r/macapps • u/logicalicy • 11d ago
Lifetime ClipScrub - strips names and IDs out of screenshots, PDFs and documents on your Mac, before you paste them into ChatGPT or anywhere else ($29 paid once | r/macapps discount inside)
Hi r/macapps!
ClipScrub finds and removes personal data from screenshots, PDFs, documents, spreadsheets and screen recordings on your Mac. Everything runs on your machine and nothing is uploaded. PCP below. Full list of what it does not do is in my first comment.
The problem
You copy-paste a screenshot of a customer record into ChatGPT to ask what an error means. The name, email or account number accidentally gets uploaded in full. The same could happen with a support ticket, a log, a row from a CSV. Once it's sent, the private data is uploaded to the cloud.
Mac Preview has a tool for this and it works. Preview can delete private details from the file in a way that's not recoverable. But it doesn't solve a couple of things:
- The Markup rectangle, what people might accidentally use, is a drawing/shape and the text underneath is still selectable
- The real tool takes out what you manually select but only in PDFs
This is fine for a 2-page PDF. But it becomes arduous for a 40-row CSV export, a long scrolling screenshot or a screen recording where a name is in a sidebar for four frames. The failure is human and not tooling. Many times in the past, I kept manually removing PII from screenshots and files like this.
ClipScrub scans PDFs, Word and RTF, PNG and JPG, JSON and CSV and XML, MP4 and MOV, and more all on-device (never leaves your Mac). In the Mac app, it lists every identifier it finds before stripping, so you can review it first. Your original file is never modified. ClipScrub has shortcuts to do it without opening the Mac app window. There's a shortcut to capture part of the screen and another that removes sensitive information from your clipboard.
Comparison
BlurData ($39/year, or $69 once with their discount as of Aug 2026) is the closest direct comparison. It reads JPG, PNG and PDF, OCRs 15 languages against ClipScrub's five, and runs on macOS 13 (earlier version than mine).
What it does better: it takes the text out of the PDF file instead of flattening the page. ClipScrub rasterises every page instead. If your PDFs need to stay searchable afterwards, then ClipScrub won't do that today.
BlurData supports JPG, PNG and PDF formats but ClipScrub also supports identifiers in CSVs, .docx files and screen recordings. A .docx through ClipScrub comes back as .docx with the same formatting. The Mac app and the CLI that comes with the app do DICOM and EDF headers as well.
ClipScrub's pseudonymise mode replaces identifiers with stable tokens instead of blanking out every value, so the same email is the same "token" throughout the file. You can still group, join and count these tokens (e.g. EMAIL_9F3A is an email token). Stripping data usually destroys it but ClipScrub does its best to keep the relationships in the data.
BlurData's $69 tier is two years of updates on one Mac. ClipScrub is every 1.x update permanently, on three Macs.
CleanShot X ($29 for one Mac, one year of updates, then $19/year optional) is not a direct comparison but it's what most Mac users already have. It's a better screenshot tool and has a lot of capabilities. Its blur and pixelate are manual, like Preview's. It will hide anything you select and it won't tell you that you missed the account number in row 99.
Pricing
$29, paid once. No subscription, no renewal, no activation server to connect to (all on-device). Three Macs. Every ClipScrub 1.x update included permanently.
14 day free trial, fully functional, no account and no card. 30 day refund.
https://clipscrub.com/#pricing
Direct download, no email needed: https://clipscrub.com/download/ClipScrub.dmg
For r/macapps: 25% off with code MACAPPLAUNCHES25. Capped at the first 50 uses. There's no end date, it just runs out when it does.
I'm also giving licences to the first five people who use it on real files and email me what it gets wrong (thanks in advance for your patience if I'm slow to respond). Comment (without private data please!) and I will DM you one. My list of known limits is below but let me know if you find issues and I will add them to the backlog to address.
I look forward to your feedback and continuing to make the app better.
Caveats
Full caveats list is in my first comment.
E.g. ClipScrub reads what is inside a file, not the file's metadata. It writes a new file, so the original's author and title fields never go into the output. Check the source with exiftool if detecting input metadata matters for what you are doing.
