer. It does not need a full IBAN sitting next to your name, or a notification banner that repeated the amount. Cover the numbers, leave the error readable. See hiding a card number or banking screenshot.

OTPs are a third trap: people screenshot a WhatsApp or SMS code to send it to themselves, then the photo sits in Recents. Do not screenshot the code if you can avoid it. If the shot already exists, black-bar it before it leaves the device.

Check the export before you send it

Open the downloaded PNG at full size. A box that covered the text in a small preview can leave a character sticking out at full resolution, and a blur that looked heavy on a phone can read clearly on a monitor.

Then confirm you are attaching the export, not the original at the top of Recents. Sending the wrong file is a more common failure than a weak cover.

For redacting a screenshot in general, use the screenshot tool. For a face, use blur a face. For a licence plate, stay on the number plate page.

Hiding passwords and account numbers: common questions

Is this free, and does the file get uploaded?
Free, with no account and no watermark. The image is decoded and painted on a canvas inside this browser tab, then downloaded from the same tab. Nothing is sent to BlurThis servers.
Should I blur or use a black bar on digits and passwords?
Black bar. A password, OTP, IBAN, or card number is a short high-contrast string from a small alphabet. A moderate blur leaves enough of each character’s shape that a person, or software, can guess the rest. A black bar leaves nothing to recover. Pixelate is a middle option if you need the region to look less harsh, but it is still weaker than a solid bar. Why a bar beats a smear for characters.
Does Find text catch every password and account number?
No. Find text is a suggestion, not a guarantee. It misses rotated text, faint grey labels, terminal scrollback, and anything the OCR skips. After you apply a suggestion, zoom in and look for the rest: a second account field, a routing number, a CVV, a recovery code on the line below.
What about a banking-app screenshot?
Cover the balance, the full account or IBAN, the last four if they sit next to a name, and any notification banner that repeated the amount. Do not send the original from Recents. The banking guide walks through the typical layout. Cover a banking-app screenshot.
How do I hide an API key in a terminal or bug-report shot?
Black-bar the token, the surrounding query string, and any .env line that is still on screen. Bug reports often include more than the one key you noticed: a second secret in the stack trace, a hostname that names the customer, a cookie in the request dump. Hide an API key before you file a bug.

Guides for specific secrets