Privacy you can understand.
Your PDF stays local
The editor reads your selected PDF in browser memory. Password unlocking, rendering, redaction, proof generation and verification run on your device. This edition has no PDF upload endpoint, account system, payment integration or analytics script. PDFs, passwords and private audit records are not saved to browser storage by the application. Downloaded files remain wherever you save them.
Your browser retrieves website code and PDF rendering assets from the hosting provider. Hosting services may retain ordinary access logs, including IP addresses and request metadata. Opening this website is not an anonymous activity. Browser extensions, device security and the website code remain parts of your trust boundary.
What redaction removes
Export creates a new image-only PDF from blackened pixels. Original text objects, hidden layers, source attachments and original metadata are not copied into it. The original PDF is not modified. Unmasked pixels can still reveal personal details; inspect every page before sharing. Redaction does not erase the original from your device.
The export loses native text search, text copying and vector resolution. Typical pages are rendered at 144 DPI; oversized pages use a lower resolution within resource limits. Each page receives a separate footer for the verification ring.
What verification checks
The verifier checks disclosed pixels and black masks against salted Merkle commitments, and requires canonical reconstruction of the PDF including its ring, link and embedded public proof. Changes or extra content cause the check to fail. Saving, printing or optimizing the PDF through another application may also change its bytes and invalidate it.
A passing check establishes consistency with the commitment. It does not certify bank origin, authorship, financial accuracy or the truth of the source. Without an independently trusted commitment, someone could replace the whole PDF and proof with a freshly generated package. The ring link alone is not an independent trusted commitment.
Public verification does not prove the mathematical relationship between the committed raster and the original PDF bytes. An owner can audit that relationship locally using the original and optional private witness. This implementation is not a complete zero-knowledge proof.
Private audit records
Share only the exported PDF. The optional local_witness.private.json contains salts needed for your own original audit. Keep it with your original; do not send either to recipients. Losing the record prevents that original audit, but does not stop public verification of the export.
Browser and offline support
Use HTTPS and a current desktop browser. The first page load and later uncached routes require network access. No service worker or full offline-installation guarantee is provided in this release. Processing can continue locally once all required assets are loaded, subject to browser memory and device limits. Input files are limited to 256 MiB and exports to supported pixel and partition counts. XFA forms are unsupported.
Contact
Questions and feedback: colliesun@yahoo.com. Do not send sensitive source documents or passwords. This contact address can be updated for a later release.