Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

Redacting Participant Data From PDFs Without Adobe Pro

True PDF redaction means permanently deleting underlying text and metadata, not just drawing a black box. This guide covers when free tools like iLovePDF genuinely work, when they don’t, and how Foxit PDF Editor compares as a lower-cost Acrobat Pro alternative for redacting participant and patient data.

Ask about Redacting Participant Data From PDFs Without Adobe Pro

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Sharing a PDF that contains participant names, patient identifiers, case IDs, or other personal data outside your research team is one of the most routine data-handling decisions a researcher, IRB coordinator, or research-integrity officer signs off on — and it almost always requires redaction first. For most researchers and research staff, that means doing it without an Adobe Acrobat Pro license, because their institution either hasn’t licensed it for them individually or reserves it for a handful of departmental seats, which pushes the choice of tool down to the individual investigator rather than IT. This guide is written for that decision: what redaction actually means for a PDF (not just “black box,” see below), why incomplete redaction is a disclosure and research-integrity problem and not just a cosmetic one, the free tools that genuinely work for low-stakes cases, and when the underlying-data-removal problem is serious enough that dedicated paid software is the defensible call.

Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched, and we say plainly where a tool is not the right fit. Read our full disclosure policy →

Why “drawing a black box” is not redaction

The single most common mistake in ad-hoc PDF redaction is covering sensitive text with a black rectangle, an annotation, or a highlight, then exporting or flattening the file and calling it done. A PDF stores its text as a searchable layer underneath whatever is drawn on top of it. A black box placed with an annotation tool, a shape tool, or even some “redaction” features in cheap PDF apps only changes what’s rendered on screen — the original characters are usually still present in the file’s text layer and can be recovered by selecting and copying the “hidden” text, running the file through OCR, or opening it in a text editor. This is not a hypothetical: it is one of the most frequently rediscovered failure modes in public-records releases, court filings, and legal document production, and it applies identically to a spreadsheet of participant IDs pasted into a PDF report.

True redaction has to do three things: (1) permanently delete the underlying text and image data in the redacted region, not just obscure it visually; (2) strip document metadata (author name, edit history, comments, embedded file properties) that can itself contain identifying information; and (3) flatten the result so nothing in the redacted area is recoverable by copy-paste, search, or re-opening in another PDF tool. A tool only qualifies as doing “true redaction” if it does all three, not just the first.

The disclosure risk: why incomplete redaction is a research-integrity issue

An incompletely redacted PDF shared as supplementary material, deposited in a repository, or attached to a public-records request doesn’t just risk an awkward correction later — it can constitute an unauthorized disclosure of participant data, which is a different category of problem than a typo. Depending on your protocol, that disclosure can trigger breach- or incident-reporting obligations to your IRB, your funder under a data-sharing agreement, or, if the file contains protected health information, HIPAA’s breach notification requirements — independent of whether anyone can be shown to have actually exploited the recoverable text. Search engines, institutional repositories, and preprint servers routinely cache a PDF before an author or journal can pull a corrected version, so “we replaced the file” is not the same as “the data was never exposed.” For a research-integrity or data-governance office reviewing an incident, the redaction method used is itself the evidence that appropriate de-identification steps were actually taken, not merely attempted — which is why the verification step later in this guide (confirming text is genuinely unselectable and unsearchable, not just visually covered) matters as much as the redaction step itself.

When a free tool is genuinely enough

For low-stakes situations — a single name or email address in an otherwise non-sensitive document, redacting your own contact details before posting a form publicly, or a quick internal draft where nothing regulated is involved — a free tool is a reasonable, defensible choice, provided you actually verify it removed the underlying text rather than just covering it. Two options that hold up reasonably well for that narrow case:

  • Preview (macOS) — has no real redaction tool. The common workaround (drawing a filled black rectangle with the shape tool, then exporting) does not remove underlying text; it only visually covers it. Preview is fine for cropping or annotating, not for redacting anything that needs to hold up to scrutiny.
  • iLovePDF’s “Redact PDF” tool — a browser-based tool that lets you draw boxes over text and, per its own documentation, permanently deletes the covered content rather than layering a mark over it, which is a meaningfully better starting point than the black-box workaround. Its practical limits for research use: it processes your file through a third-party server (a real consideration if your document contains protected health information or falls under a data use agreement that restricts where data can be transmitted), it has no batch/bulk mode on the free tier, and it has no dedicated tool for stripping document metadata separately from the visible content.

