How to cover something so that it stays covered
There are two ways to hide part of a photograph, and only one of them works.
The way that does not work is to put something on top: a black rectangle in a PDF, a shape pasted over a screenshot in a slide, a sticker in a chat app. The original pixels are still in the file, sitting underneath a layer that anybody can move, delete or select around. Every few months a redacted court filing or a government report makes the news for exactly this reason.
The way that works is to destroy the pixels. That is what this tool does: the area you drag over is recomputed and written back into the image, and the values that were there are gone from the exported file. There is no layer to peel off, because there is no layer.
The three effects
Blur replaces the region with a smeared version of itself. It reads as a deliberate edit while still showing that a person was there, which is why it is the usual choice for faces and for backgrounds.
Mosaic replaces it with large uniform blocks. It survives re-compression more visibly than blur — a heavily compressed blur can look accidental, a mosaic never does — and it is the convention on Korean and Japanese broadcast television, so viewers read it as censorship rather than as a bad lens.
A solid block replaces the region with black. It is the honest choice for anything a machine might read: an identity number, a bank account, a licence plate, a QR code. Nothing is left to reconstruct because nothing is left.
The strength slider controls how far blur smears and how big the mosaic blocks are. Both are measured against the size of the area rather than in fixed pixels, so a small box gets small blocks and the result looks the same whether you export at 800 px or 4000.
One caveat worth stating plainly: a weak blur over text is the one case where covering can be partially defeated. If the font and the wording are guessable, an attacker can blur candidate strings the same way and compare. Turn the strength up, or use the block, and the problem does not arise.
Rectangles and the brush
The rectangle is for things that are rectangular — a form field, a name badge, a screenshot region. Drag to draw one; drag it again afterwards to reposition it.
The brush is for things that are not. Painting along a road sign, around a child’s face in a crowd, or over a tattoo follows the shape more closely than a box would, and covers less of the photo you wanted to keep. Its size is set in the panel, and each stroke counts as one area you can remove later.
Areas are listed in the panel in the order you made them, with an undo button for the last one and a delete on each. Changing the effect or the strength changes every area at once — one set of controls, not one per box.
Crop first, then cover
The covered areas are recorded against the picture you are looking at. If you crop afterwards, the crop changes what “the picture” is, and the areas move relative to the photo. So do it in the order that reads naturally anyway: straighten and crop, then cover, then set the size and export. If you do need to re-crop after covering, glance at the blur tab afterwards to confirm the boxes are still where you want them.
What this does not do
It does not follow a face through a batch of different photographs, and it does not know what is sensitive. It covers what you tell it to cover, in the place you put it, and then it makes that permanent — which for the specific job of handing a photograph to somebody else is the whole requirement.