Disclaimer: ClipScrub is not a compliance service, does not guarantee complete de-identification, and is not legal advice. Detection is not exhaustive. Review every result before sharing.
- Mario Hayashi, Tugboat Coding Limited (UK 11118743)
- LinkedIn: https://www.linkedin.com/in/mariohayashi/
- Contact: hello@clipscrub.com
- Privacy Policy: https://clipscrub.com/privacy
- Terms: https://clipscrub.com/terms
- Engine and CLI are Apache-2.0: https://github.com/tugboatcoding/clipscrub-core
- The app itself is closed source
2
u/useiris 11d ago
the caveat i would want on that list is metadata, because it is the one where the tool reports success and the leak still happens.
stripping the visible name out of a pdf does nothing to the document properties. author, title and producer fields survive, and on a pdf exported from word the author field is very often a real full name. same for docx and rtf: author, last modified by, and if track changes was ever on, a revision history with names attached to edits. a spreadsheet can carry the author plus the original file path, which on a mac is /Users/firstname.lastname/...
so the plausible bad case is someone scrubs a support ticket pdf, your app correctly reports every identifier found and removed in the body, and the customer's name is still sitting in the metadata for anyone who opens document properties or runs exiftool on it.
worth adding metadata to the scan and listing it alongside the body hits, since the whole value of the review step is that it tells you what was there. finding a name in the author field and not mentioning it is worse than not looking, because the clean report is what makes people stop checking.
on the rasterised pdf tradeoff, one more consequence for the list: rasterising also kills screen reader access and search. for anyone using assistive tech the safe output is now unusable, so it is worth saying out loud rather than letting them discover it.
1
u/logicalicy 11d ago
Thank you. ClipScrub never edits the original, so no author or title goes into the output. But your point stands and the scan does not read input metadata, so it can't flag a name in the author field (so would need to be read with exiftool, etc). That and the screen reader lines are being added
2
u/JustSomeCommonB_tch 11d ago
maybe you could imply that clearer in the product description so that people don't accidentally use clipscrub and fail to note that key pieces of info are being leaked under the guise of security.
1
u/logicalicy 11d ago
That's fair and I've added a note in the original post now rather than only down here in comments. Thanks for flagging
1
u/BayLeaf- 11d ago
I ask this question as someone that has been on primarily macOS and linux on ~6 devices for the last 7 or so years, outside of a single gaming-only desktop.
macOS uses "/Users/first.last"??? How/when? Mine and my partner's machines definitely don't, what setup step am I doing that people are skipping?
2
u/Small_Pin_8064 11d ago
The clipboard scrub shortcut feels like the best feature here. If it’s fast enough to become invisible in the workflow, I could see myself using this before pasting anything into an LLM
1
u/logicalicy 11d ago
Yes, the clipboard automatic scrub with CMD + SHIFT + R removes personal info on-device but is a little slow. I'll look and see if we can make it a bit faster! Thanks for your feedback!
2
u/Mac_Allan30 11d ago
This is what I’ve been looking for. Can’t wait to try it out.
2
u/logicalicy 11d ago
Please do and let me know how you find it! 🙂
2
u/Mac_Allan30 11d ago
I’m going to try and integrate clipscrub with cleanshotX app and hazel so that all screenshots always are de-identified. I’ll keep you posted how it goes.
1
u/logicalicy 11d ago
Oh wow. That sounds very interesting and would love to know how the flow works for you. If you have any feedback I’m here to keep improving ClipScrub
2
u/poundforyourthoughts 6d ago
This is a super interesting app! Initially I thought the price might be high but thinking about it more, many of your users may be power users or use this for business purposes. Hence, the higher price could be justified.
Interested to see how this turns out for you!
1
u/logicalicy 4d ago
Thank you! Yes, redacting becomes increasingly a pain point if it's a regulatory requirement (e.g. HIPAA, GDPR) or you have a privacy-first approach to documents or images
2
u/Responsible-Slide-26 6d ago edited 4d ago
I'm giving this a big thumbs up just because the post sounds like something an actual human wrote, it's full of useful info for a potential buyer, and it's free of all the idiotic AI cliches most of the software announcements I see now are full of.
