Redacting a document before you share it with an AI chatbot
· 7 min read
Before a document goes into an AI chat app, take out what identifies people and accounts: names, account and reference numbers, addresses and signatures. Take them out of the file, not just out of view. These apps generally pull the text out of a PDF, not just the picture of the page, so a black box drawn in Preview hides nothing from them.
Often the better move is not to upload the file at all. Copy the paragraph you need, swap the identifiers for placeholders, and paste that instead.
Decide what the question actually needs
The chatbot needs the substance of your problem, not the identity of everyone in it. “Is this clause in my lease normal?” needs the clause. It does not need the landlord’s name, your address or the unit number at the top of page one.
Remove these first, roughly in order of how much harm a leak would do:
- Numbers that unlock things. Account, card, policy, case, patient and tax reference numbers. Check footers and reference lines (“Our ref:”), where the same number is often printed a second time in smaller type.
- Names. Yours, and above all other people’s: the colleague copied into an email thread, a client, a patient, a child named in a school report. Their details are not yours to share, and a work document may be covered by a confidentiality policy that settles the question for you.
- Contact details. Home addresses, phone numbers, email addresses, dates of birth.
- Signatures and initials. A signature is an image of the thing that authorizes contracts and payments. No question about a document needs it.
- Letterheads, barcodes and QR codes. These identify the organization and can encode account details.
- The file itself. A file named “Lease 14 Elm Rd.pdf” undoes careful work on the pages, and so does an author field carrying your full name.
Keep what the question depends on. If you are asking whether a bill adds up, the amounts stay. If timing matters, keep the dates, or shift them all by the same amount.
Why a black box hides nothing from a chatbot
A PDF exported from a word processor or downloaded from a bank or an employer’s portal contains its words as real text. When you draw a filled rectangle with Preview’s Markup tools, you add a shape on top of that text and leave the text exactly where it was. Anyone looking at the screen sees black. A program that reads the file pulls out the text directly and gets every word, including the ones under the box. AI chat apps typically take in a PDF this way, whatever else they do with the page. Why a black box on a PDF does not redact anything explains the mechanism in full.
The reverse also catches people out. Many of these apps can read images, so a screenshot or a phone photo of a document is read in full: the small print in the footer, the reference number in the corner, the name on the envelope at the edge of the frame. A picture is only as private as everything visible in it.
Word processor files carry their own extras. Tracked changes keep deleted wording in the file, comments keep their authors’ names, and an uploaded .docx may hand over all of it, depending on how the app reads the format. Accept or reject every change and delete the comments first, or copy the clean text out into a new document.
The copy-paste test
This is a fair approximation of what a chat app extracts from a PDF, and it takes a minute.
- Open the exact file you plan to upload in Preview. Not the working copy: the one you will attach.
- Press Command-A, then Command-C.
- In TextEdit, make a new document, choose Format, Make Plain Text (Shift-Command-T), and paste.
- Press Command-F and search for each thing you meant to remove: the surname on its own, the last four digits of the account number, the street name.
- Read the whole paste once, top to bottom. Headers, footers and fine print you skimmed past on screen turn up here.
If the paste comes back empty for pages that clearly have words on them, those pages are images, usually a scan. The test cannot see them, but an app that reads images can, so check those pages by eye at full zoom. A scan that was made searchable also carries a hidden text layer, which is exactly what the test is for.
Then rename the file, and open Tools, Show Inspector to read its title and author. How to check whether a PDF was really redacted has the longer list, including a full text extraction with Automator.
When to retype an excerpt instead
Most of the time this is the better answer, and it is quicker than redacting. It suits three situations: the question is about one part of the document, the document contains other people’s information, or the document is a scan, where you would otherwise have to deal with both the pixels and a hidden text layer.
- Copy only the passage you need into a plain TextEdit document.
- Replace each identifier with a role or a placeholder: “the landlord”, “Employee A”, “[account number]”, “[address]”.
- Use the same placeholder every time the same person or number appears, so the answer still makes sense.
- Keep the wording, figures and dates the question depends on; round or remove the rest.
- Paste the result into the chat. If you need to map the answer back to real names, keep that key in a note on your Mac, not in the conversation.
It stops working when the layout is the question: a form you cannot make sense of, a table of figures, a letter whose formatting matters. Then the file has to go whole, and it has to be redacted properly.
Redacting the file when it has to go whole
- In Preview, choose File, Duplicate and work on the copy.
- Choose Tools, Redact. This is not the Markup rectangle: it removes the content under the mark.
- Select each item from your list, then save and close the file. Preview’s own warning says marked content is permanently deleted when the document is closed.
- Reopen it and run the copy-paste test again.
Preview’s tool handles the page; the file’s properties are still yours to check. Redacting a PDF in Preview covers exactly what it changes in the file. For documents where a miss would be costly, or ones you prepare regularly, Basalt removes content rather than covering it: text under a mark is excised glyph by glyph, images under a mark are destroyed and re-encoded, and metadata, attachments, hidden layers and stale thumbnails are stripped. You review every mark before it is applied, and its verifier re-opens the export and proves the removed strings are absent before any file is written. The engine that opens your documents has no network access, which is a reasonable property for a tool you are using precisely because the full file should not leave the Mac.
What redaction does not solve
Context can name someone on its own. A job title, a town and a date can identify a person as surely as a name. When the person is the sensitive part, generalize those too: “a manager at a regional office” instead of the title and the branch.
The service keeps what you send on its own terms. Look in the app’s settings for its data controls: whether conversations are used to improve its models, how long they are kept, and how to delete them. Deleting a conversation from the sidebar is not necessarily the same as deleting it from the provider’s systems.
Some documents should not go at all. Material your employer’s policy rules out, privileged legal papers, someone else’s medical records. Redaction makes a document less identifying. It does not make it yours to share.
Questions
Does an AI chat app see text under a black box in a PDF? If the box was drawn as a shape, usually yes, because the app reads the file’s text and the text is still there. Use a real redaction tool, or paste an excerpt instead.
Is a screenshot safer than uploading the PDF? Once a screenshot is covered with an opaque filled shape and saved as a PNG or JPEG, the covered area is gone, because the saved image is just pixels. But the app reads everything that is visible, so crop to the part you are asking about before you cover anything.
Should I use fake names or just delete them? Placeholders work better than gaps. “Tenant A wrote to Landlord B” keeps the meaning of the passage; a run of blanks makes the answer harder to follow and easier to get wrong.