TopSecret documentation
Black out anything sensitive in an image or PDF — draw the bars yourself or let TopSecret find emails, IDs, card numbers, and faces for you. Export a flattened copy where the hidden data is genuinely gone, not just covered. Everything runs on your own device, on Mac, iPhone and iPad. This page walks through how it works, from the Mac; On iPhone and iPad covers what's different there.
Installation
TopSecret comes three ways. The download from bendansby.com/apps/topsecret is a notarized .dmg — open it and drag TopSecret.app to your Applications folder. It ships with a free 7-day trial; a one-time license then unlocks unlimited use. The Mac App Store version is a paid-through-Apple copy that installs and updates the usual way. The Setapp version is a one-time purchase, not part of a Setapp Membership subscription; it installs through the Setapp client, with no separate license key and no trial.
Requires macOS 13 Ventura or later, on Apple Silicon or Intel. The direct-download build keeps itself up to date via Sparkle; you can also check anytime from within the app. The Mac App Store and Setapp builds update through their own channels.
The iPhone and iPad app comes from the App Store — the same purchase as the Mac App Store version — and needs iOS 26 or iPadOS 26 or later.
Opening an image or PDF
Drop a file onto TopSecret to get started — a screenshot, a photo, or a multi-page PDF — or choose File ▸ Open. With nothing open, ⌘V opens whatever image or PDF is on the clipboard. Whatever you hand it opens on the canvas, ready to redact. TopSecret only ever touches the file you give it, and the first time you open one it says so: opening a file never changes it.
Redaction is permanent
This is the whole point of TopSecret, so it's worth stating plainly: a redaction bar is not a sticker laid on top of your image. When you export, the bars are burned into a new flattened file and the pixels underneath are recomputed. The hidden text or face can't be selected, copied, or recovered from the exported copy — it's genuinely gone.
Exported PDFs are rasterized during this same flattening, so nothing lingers on a layer or in a text stream underneath the bar. What you see in the finished file is all there is.
The Redact sidebar
Every redaction tool lives in the sidebar on the right of the window, beside the page it applies to:
| Section | What it's for |
|---|---|
| Manual Redact | Whether a drag on the page draws a bar (Draw) or selects text (Select Text), with a reminder of how each works. |
| Find & Redact | Words, numbers and blocks of text to black out wherever they appear, and your saved term sets. |
| Auto-Detect | A switch for each kind of sensitive content TopSecret can find on its own. |
Below them, the latest result of a scan or an export, and the Export… button (⌘E). Every bar is solid black.
Drawing & adjusting bars
Drag on the canvas to place a redaction bar over anything you want hidden. Once it's down you can move it or resize it to get the coverage exactly right.
- Drag out a bar to cover a region.
- Move or resize a placed bar until it frames the sensitive area.
- ⌫ removes the selected bar. The arrow keys move it, ⌥-arrows resize it, and holding ⇧ takes bigger steps.
- Zoom in with a pinch or ⌘-scroll, or ⌘+ and ⌘−, for fine work; ⌘0 fits the page again.
- Full named undo & redo covers every change, so you can back out of a mistake without starting over.
Selecting text
Switch Manual Redact to Select Text and drag across the words on a page — TopSecret reads them on-device, even from a scan or a photo. A small menu appears over the selection:
- Copy puts the text on the clipboard.
- Redact This blacks out just the selection, one bar per line.
- Redact All adds the text to the Find & Redact list, so every copy of it in the document is blacked out — however it wraps.
Esc clears the selection.
Auto-detect sensitive content
Rather than hunt for every sensitive field by eye, let TopSecret find it. Each kind below is a switch: turn one on and TopSecret scans the whole document and blacks out every match; turn it off and those bars come back off.
- Email addresses
- Social Security numbers
- Phone numbers
- Card numbers
- IP addresses
- Faces
The number beside each switch is how many bars it has placed. All and None switch every kind at once. It all runs on-device with Apple's Vision framework — nothing is uploaded to find these things. Detected regions are ordinary bars, so you can nudge, resize, or delete any of them before exporting.
Find & redact by text
When you know what to hide, type it into the Find & Redact box and choose Redact Matches (⌘↩; ⌘F jumps to the box). TopSecret blacks out every occurrence across the document and adds the term to a list underneath, with how many matches it found.
- Put a blank line between terms to add several at once. A single line break keeps going with the same term, so a two-line address stays one term — and it's still found if the document wraps it differently or runs it together on one line.
- Turn on fuzzy match before adding a term to also catch close spellings and OCR slips, so a name or ID that got scanned imperfectly still gets covered.
- Every term stays redacted until you remove it: click the ✕ beside it and its bars come back off.
Saved term sets
For the names and numbers you redact again and again, use the Sets menu beside Find & Redact. Save as Set… stores the terms in the box — or, if the box is empty, the list — under a name, pre-filled from the first line. Choose a set from the menu to add all of its terms at once. Saving under a name that already exists replaces that set; Manage Sets… lists them all, with a delete button for each.
Images & multi-page PDFs
TopSecret handles single images and long PDFs alike. For a multi-page document, a page list on the left tracks the redactions on each page, so you can see at a glance where you've been and what's still bare.
Auto-Detect and Find & Redact always cover every page, so nothing slips through on a page you didn't check. As with any export, PDFs are rasterized on the way out so nothing survives underneath the bars.
Exporting a flattened copy
When the document is redacted the way you want it, export it. This is the step that burns the bars in and produces the safe-to-share copy described in Redaction is permanent — a new flattened file with the hidden pixels recomputed away and (for PDFs) the pages rasterized. Before your first PDF export, TopSecret explains that the rest of the text becomes part of the page image too; it asks again until you go ahead.
Saving a session
Redaction bars stay editable while you work. Save your progress as a .topsecret session (File ▸ Save, ⌘S) and you can reopen it later to move bars around, add more, or switch Auto-Detect kinds and Find & Redact terms on and off — the session keeps them, and the flattening only happens when you export. Once a session is saved, Save As… (⇧⌘S) makes a copy under another name. A dot next to the file name means there are unsaved changes.
On iPhone and iPad
The iPhone and iPad app does everything described here, with the platform's own ways in and out:
- Opening: Choose Photo or Choose File, the Open menu at the top left, Open in TopSecret from another app's share sheet, or — on iPad — drag a file in.
- The tools: on iPad the Redact sidebar sits beside the page, with the page list on the left when there's room. On iPhone, tap Redact in the bottom toolbar to bring the same tools up in a sheet; the bottom toolbar also switches between Draw and Select Text and carries Delete, Undo and Redo.
- Gestures: drag to draw a bar, drag a bar to move it or a corner to resize it, pinch to zoom, and drag with two fingers to move around a zoomed page.
- Saving and exporting: Save and Save As are in the Session section at the bottom of the Redact tools. Export shares the flattened copy through the share sheet — Save to Files, AirDrop, Mail, and the rest.
A .topsecret session saved on one device opens on the others.
Privacy
TopSecret is private by design. There is no network access, no account, and no telemetry — it only ever touches the file you hand it, and everything, including auto-detection, runs locally on your device. It's built in SwiftUI as a universal binary and, on the direct-download build, keeps itself up to date via Sparkle.
For the full details, see the privacy policy.
Support
Questions, bug reports, or feature requests? Email ben.dansby@gmail.com and you'll get a reply, usually within a day or two.