Protest photos: a safety checklist before you share

In 2020, face-blurring went from a niche journalist skill to a mainstream expectation in the space of a month: Signal added a blur tool to its camera, digital-rights groups published how-tos, and news organizations debated showing protesters’ faces at all. The underlying logic hasn’t changed since. Photos are how protests are seen and remembered; they’re also, with modern face search, how attendees get identified — by employers, by opponents, by anyone motivated. If you photograph and share crowds, this checklist is for you.

It’s written to be honest rather than comforting: some of it is about what blurring cannot do.

Step 1: decide before you share, not after

The only redaction that fully works is the one applied before a photo exists anywhere else. Once an unblurred version is posted — even briefly — screenshots and archives exist outside your control. The workflow that survives contact with reality: photos go from your camera roll through a redaction pass, and only the redacted exports get shared, posted or sent to group chats. Nothing sensitive goes out raw “just to one person”.

Remember also that your camera roll itself syncs: if your phone backs up to a cloud account, the unblurred originals live there under that account’s security, not your intentions. For genuinely sensitive material, that’s worth thinking about independently of what you post.

Step 2: blur faces — properly

Two properties separate real anonymization from decoration:

Blur the faces of people who haven’t chosen to be identified. People speaking at the microphone, organizers who publish under their names, or people who’ve asked to be shown are a different call — that’s editorial judgment, not a technical rule.

Step 3: know what face blurring doesn’t hide

An honest list, because overconfidence gets people hurt:

None of this argues against blurring faces — it argues against stopping there when someone’s safety is the point. The black box works on a backpack exactly as well as on text.

Step 4: strip the metadata

Phone photos embed GPS coordinates, capture time and device identifiers in their EXIF data — for a protest photo, that’s where you stood, to the minute. Major social platforms strip EXIF from public copies, but direct sends (email, messaging apps in original quality, cloud links) usually don’t, and the platform itself reads the data before discarding it. Every export from this site is re-encoded with no metadata at all, automatically; the metadata guide explains how to verify that on any photo.

Step 5: use a tool that can’t collect what it processes

For most photo edits, where the processing happens is a detail. For protest photos it’s the threat model: a server-side “free blur tool” receives, however briefly, an unblurred archive of who attended — exactly the dataset nobody should be assembling. The fix isn’t finding a tool with a nicer privacy policy; it’s using one where upload is architecturally impossible. BlurLocally is a static site: detection runs in your browser, there is no endpoint to receive a photo, and the tool works with your connection off — the two-minute verification shows how to confirm that yourself, here or anywhere.

The checklist, compressed

  1. Redact before anything is shared anywhere; keep originals off auto-sync if they’re truly sensitive.
  2. Auto-scan, then manually review every face in every row. Strength high.
  3. Box non-face identifiers on people who matter: tattoos, distinctive clothing, held signs and screens.
  4. Export through a metadata-stripping path (automatic here).
  5. Reread your caption as an adversary would.
  6. Post the export, never the camera-roll original — and never a screenshot of the original.

The pattern in all six: the pixels are only part of the photo. What identifies people is the whole object — image, file, words — and it takes about three minutes per photo to handle all three. For photos of people exercising rights they may pay for later, that’s cheap.