Processed in your browser · never sent to our servers
Blur text in a screenshot (passwords, account numbers, keys)
Cover a password, API key, account number, bank detail, one-time code, or card number with a black bar in your browser, then download a PNG. The file never leaves this tab.
Use a black bar, not a blur. Short strings survive a smear. There is no account and no watermark on the export.
Drop a screenshot or photo here
Choose a screenshot or photo that shows a password, account number, or key. Editing stays in this browser tab. Nothing is sent to BlurThis.
How to hide sensitive text in three steps
- 1
Add the screenshot or photo
Drop the file onto this page, tap to choose it from your phone or computer, or paste it with Ctrl / Cmd + V. There is no upload step: the file opens in this browser tab and is never sent to BlurThis servers.
- 2
Select black bar (not blur)
Pick Black bar, then Box for a rectangle or Draw for an irregular shape. Short strings survive a smear: passwords, recovery codes, API keys, IBANs, card digits, and one-time codes. Blur keeps the original pixels in a degraded form. A black bar replaces them with flat colour.
- 3
Drag over the secret, then download PNG
Click and drag across the password, key, account number, or other private text. Add a little padding so no character peeks out. Tap Download PNG and share that new file instead of the original.
I could still read a blurred six-digit code
I typed a fake OTP into a notes app, screenshotted it, and tried a moderate blur. At 100% zoom I could still name four of the six digits from the leftover shapes. A black bar on the same region left a flat slab. That is why this page starts you on the bar, not a smear.
Pixelate at a large tile size is a middle option if a solid rectangle looks too harsh in a ticket. It is still weaker than a bar. Do not use a light blur on passwords, keys, IBANs, or card digits.
Why blur fails on short secrets
A face can survive a smear because you only need “not identifiable at a glance.” A password cannot. The original pixels are still in the file, just spread. With a known font, a small alphabet, and a string that is six to nineteen characters long, that leftover shape is often enough.
Number plates have the same physics, which is why the plate tool tells you to pixelate rather than blur. Passwords, keys, and account numbers are the same class of object: high contrast, even spacing, short enough to brute-force by eye. A black bar replaces the pixels with flat colour. Nothing is left to recover.
Crop is better still when the secret sits in a corner. Pixels that are no longer in the file cannot be guessed back. Paint over what you must keep in frame; cut off what you do not.
What usually needs covering
- Passwords and recovery codes, including the line a password manager or “show password” eye left visible.
- API keys, personal access tokens, session cookies, and
.envvalues in a terminal, editor, or browser query string. - IBANs, account numbers, routing numbers, and the balance on a banking screen.
- Card PAN, expiry, CVV, and the last four when they sit next to a name or address.
- One-time codes from SMS, WhatsApp, or an authenticator app. They expire, but they are short enough that a light blur does not hide them.
- Salary figures, tax IDs, and employee or customer account numbers in a spreadsheet snip.
Phone numbers and email addresses belong on the same list when the screenshot is going to anyone who should not have them. The phone and email guide covers that case.
Bug reports and bank support
Two situations produce most of the leaks, and they look like “being helpful.”
A bug report wants the error. It does not need the token in the URL, the customer hostname in the stack, or the Authorization header in the dumped request. Cover those, then attach the export. The walkthrough is hide an API key before you file a bug.
Bank support wants the error code or the failed transfer. It does not need a full IBAN sitting next to your name, or a notification banner that repeated the amount. Cover the numbers, leave the error readable. See hiding a card number or banking screenshot.
OTPs are a third trap: people screenshot a WhatsApp or SMS code to send it to themselves, then the photo sits in Recents. Do not screenshot the code if you can avoid it. If the shot already exists, black-bar it before it leaves the device.
Check the export before you send it
Open the downloaded PNG at full size. A box that covered the text in a small preview can leave a character sticking out at full resolution, and a blur that looked heavy on a phone can read clearly on a monitor.
Then confirm you are attaching the export, not the original at the top of Recents. Sending the wrong file is a more common failure than a weak cover.
For redacting a screenshot in general, use the screenshot tool. For a face, use blur a face. For a licence plate, stay on the number plate page.
Hiding passwords and account numbers: common questions
Is this free, and does the file get uploaded?
Should I blur or use a black bar on digits and passwords?
Does Find text catch every password and account number?
What about a banking-app screenshot?
How do I hide an API key in a terminal or bug-report shot?
Guides for specific secrets
- Hide credit card numbers on a screenshot (safe, on-device)Cover the PAN, expiry, and name on a card photo, banking app, or checkout screen without uploading. A light blur is the wrong tool for digits.
- Hide a phone number or email in a screenshotCover a phone number or email before you send a screenshot. Black bar is safer than a light blur.
- Hide API keys and .env in screenshots before a bug reportBlack-bar API keys, tokens, and .env lines before you attach a bug-report screenshot. Rotate anything that was on screen.
- Don’t screenshot the WhatsApp codeHijackers ask contacts to read a six-digit SMS. A screenshot of that code is the whole attack.
