PiBye archive
Archive: Black boxes on a PDF are not redaction
This article describes an earlier version of PiBye, released as Sidebar. PiBye now uses Import → Review → Use with AI → Restore, with explicit file handoff and no automatic Claude connection. A black rectangle is an annotation. The original text stays in the PDF content stream and can be copied, searched, or extracted. True redaction removes the text. A fully rasterized “static” PDF can do that — and then Claude cannot read the matter either.
Published
What a PDF actually stores
A page is a content stream: instructions that place fonts, strings, and images. “Jane Smith” is not a picture of ink. It is a text-showing operator and a string. A black box drawn in Preview’s shape tools, Word, or a highlighter is usually a separate object on top of that stream.
Delete the annotation, or extract text, and the string is still there. That is why “I put a black box on it” keeps showing up in leak write-ups. Flattening is not a fix by itself. Flattening merges layers. It does not promise that the original Tj/TJ operators were removed.
True redaction, sanitizing, and the static-PDF nuclear option
True redaction rewrites the content stream: the sensitive string is gone, the region is filled, and copy-paste returns nothing. Acrobat Pro’s Redact tool, used through Apply and then Sanitize, is built for that. macOS Preview’s Redact tool (Ventura and later) is also meant to remove content, not paint over it. Drawing a rectangle is not that tool — Preview will warn you.
A second method is to rasterize every page to an image and build a new, static PDF. There is no text layer left to recover. There is also no text layer for Claude, for search, or for a screen reader. That is defensible when the file must be published and nobody has to reason over it. It is a poor Vault for an assistant.
What an assistant actually needs
Claude Desktop is not a FOIA publication desk. It needs to follow who is who across a folder. If every identifier is a black rectangle, the model infers around holes. If every page is a photograph, it is doing OCR again on a file you already had as text.
PiBye writes stand-in tokens. [PERSON_001] is the same person on every page. The real name never enters the Vault. That is not a rasterized static PDF. It is a readable copy with the identifiers removed. For Claude, that is the useful file.
A second reader, sharing no code with the app, then searches test copies for leftover personal information. A leftover is patched and the battery starts over. That process is described in How redaction is tested.
How to check a file before you share it
Search the “redacted” PDF for a name you think you covered. Select the black region and copy. If either returns the original, it was wallpaper.
If the destination is Claude Desktop, also ask whether the assistant can still follow the matter. A tokenized Vault answers both: identities swapped for tokens only your Mac can reverse, and enough text to work.
Questions this page answers
Can you recover text under a black box on a PDF?
Often yes. If the box is an annotation or a shape sitting on top of the page, the original text is still in the file. Select, copy, or run pdftotext.
Does flattening a PDF redact it?
No. Flattening turns form fields and annotations into page graphics. It does not delete the original text objects unless the tool also rewrites the content stream.
Should I rasterize the whole PDF before sending it to Claude?
Rasterizing can make identifiers unrecoverable. It also destroys the text Claude needs. For an assistant, a tokenized copy — real identifiers gone, the matter still readable — is the point.
PiBye is available now for macOS. The current PiBye workflow · Price.