Find and hide sensitive information before you share a screenshot. Automatically find emails, phone numbers, IP addresses, URLs and other potentially sensitive information, then blur or hide them with one click — before posting to LinkedIn, Reddit, a support ticket, GitHub or anywhere else.
100% browser-based processing. Your screenshot stays on your device. We don't upload or store your image — detection and redaction both run locally in your browser.
Your screenshot is processed directly in your browser using on-device text recognition (OCR). It isn't uploaded to our server for normal use. The tool looks for common patterns such as email addresses, phone numbers, IP addresses, URLs and possible secrets, then draws a box around each one it finds. You decide what gets hidden — nothing is redacted automatically without your say-so. The protected image is generated on your device and only leaves your browser when you choose to download it.
Your screenshot never leaves your device during scanning, redaction or export. Only the OCR library itself is fetched from a CDN — never your image.
Every detection is a suggestion, not an automatic action. Review each one, choose what to redact, and apply it yourself.
Automatic detection will never catch every possible label or wording. Turn on "Click Text to Redact" and hide anything the tool read — flagged or not — with a single click, or draw your own box over a logo or photo.
Exporting re-encodes the image, which strips EXIF data like GPS location and camera information automatically.
Can be used for spam, targeted phishing, or to identify you or a colleague.
May reveal internal network information, even for private ranges like 192.168.x.x.
Could allow unauthorised access to a system or service if the key is still active.
May reveal information about an organisation's infrastructure and naming conventions.
Tenant, application and object identifiers may expose organisational details.
May contain sensitive paths, access tokens, or point to internal-only systems.
Can reveal exactly where a photo was taken, even if the image itself shows nothing sensitive.
Screenshots of tax returns, HR systems or ID documents often contain a full name, National Insurance number or UTR next to a "Name:" or "NI No:" label — exactly the kind of information worth double-checking before you share.
Salman IT Tools is an IT-focused site, so Screenshot Privacy includes an optional IT Mode. When enabled, it prioritises and more aggressively looks for the kind of information IT engineers accidentally leave in screenshots: internal hostnames, UNC paths, DOMAIN\username strings, PowerShell lines containing secrets, database connection strings, JWTs, and possible Microsoft 365 / Entra tenant, application and object identifiers. It's off by default because some of these checks are more prone to false positives outside an IT context.
No. Your screenshot is loaded and analysed entirely inside your own browser using on-device OCR and pattern detection. It is never uploaded to Salman IT Tools' servers for normal use. The only network request made is to fetch the OCR library itself from a CDN the first time you scan — your image is never part of that request.
Yes. The tool automatically detects email addresses using on-device text recognition and lets you blur, pixelate or solidly cover them with one click, or draw your own manual redaction box over any area.
Yes, both IPv4 and (where practical) IPv6 addresses are detected, including private/internal ranges, since these can still reveal information about a network.
The tool looks for common patterns associated with API keys, access tokens, bearer tokens, GitHub tokens and JWTs and flags them as a possible secret. It cannot verify whether a key is real, active or valid — treat any flagged item as worth reviewing, not a confirmed credential.
Yes. Exporting a protected screenshot re-encodes the image on your device, which strips EXIF data such as GPS location and camera information automatically. The tool also shows you what metadata was found before you download.
Yes, two ways. "Click Text to Redact" shows every piece of text the tool could read, flagged or not, and lets you redact any of it with a single click — useful for a label or value the automatic detectors don't recognise. "Draw a Box" lets you drag a freehand rectangle over any area, including photos, logos or anything the tool couldn't read as text at all. Both support blur, pixelation, a solid block or an approximate background-blend cover.
Redactions are only baked into the image you download. Your original screenshot stays untouched in the editor until you close or refresh the page, so you can undo, redo or reset at any time before exporting.
Not recommended. Blur can sometimes be partially reversed or may not fully obscure high-contrast text. For passwords, API keys, tokens and card numbers, use Solid Cover instead.
Common candidates include full names, National Insurance numbers, dates of birth, email addresses, phone numbers, IP addresses, internal hostnames or file paths, API keys and tokens, payment card, bank or tax reference details, and anything that identifies a person, account or internal system that isn't relevant to what you're sharing.
Yes. It recognises the standard UK National Insurance number format and HMRC Unique Taxpayer Reference (UTR) directly, and looks for names and dates of birth next to common form labels like "Name:" or "Date of Birth:", including when the label and value are on separate lines. Because a name has no fixed structural pattern the way an email address does, this is a best-effort heuristic rather than a guarantee — always review the whole screenshot yourself, and use Manual Redact for anything it misses.