Redaction that destroys what it covers.
The redaction failures that make the news share one anatomy: a black rectangle drawn over text that was still in the file. Copy, paste, and the "redacted" names are on the clipboard. Courts have done it, law firms have done it, government agencies keep doing it, because most PDF tools treat redaction as decoration.
Blot treats it as demolition. Your document's pages are rendered to plain pixels, your ink is painted into those pixels, and a brand new PDF is built containing only the pictures. There is no text layer in the output because there is no text in it at all, no annotations, no form data, no attachments, no metadata, no earlier versions. The finished file is then reopened and re-checked in front of you: zero extractable text items, zero annotations, zero form fields, or you see exactly what survived.
Documents Blot cannot flatten honestly get refused with an explanation, not half-handled: password-protected files, filled forms, XFA, and digitally signed documents each get told why and what to do instead. The trade is stated plainly too: the output is a picture of a document. It prints and reads fine; it is not editable and not searchable. That is the cost of certain.
Android: install blot.apk on Android 9 or newer, with Android System WebView at Chromium 109 or later (Android 9 phones with Google Play keep this current by themselves; a stock, never-updated WebView is older than that). Below that version, Blot shows a plain screen asking you to update WebView instead of a blank page. It's not in the Play Store, so Android will warn you that it's blocking an install from outside the store; that warning exists for apps that misuse permissions, and Blot asks for none. Settings offers a one-time "install anyway," which is the only extra step. The same release link always points at the current version, so an updater like Tern can track it for you.
iPhone: open blot.munzzyy.dev in Safari, tap
Share, then "Add to Home Screen". Blot is not on the App Store; you can
also build the ios/ wrapper yourself with Xcode
(docs/IOS.md).
Anywhere else: open blot.munzzyy.dev. app/
is the whole web app, a static page with no build step and no server side,
so you can also serve your own copy from anything that can serve files.
npm test validates the PDF writer against poppler, a completely
independent implementation: image-only output must yield zero text to
pdftotext. npm run e2e goes end to end: a real PDF with a planted
secret goes in, ink goes over it, and the output is checked outside the
app three ways: pdftotext extracts nothing, the secret string exists
nowhere in the raw output bytes, and the re-rendered page is probed to
confirm the ink is really there. The APK requests no Android permissions,
not even INTERNET; its one manifest entry is androidx's self-scoped
not-exported marker, which grants nothing.
The web app has one dependency, on purpose: Mozilla's PDF.js reads the
input, vendored at a pinned version whose checksum is verified against
the npm registry. CI re-checks every vendored file's checksum on every
push; provenance and manual re-verification steps:
app/vendor/pdfjs/PROVENANCE.md. Everything else in the web app,
including the PDF writer, is dependency-free (the Android wrapper carries
the standard androidx runtime, like any modern app).
For development: node test/serve_local.mjs serves the web app, and
cd android && ./gradlew assembleDebug builds an installable debug APK
(release signing goes through tools/release-android.sh).
There is also a native iOS wrapper around the same app/, built with
Xcode from a generated project rather than a checked-in one. It has no
prebuilt release yet; Safari can install the hosted web app from
blot.munzzyy.dev instead. Details,
and exactly how the wrapper differs from the Android app:
docs/IOS.md.
What is left needs someone other than this repo's code: a store review or a native speaker.
- F-Droid. Blot is not in it yet. The store text and the per-version
changelogs it reads are in
fastlane/; the submission to fdroiddata and its review are still ahead. - The sha256 and signing certificate lines in the release notes. v0.3.0 and v0.5.0 have them; the v0.4.0 to v0.4.3 notes still need them added.
- A native speaker's read of the Spanish UI and store text. The move from "redactar", which means to write, to "tachar" was not checked by one.
Getting text, form data, or metadata out of a Blot output is the bug that matters; SECURITY.md has the private route for that. Everything else: issues and pull requests are open and welcome. Releases list the APK's sha256 and signing certificate digest.
GPL-3.0-or-later. You can use, study, change and share it. If you distribute a copy or a modified version, it has to stay under the GPL and come with its source. Releases up to v0.4.0 were under MIT. The vendored PDF.js is Apache-2.0.


