BlueMask

Hide private details in photos and screenshots.

Local processing · No uploads

Drop an image here

PNG, JPEG or WebP · Paste with ⌘V / Ctrl+V

Choose an image, then draw over what you want to hide.

Cosmetic blur

Blur can leave recoverable details.

Bluethroat recommends secure masking for sensitive data.

APPEARANCE ONLY

Cosmetic blur

Softens pixels without securely removing them. Use for backgrounds and visual effects.

This changes the method for new regions. Existing masks keep their method.

Before downloading

Some regions are only blurred.

Bluethroat recommends secure masking for sensitive data.

Paranoia Mode

Why Paranoia Mode exists

How do you know Bluethroat Labs isn’t uploading your photo or extracting sensitive details from it?

You can check that BlueMask works with your device disconnected. While there is no network connection, this page cannot upload your photo or send its contents to our servers.

  1. Download the offline edition.Everything is included in one HTML file.
  2. Disconnect before opening your image.Turn off Wi-Fi and mobile data; unplug Ethernet.
  3. Open the file, mask and save.Review the download. Close BlueMask before reconnecting.

Your device controls that connection; this button cannot disconnect it.

Offline editing shows that no server is needed. It does not certify the code or your device.

Download offline edition

About BlueMask

BlueMask hides private details in photos and screenshots. It runs in your browser, without uploading your image.

Use secure masking for sensitive data. It replaces the covered pixels with a solid patch. Cosmetic blur is an appearance effect and may leave recoverable details.

  1. Why isn’t ordinary blur enough?

    Blur mixes pixels together. A name can look unreadable while still leaving enough shapes and patterns for software to recover it.

    Deblurring models such as Restormer and NAFNet reconstruct detail from degraded images. They can also produce plausible guesses. A sharp result is not necessarily the original. These are research references, not BlueMask test results.

  2. What is Gaussian blur?

    Each pixel becomes a weighted average of its neighbors. Nearby pixels count more, following a bell-shaped pattern called a Gaussian kernel. The mixed values still depend on the original image.

    A stronger blur is not a guarantee that a secret is gone. See the Gaussian filter definition.

  3. What makes secure masking different?

    It replaces the selected pixels with a fixed, opaque color. The mask’s color does not depend on the hidden image. The export is a flattened PNG, with no separate layer to lift off.

    For the same mask positions and visible surroundings, changing the hidden pixels produces the same output. Secure masks also take priority wherever they overlap cosmetic blur. Your original file is unchanged.

  4. Does my image leave my device?

    This edition reads, edits and saves images locally. It has no image uploads, analytics, accounts or remote AI calls.

    Opening the hosted website still connects you to its host. For sensitive images, download the offline edition and disconnect before choosing your image.

  5. Why does Paranoia Mode exist?

    How do you know Bluethroat Labs isn’t uploading your photo or extracting sensitive details from it? Paranoia Mode lets you check that BlueMask works offline. While your device has no network connection, the page cannot send your photo or its contents to our servers.

    A webpage cannot turn off your internet connection for you. Disconnect before opening your private image:

    1. Download the offline HTML file.
    2. Turn off Wi-Fi and mobile data; unplug Ethernet.
    3. Open the file, choose your image, mask and save.
    4. Review the export and close BlueMask before reconnecting.

    The browser’s connection indicator is only a hint. Use your device’s network controls to disconnect.

  6. Does working offline prove it is trustworthy?

    It proves editing needs no server. It does not prove the code, browser or device is safe.

    The source and recorded tests are downloadable. File hashes identify the exact build; they do not certify its safety.

  7. What about filenames and hidden metadata?

    BlueMask creates a new PNG named bluemask.png. It does not copy the original filename, camera details or GPS metadata. Ordinary image properties, such as dimensions, remain.

    Anything visible in the picture still needs to be covered.

  8. Can someone still identify what I hid?

    Yes, from context. A box’s width can suggest a name’s length. Nearby text, logos, reflections and timestamps can give you away.

    Cover the full detail with room around it. A whole line can reveal less than a tightly fitted word. Avoid sharing differently masked versions of the same image.

  9. What do the recovery tests establish?

    The published test uses twelve synthetic codes. DPIR recovered all twelve from the Gaussian blur control and none from secure masks. All twelve secure inputs were identical, so they were not independent challenges.

    DarkIR failed the ordinary-blur control; its failure on masks is not a useful resistance result. These tests do not establish protection against every model, face recognition or guesses from context. Settings, originals and outputs are available with the results.

Recovery tests

Can a deblurring model recover a hidden code?

12 synthetic codes · Tested 2026-09-06

DPIR / DRUNet (2021) · Exact codes read by OCR
MethodBefore recoveryAfter recovery
Gaussian blur9 / 1212 / 12
BlueMask secure masking0 / 120 / 12

All twelve secure inputs were identical. This small test does not establish protection against every image or AI model.

Original

Synthetic code: 30008867.
Synthetic code: 30008867.

Blur → recovery

Exact code recovered.
Exact code recovered.

Secure mask → recovery

Code not recovered in this test.
Code not recovered in this test.

Example 05. All inputs and outputs are included in the download.

Test setup and limitations
  • Twelve synthetic eight-digit codes, one font and fixed mask positions. Exact matches were measured with Apple Vision OCR.
  • DPIR is an established 2021 baseline. The Gaussian control uses σ = 3 and a known kernel; it differs from BlueMask’s cosmetic blur.
  • The twelve secure exports collapse to one identical input. They are not twelve independent model challenges. OCR failure alone does not prove that no information remains.
  • DarkIR (CVPR 2025), a low-light photo model, failed the blur control: exact matches fell from 9/12 to 0/12. Its failure on secure masks does not demonstrate resistance to a capable recovery attempt.

Download tests & outputs ↓

Secure masking removes the covered pixels. Visible context can still reveal private details.