Sensitive Text Redactor

Mask known sensitive patterns in text or selected CSV columns and download a redacted table.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Redact the text controls

Showing an example. Edit to see your own.

Used in text mode. Showing an example with a fictional address and test card number. Replace it with your text. The tool does not send or save it. Clear the box and your clipboard when you are done.

One per line. Each line is matched as plain text, so punctuation in it is safe.

Showing a small example with fictional names, an example.com address and standard test card numbers. Replace it with your CSV. The tool does not send or save it. Clear the box and your clipboard when you are done.

Comma-separated header names, for example email,card. The match is by exact header name, so a misspelling stops with a list of the headers that were read.

Text mode reads the whole pasted text. CSV mode reads a small table, changes only the columns you name, and offers a redacted CSV download.

Off by default because a long identifier or hash is often not a secret.

Masking matches uses the pattern groups below inside the chosen columns only. A value that matches no chosen pattern stays unmasked.

Without a header row, columns are numbered column_1, column_2 and so on, and those are the names to type in the box above.

Stops a value that begins with = + - or @ from running as a formula when the CSV is opened in a spreadsheet. It runs over every exported cell, masked or not.

Processed in your browser. Your inputs stay on this device.

How to use Sensitive Text Redactor

  1. Paste the text you need to share into the box and leave the pattern groups you want switched on.
  2. Add any exact words of your own on separate lines, one per line, if the text repeats a name or a project code.
  3. Read the masked text and the count for each group, then copy the masked version and replace the original wherever it was stored.

Example: Sensitive Text Redactor

Mask an email address, a card number and a token in a support note before it is posted.

You add
Text: Hello [email protected], please check card 4111 1111 1111 1111 and token ghp_1A2b3C4d5E6f7G8h9I0jKlMnOpQrStUvWx9Y0z. Mask style: Label each match, such as [EMAIL].
You get
The masked text reads Hello [EMAIL], please check card [CARD] and token [API KEY]. The table counts 1 match in Email addresses, 1 in Card numbers and IBANs, and 1 in Keys and tokens.

Options

Pattern groups
Each group is a shape with its own rule: an address with an at sign, a number with enough digits and a separator, a card that passes the Luhn check, an IBAN that passes the country checksum, an IP literal, a token with a known prefix, or a US Social Security number. A group you switch on is also a group you can see the count for, including a count of zero.
Mask style
Labels such as [EMAIL] keep the text readable and show which rule matched. Asterisks hide the label, but a reader can still count the characters. The word REDACTED is the plainest option. None of the three changes what was found.
Long random strings
This option is off until you switch it on. It matches runs of 32 to 64 characters that mix upper case, lower case and digits, which catches some keys and also some hashes, identifiers and machine-generated names that are not secret at all.
Also mask these exact words
Type one word or phrase per line and each line is matched as plain text, in any letter case. Punctuation is treated as ordinary characters, so a name with a dot or a bracket is matched as written, not as a pattern.
CSV column redaction
Choose Mask chosen CSV columns, paste the table and enter comma-separated column names. Matching-values mode uses the selected pattern groups only inside those columns. Every-value mode masks each non-empty selected cell. The report shows counts; the download holds the redacted data.

Supported inputs and limits

Pasted text or CSV up to 200,000 characters. CSV mode allows 10,000 data rows and 100 columns. Name the columns to mask; matching names are exact, and repeated headers with that name are all selected. Mask known patterns or every non-empty value in the chosen columns. Other cells retain their text except for the selected spreadsheet formula guard, which prefixes risky exported values by default. Patterns can miss secrets or mask values that are not sensitive. Review the downloaded CSV before sharing it. No originals or input files are sent to the server or saved by this tool. The original input remains in the page until cleared; clear it and your clipboard when finished.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Masking is not deletion

A redactor changes the text you are about to share, not the copy it came from. The version in your notes, your ticket, your log export or your clipboard is untouched, so masking a paragraph and then pasting the same paragraph from somewhere else undoes the work. Treat the masked text as a new, separate copy, and replace the original wherever it is stored. Where a value is a live credential, rotate it rather than only hiding it, because a value that has already been written into a shared system may still be usable. The patterns on this page cover common shapes and miss unusual ones, so a person still has to read the result before it leaves your hands.

Questions about Sensitive Text Redactor

Does this find every secret in my text?

No. It matches a fixed list of shapes and reports nothing for everything outside that list. A blank result is not proof that a piece of text is safe to share, so read the masked version yourself before you post or send it.

Is the mask reversible?

There is no mapping to reverse, because no list of the masked values is kept. The original text is still in the box above until you clear or replace it, and the masked copy is the version you would share.

Which card numbers are masked?

Only numbers of 13 to 19 digits that pass the Luhn check. That keeps order numbers and timestamps out of the results, and it also means a real card number with one wrong digit is left alone.

Why was my long token left alone?

The long random string rule is off by default. Even when it is on, it needs 32 to 64 characters with upper case, lower case and a digit in the same run, and a token that is shorter, all lower case, or split across lines will not match.

What happens to my text?

It stays in the page while you work, and the tool does not send it or save it to a store of its own. A browser can still keep a page you return to, and the site's own analytics are separate from what you paste, so clear the box and your clipboard when you are finished rather than relying on closing the tab.

Project manager: Tony Hines · Content updated 30 September 2026 · Report a problem