The honest line: if the document has no PHI, no data-use-agreement restrictions on third-party processing, and only one or two items to redact, a free browser tool is proportionate. If any of those conditions aren’t true, treat the free tools as insufficient and move to the next section.

When you need real redaction software

Institutional review board protocols, HIPAA-covered data, funder data-sharing requirements, and multi-site data-use agreements routinely require more than “the box tool” — they require a defensible process: permanent removal of underlying text and images, metadata stripping, and often a way to demonstrate (for an audit trail or a compliance review) that redaction was applied correctly. That’s the gap dedicated PDF editing software closes, and it’s also where an on-server browser tool becomes a liability rather than a convenience, since uploading PHI to a third-party redaction service can itself be a data-handling violation independent of whether the redaction works.

This is the situation the “how to redact a PDF without Adobe Pro” search usually describes: someone who needs Acrobat-Pro-grade redaction (true content removal, metadata stripping, desktop processing) but doesn’t have or want an Acrobat Pro license. Foxit PDF Editor is a direct, lower-cost alternative built for exactly that: it performs true redaction (the underlying text and images in the marked region are deleted, not just covered) and its higher tier adds an AI-assisted “Smart Redact” feature intended to help locate personally identifiable information across a document rather than requiring you to manually mark every instance, which is a real time-saver on longer files with repeated identifiers (case IDs, patient names, dates of birth) scattered throughout.

Purchasing dedicated redaction software also raises a procurement question a generic buying guide won’t address: is this an allowable direct cost on your grant, or should it be requested through your research computing office as a shared license instead? Under federal Uniform Guidance rules for sponsored awards (2 CFR 200), whether software can be charged directly to a project depends on whether the cost is specifically identifiable to that award and treated consistently with your institution’s cost-accounting practices — many institutions instead classify general-purpose office software, including PDF editors, as an indirect (facilities-and-administrative) cost already covered by overhead, which means an individual purchase charged to a grant may not be allowable even when the tool is used exclusively for study-related redaction. Before buying a personal license, check with your grants office or research computing office: some institutions already hold a comparable site license, and where a direct-charge purchase is allowable, most sponsors expect documentation (an invoice tied to the specific award, and a justification for why an existing institutional tool was insufficient) at the time of purchase, not retrofitted later during an audit.

Try Foxit PDF Editor free for 14 days →

Foxit PDF Editor: pricing, tiers, and what redaction requires (verified August 2026)

As of August 2026, per Foxit’s own pricing page, Foxit PDF Editor is sold in three tiers:

  • PDF Editor — subscription starting around $10.99/month, covering core editing on Windows, macOS, and web.
  • PDF Editor+ (the tier Foxit markets as most popular) — roughly $159.99/user/year billed annually, adding mobile apps and the AI-assisted “Smart Redact” feature for automated PII detection and removal.
  • Foxit PDF Editor (perpetual license) — a one-time purchase around $209.99/user for a permanent desktop license (Windows/macOS only), which Foxit’s own page notes explicitly excludes the AI Assistant, Smart Redact, and cloud/DMS features.

The practical implication for a researcher evaluating this: standard redaction functionality is generally available across Foxit’s editing tiers, but the automated PII-detection “Smart Redact” capability specifically is gated to PDF Editor+. If your redaction workload is a handful of documents with identifiers you can locate and mark yourself, the base tier is sufficient. If you’re regularly processing longer documents (clinical case report forms, transcripts, multi-page consent logs) where manually finding every instance of a name or ID is itself time-consuming and error-prone, the automated-detection tier is the one worth the extra cost. Foxit offers a 14-day free trial with no credit card required, which is enough time to test true redaction against a real (de-identified test) document from your own workflow before committing.

Pricing and feature gating change over time on any vendor’s site — confirm current tier details on Foxit’s own pricing page before purchasing rather than relying solely on this summary.

Step-by-step: redacting a PDF without Adobe Acrobat Pro

For a low-stakes document (free tools)

  1. Confirm the document does not contain PHI or data covered by a data use agreement restricting third-party transmission — if it does, skip to the paid-software steps below.
  2. Upload the file to a browser-based redaction tool such as iLovePDF’s Redact PDF tool.
  3. Draw a redaction box over each instance of sensitive text (name, email, ID number). Check every page manually — automated detection is not typically available on free tiers.
  4. Apply/export the redaction, then verify by opening the exported file and attempting to select text in the redacted area with your cursor, and by running Ctrl/Cmd+F for the redacted string. If either surfaces the original text, the redaction failed and the file is not safe to share.
  5. Check document properties (File > Properties, or equivalent) for author name, comments, or other metadata that might itself be identifying, and clear it manually if the tool doesn’t do this automatically.