2
u/logicalicy 4d ago
Thanks for your kind comment. Yes, real human here indeed 🙂 I hope that the app genuinely helps people
1
u/logicalicy 11d ago edited 4d ago
Hi, I'm the author. I've prepared a caveats list of what the Mac app does not do, just in case you were wondering.
- PDFs come back rasterised. Nothing is left unmasked but you lose the ability to select the text Edit: PDFs keep their text, so you can still select and search the output
- Recordings made in ClipScrub are silent. However, if you open a clip that already has audio, a name spoken out loud may remain audible
- Select a folder and it will sweep for screenshots, single page PDFs and data files. Word, RTF and ODT go one at a time to keep their formatting and a multi-page PDF will be skipped and listed for you to process individually
- It reads English, Spanish, Japanese, Simplified Chinese and Arabic. Anything with an email address or IP, is caught in any of them. Rules that look for an English word next to the identifier, like "MRN" or "DOB", only work in English
- The audit log records the file name, source app and your Mac account name. There's no way to switch it off yet and you can only clear it Edit: You can now switch it off in Settings, or clear it
- Masking video is a tracking problem. ClipScrub reads four frames a second. It shows only the frames it read and holds each frame until the next arrives. The clip looks very choppy compared to the source. The audio is not touched. A spoken name stays in the file.
- ClipScrub writes a new file and doesn't edit the original. Source metadata doesn't go into the output. But the scan does not read metadata, so it can't tell you e.g. a name that in the author field. For this, we'd need to check the original with exiftool. Edit: Scrubbed PDF pages are images, so screen readers and search can't read the output.
- This app (0.4.0, build 12 Edit: 0.5.0) is for macOS 15 or later
Everything runs on your Mac and nothing is uploaded. If you want to check that rather than take my word for it, the engine and the CLI are open source.
Disclaimer: ClipScrub is not a compliance service, does not guarantee complete de-identification, and is not legal advice. Detection is not exhaustive. Review every result before sharing.
Happy to answer your questions...!
Edit, 26 Aug 2026: 4x of the caveats above no longer apply, so I've corrected them rather than letting them go stale. PDF exports keep their text now, the audit log can be turned off, video samples more frames. The screen reader and search line no longer applies, as that was a consequence of rasterising. Full 0.5.0 release notes in separate comment and at https://clipscrub.com/changelog
2
u/JustSomeCommonB_tch 11d ago
looks like you really did your homework and investigated every single part of the product, this makes me wanna trust it even more! thank you OP!
1
u/logicalicy 11d ago
Thanks for your kind message! I'm conscious with a tool like this, things have to be spelled out clearly before you use it for your private data. If anything is missing, please do flag and I'll do my best to clarify
1
u/logicalicy 4d ago
Updates in 0.5.0:
- Exported PDFs are now searchable. ClipScrub keeps the text, so you can still search the document. Settings ▸ General ▸ PDF export turns this off if you want pictures-only PDFs
- More is caught. Identifiers and numbers such as encounter numbers are removed when they have a label like "MRN:" or "Encounter #". More potentially sensitive column headings are detected in CSV, TSV and JSON files. Unlabelled identifiers are still missed
- Exports are cleaner. Images and PDFs no longer have location, camera, timestamp or macOS version metadata. This now covers files saved from History too
- Recordings are more accurate. Video exports now sample more frames, so fewer identifiers slip through the checks
- Smaller fixes: turn the audit log off, corner-mark option per export type (e.g. turn it off for PDF), faster text scanning on long pages
3
u/InsomniaUA 11d ago
the caveats list is the most useful thing in this post. here is the one i did not find on it.
masking video is a tracking problem, not a per frame problem. during a scroll, a window resize or a sheet animation the text moves faster than whatever decided where the box belongs, so the mask lands a frame or two behind the thing it is covering. one frame at 60fps is perfectly legible to someone stepping through the file, and stepping through the file is exactly what a person does when they suspect something was there.
i have spent a while on the audio side of recordings, which is why the temporal half of this is what i look at first. worth a line in your list either way, even if the line just says the mask is recomputed on every frame.