Document properties and metadata
Every PDF can store details that most people never look at.
- What the properties hold: These include a title, an author, a subject and keywords. They also include the app that created the document, the software that made the PDF, and the dates it was created and changed.
- The XMP stream: Many files also carry an XMP stream, a block of XML that repeats those details and can add more, like editing history or the organization name from a software license.
- Invisible on the page, readable in a viewer: None of it appears on the page, yet anyone can read it in a viewer's document properties. The classic embarrassment is a template: a proposal sent to one client whose title still names another.
- Clearing it: Remove Metadata clears both the properties and the XMP stream, and View / Edit Metadata lets you set a clean, deliberate title for documents you publish.
Text that's covered but not removed
- Black boxes hide nothing: The most damaging PDF leaks rarely involve hacking. They happen when someone draws a black rectangle or a heavy highlight over sensitive text and assumes it's gone. The shape hides the words visually, but the text underneath is still in the file: it can be selected, copied into another document, found with search or revealed by moving the shape aside.
- It has happened in public: Court filings and official reports have exposed information this way more than once.
- What proper redaction does: Proper redaction works differently, deleting the content inside the marked area before filling it with black. Redact PDF removes the text inside each area and blanks the image pixels beneath.
- Verify before you send: Whatever tool you use, verify the result: search the redacted file for the words you removed, and try selecting across the black areas. If anything highlights, the content is still there.
Content outside the visible page
A page can hold more than it shows.
- Cropping only sets a box: Cropping a PDF sets a visible box, but everything outside that box stays in the file, where anyone with an editor can expand the page and see it again.
- Other unsafe hiding places: Designers sometimes leave notes or alternative versions just outside the page edge. Text can be colored white on a white background, shrunk to an unreadable size, or placed in an optional layer that's switched off. None of these are safe ways to hide anything.
- Crop is for margins: Crop PDF is useful for trimming margins, not for concealment.
- Flattening leaves it behind: If you need a copy with only what you can see on each page, use Flatten PDF. It turns every page into an image and rebuilds the document from those images. Hidden layers, content off the page and invisible text are left behind.
Comments, tracked history and form entries
- Review comments travel: Review comments often travel further than intended. Sticky notes can be collapsed so they're easy to miss, and every annotation may carry the reviewer's name and the time it was made.
- Tracked changes from exports: Documents exported from word processors can include comments or tracked changes depending on the export settings, exposing earlier wording that was deliberately removed.
- Form field values: Forms are another source: values typed into fields remain in the file, including fields that were later hidden or cleared visually in some viewers.
- Fix it in the source: The safest approach is to resolve comments and accept or reject tracked changes in the original document before exporting it.
- If all you have is the PDF, flattening turns visible comments and form values into part of the page image and drops the editable versions. Delete any comments you don't want shown before you flatten.
Photos and scans carry their own details
Images embedded in a PDF can reveal things the page doesn't.
- EXIF in photos: Photos taken with phones and cameras often contain EXIF data. It can include the device model, the date and time and sometimes GPS coordinates.
- Why it survives conversion: When a JPEG goes into a PDF without being re-saved, its original data can come along. VelloDoc's own JPG to PDF keeps standard JPEGs unchanged to protect quality. So if it matters, remove location data from your photos before you convert them.
- Cropped images keep the full picture: Cropping an image inside a layout program usually stores the full picture and merely hides the edges, so Extract Images can bring the uncropped original back.
- Scans capture the whole glass: Scans capture everything on the glass, including sticky notes and neighboring papers.
- Flattening rebuilds the pages: Flattening creates new page images without the original image data or its metadata.
Attachments, links and bookmarks
- Files attached inside: Some PDFs contain whole files attached inside them, from spreadsheets supporting a report to earlier drafts bundled into a portfolio, and those attachments are easy to overlook in many viewers.
- Links and bookmark titles: Hyperlinks can reveal internal system addresses or carry tracking parameters, and bookmark titles sometimes preserve working labels like "draft, don't send".
- What flattening drops: Removing metadata doesn't affect any of these. Flattening produces a new document built only from page images, so attachments, links and bookmarks aren't carried over, although links also stop working.
- Check before sharing: For documents where these details matter, check the attachments and bookmarks panels in a full PDF viewer before sharing, and rebuild the PDF from a cleaned source when possible.
Access control is a separate layer
- Encryption answers a different question: Passwords answer a different question from everything above. Encryption controls who can open a document. It does nothing about what the document reveals to people who can open it.
- What Protect PDF does: Protect PDF encrypts a file with AES-256, which is strong protection against anyone who doesn't have the password, provided the password itself is strong and shared through a different channel from the file.
- Password holders still see everything: But every recipient who has the password sees the hidden metadata, the covered text and the uncropped images too. Treat protection as the final step that limits who receives a document you have already cleaned, never as a substitute for cleaning it.
A pre-sharing checklist
Work from content toward access.
- Send only what's needed: First decide what the recipient actually needs, and remove or extract everything else with Remove Pages or Extract Pages.
- Resolve comments in the source: Resolve comments and tracked changes in the source file if you have it.
- Redact, then remove metadata: Redact sensitive areas properly, then remove metadata.
- Flatten for the strongest result: For the strongest result, flatten the document so only visible content remains.
- Protect the file last if it should be limited to specific people.
- Verify what a reader can extract: Then verify: search for redacted terms, check the document properties, and extract the text with PDF to TXT to see exactly what a reader could copy out.
- Where to read more: Files processed on VelloDoc are handled in a temporary folder that's deleted after the download, as described on the file security page. The guide to security tools covers each tool in detail. The step-by-step guide to removing metadata before sharing goes further into document properties.
Questions
Can someone see what I blacked out in a PDF?
Yes, if the black box is only a shape drawn over the text. The words underneath can be selected or searched. Use real redaction, then search the result to confirm the text is gone.
Does exporting to PDF remove Word comments and tracked changes?
Not necessarily. It depends on the export settings. Resolve comments and accept or reject changes in Word before creating the PDF.
Can photos in a PDF contain location data?
They can, if the original photo contained GPS data and was embedded without re-encoding. Remove location data before converting, or flatten the PDF to create new page images.
Is a password-protected PDF private?
Only from people who don't have the password. Anyone who can open it can see all of its content and metadata, so clean the document before protecting it.
What's the safest way to share part of a document?
Extract only the pages needed, redact sensitive areas, remove metadata and flatten the result, then protect it if access should be limited.