For PHI, IRB-governed data, or multi-instance documents (paid software)

  1. Install Foxit PDF Editor (or comparable true-redaction desktop software) so the file is processed locally rather than uploaded to a third-party server.
  2. Use the built-in Search & Redact (or, on PDF Editor+, Smart Redact) function to locate every instance of the identifier across the full document, rather than paging through manually.
  3. Mark all instances for redaction, then apply — this step deletes the underlying text/image data, not just the visible mark.
  4. Use the metadata/properties removal function to strip author, edit history, and embedded document properties before export.
  5. Verify the same way as above: attempt to select and search the redacted text in the final exported file. A tool doing true redaction will return nothing.
  6. Retain your redaction workflow notes (which tool, which version, verification steps taken) if your IRB protocol or data-sharing agreement requires documented evidence of your de-identification process.

How this fits into your broader data-handling obligations

Redacting a single PDF is rarely the whole compliance picture. If you’re preparing data for a repository, a co-investigator at another institution, or a funder deposit, redaction needs to sit inside your project’s broader Data Management Plan and, where applicable, a formal de-identification process consistent with the HIPAA Privacy Rule‘s Safe Harbor or Expert Determination methods if the data includes protected health information. Redacting visible identifiers from a PDF is necessary but not sufficient for HIPAA de-identification, which has specific requirements about the 18 identifier categories and re-identification risk that go beyond what a redaction tool alone verifies. If the document is being shared under a Data Sharing Agreement, check whether the agreement specifies an approved redaction/de-identification method or requires sign-off before the file leaves your institution.

Frequently asked questions

Does redacting a PDF for free actually remove the data, or just hide it?

It depends entirely on the tool. Drawing a black box with an annotation or shape tool (the Preview workaround, or a basic PDF viewer’s “highlight/blackout” tool) almost never removes the underlying text — it only covers it visually, and the original text is usually still selectable, searchable, or extractable via OCR. Purpose-built redaction tools, including some free ones like iLovePDF’s Redact PDF tool, are designed to delete the underlying content rather than cover it, but you should always verify by trying to select or search the redacted text in the exported file before trusting it.

Is Foxit PDF Editor good enough for HIPAA-related redaction?

Foxit’s redaction feature is built to remove underlying text and images (true redaction), which is a necessary technical capability for handling PHI-containing documents. But redacting a PDF is only one piece of HIPAA de-identification, which requires either removing all 18 Safe Harbor identifier categories or a formal expert determination of re-identification risk — software can help you execute the redaction correctly, but your institution’s privacy/compliance office, not the software vendor, is responsible for confirming the overall de-identification method meets HIPAA’s standard.

Can I redact a PDF on my phone?

Foxit PDF Editor+ includes mobile apps (iOS/Android), which extend redaction to mobile, but for anything involving PHI or IRB-governed data, verify your institution permits handling that data on a personal or mobile device at all before doing so — many data use agreements and IRB protocols restrict this regardless of which app is used.

What’s the cheapest way to redact a PDF if I only need to do it occasionally?

For occasional, low-stakes redaction with no PHI or DUA restrictions, a free browser tool is a reasonable choice as long as you verify the underlying text is actually removed (see the FAQ above). For occasional but higher-stakes redaction (even a single PHI-containing document), a short paid trial or a monthly subscription tier is more defensible than routing sensitive files through a free third-party web tool, given the data-transmission exposure involved.

Does Foxit PDF Editor replace Adobe Acrobat Pro entirely?

For redaction specifically, yes — Foxit’s redaction tooling is built to do the same underlying job (permanent content removal, not just visual coverage). Whether it replaces Acrobat Pro for your full workflow depends on which other Acrobat features you rely on (form design, advanced accessibility tagging, certain e-signature workflows); compare feature lists for your specific use case rather than assuming full parity.

Who this is not right for

If your institution already provides Acrobat Pro (even a shared departmental license you can request access to), there’s little reason to purchase separate software just for occasional redaction — ask your IT or research computing office first. If your redaction needs are genuinely rare (a handful of documents a year, none containing PHI), a free tool with careful manual verification is proportionate and a paid subscription is hard to justify. And if your institution’s IRB or data governance office mandates a specific approved tool or vendor for de-identification, use that tool regardless of what this guide recommends — institutional policy overrides a general recommendation every time.

See Foxit PDF Editor pricing & start a free trial →

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →