Privacy and technical information
This page is for survivors who want more detail, and for advocates, IT staff and privacy reviewers assessing whether to recommend SafeKopy.
Version 0.1.0 · Last updated 29 July 2026
In plain language
- Your document is read by your own browser, on your own computer.
- It is not uploaded to SafeKopy or to anyone else.
- Nothing about your document is stored, logged or recorded.
- The new PDF is built on your computer and saved directly to you.
- SafeKopy does not find everything. Please review the new PDF yourself.
What actually happens
- The page loadsYour browser downloads SafeKopy's code and, if needed, the text-recognition engine. This is the only time anything is downloaded.
- You choose a fileThe file is read into your browser's memory using the standard file API. No upload occurs.
- Each page is examinedIf a page has a text layer, that text is read directly. If it is a scan, the page is rendered to an image and read by text recognition running inside your browser.
- Personal information is locatedPattern rules, checksums, word lists and document-structure cues identify likely personal information and its position on the page.
- A new document is builtEach page is drawn as an image, black rectangles are painted onto that image, and the image is placed into a brand-new PDF.
- The file is saved to youThe finished PDF is handed to your browser's download mechanism. It never touches a server.
Why the redacted text cannot be recovered
SafeKopy does not edit your PDF. It builds a new one out of pictures of the pages, with the black already painted on before the picture is taken.
The result is that the output file contains no text at all — not hidden, not underneath, not anywhere. There is nothing to select, nothing to copy, and nothing for a text-extraction tool to find. The same is true of the original file's metadata, comments, annotations, attachments, form values and embedded scripts: none of it is carried across as structure, because no structure is carried across.
One thing that needs saying precisely, because it is easy to state too strongly. If a comment, a note or a filled-in form field is visible on the page, then it is part of the picture, and SafeKopy has to find and cover it like anything else on the page. It is not removed simply because the new file has no comments or form fields in it. SafeKopy reads those values and covers them, and this is tested — but it is detection doing the work, with the same limits as everywhere else, not a guarantee that follows from how the file is built.
This is verified automatically on every change. The tests extract text from the output, scan its raw bytes, inspect its object structure, and then re-render the finished file at high resolution and run text recognition on it again — the same thing someone trying to recover the content would do.
What leaves your browser
| Data | Sent anywhere? |
|---|---|
| Your original document | No |
| Page images | No |
| Text extracted from the document | No |
| Text recognition output | No |
| Detected personal information | No |
| The finished PDF | No |
| Your filename | No |
| Analytics or usage data | No — there is no analytics of any kind |
Processing is verified to make zero network requests. The full flow is also tested with the browser's network switched off, and completes normally.
What we can still see, and what we cannot promise
Being straight about this matters more than sounding reassuring.
- Our web host records ordinary web-server information when the page loads — including your IP address — the same as any website. That happens before you choose a file and has no connection to your document.
- SafeKopy cannot protect you from someone who has access to your computer. The downloaded file goes to your Downloads folder, and the original stays where it was.
- SafeKopy cannot promise that a document cannot be traced, or that a person cannot be identified from what remains. Redaction reduces exposure; it does not erase risk.
- Automatic detection makes mistakes in both directions.
Storage and logging
- No cookies.
- No local storage, session storage, IndexedDB or cache storage is written. This is asserted by automated test after every run.
- No server-side session, database or document store exists, because no server processing exists.
- No error-reporting service. No crash reporter. Nothing that could receive document content.
How personal information is found
Detection runs entirely in your browser and uses no artificial-intelligence service. It combines pattern matching, checksum validation, word lists, and the structure of the document itself. Court forms are highly regular, which makes rule-based detection more effective here than it would be on ordinary prose.
Categories currently detected include:
- Names, including titles and party roles
- Street addresses, unit numbers and post office boxes
- Cities, states and postal codes
- Phone and fax numbers
- Email addresses and web addresses
- Usernames and social media handles
- Social Security and taxpayer numbers
- Immigration and alien registration numbers
- Passport, driver's licence and state ID numbers
- Bank account and routing numbers
- Payment card numbers
- Insurance policy and member numbers
- Medical record and patient numbers
- Medicare, Medicaid and provider identifiers
- Dates, including dates of birth
- Case, docket and cause numbers
- Attorney bar numbers, badge and employee numbers
- Vehicle identification numbers and licence plates
- Employers, schools, hospitals and other organisations
- IP addresses and geographic coordinates
- Any value following a sensitive label on a form
- Marks that could not be read, including signatures
What is deliberately kept
Citations to published law — statutes, rules and reported cases — are not redacted. Blacking out 750 ILCS 60/214 removes no personal information and would make the document useless to whoever you are asking for help. Case captions containing party names are treated as names and are redacted.
Signatures and handwriting
Text recognition cannot reliably read handwriting, and SafeKopy does not claim to. Instead, marks it cannot read confidently are covered rather than trusted. This means signatures are generally blacked out, but SafeKopy cannot confirm what any given mark said.
Output characteristics
- Always a PDF, whatever the input.
- Same number of pages, same order, same page dimensions.
- Pages are images rendered at 200 dots per inch; text recognition runs separately at 300 dots per inch for accuracy.
- No metadata, no annotations, no attachments, no form fields, no fonts, no scripts.
- Anything that was visible on the original page — including a comment or a filled-in form field — is covered by detection, not by the rebuild. See above.
An accessibility cost. Because the output contains no text, it cannot be read aloud by a screen reader and cannot be searched. That is a real loss, and it is the direct price of making the redaction unrecoverable. We would rather state it plainly than hide it.
Limits
- PDF files only. Word documents are not supported yet — save them as PDF first.
- Up to 50 pages per document.
- Desktop and laptop browsers only. Phones and tablets are not supported.
- English text recognition only.
- Password-protected PDFs cannot be opened.
Open-source components
| Component | Purpose | Licence |
|---|---|---|
| PDF.js | Reading PDFs, extracting text positions, rendering pages | Apache-2.0 |
| Tesseract.js | Text recognition on scanned pages | Apache-2.0 |
| Tesseract English model | Text recognition data | Apache-2.0 |
| pdf-lib | Building the output PDF | MIT |
Every one of these is served from SafeKopy's own address. Nothing is loaded from a content delivery network or any third party, so no third party learns that you visited or what you did.
Browser security policy
SafeKopy is served with a restrictive Content Security Policy that permits connections only to its own origin, forbids inline scripts, forbids plugins and framing, and disables camera, microphone, geolocation and payment access. Policy violations are treated as test failures.
Reporting a security problem
If you find a way to recover redacted content, or any other security issue, please write to info@StatuteFINDER.org. We will respond and will publish a fix. Please give us a reasonable chance to correct the problem before disclosing it publicly.
Who provides this
SafeKopy is provided by Domestic Violence Statute FINDER (Domestic Violence Statute Finder), a 501(c)(3) nonprofit organization, EIN 99-1590831.
https://statutefinder.org · info@StatuteFINDER.org
SafeKopy is a privacy tool, not legal advice. It is not affiliated with or endorsed by any court, government agency, or artificial-intelligence provider. If your court has rules about what must be removed from a filing, follow those rules — a lawyer or legal aid office can help.