Protest photos: a safety checklist before you share
In 2020, face-blurring went from a niche journalist skill to a mainstream expectation in the space of a month: Signal added a blur tool to its camera, digital-rights groups published how-tos, and news organizations debated showing protesters’ faces at all. The underlying logic hasn’t changed since. Photos are how protests are seen and remembered; they’re also, with modern face search, how attendees get identified — by employers, by opponents, by anyone motivated. If you photograph and share crowds, this checklist is for you.
It’s written to be honest rather than comforting: some of it is about what blurring cannot do.
Step 1: decide before you share, not after
The only redaction that fully works is the one applied before a photo exists anywhere else. Once an unblurred version is posted — even briefly — screenshots and archives exist outside your control. The workflow that survives contact with reality: photos go from your camera roll through a redaction pass, and only the redacted exports get shared, posted or sent to group chats. Nothing sensitive goes out raw “just to one person”.
Remember also that your camera roll itself syncs: if your phone backs up to a cloud account, the unblurred originals live there under that account’s security, not your intentions. For genuinely sensitive material, that’s worth thinking about independently of what you post.
Step 2: blur faces — properly
Two properties separate real anonymization from decoration:
- Strength. A face at close range needs to be destroyed, not softened — research has shown lightly blurred faces being re-matched by machine learning. On this site’s protest preset, strength starts at 9; the blur is a downsample, so the face’s pixels are discarded, not smeared, and can’t be recovered from the export.
- Coverage. Automatic detection is a first pass, and crowds are its hardest case: masks, profiles, raised arms, motion blur. This site scans in overlapping tiles specifically to catch small background faces, and it will still miss some. Zoom across every row of the crowd and drag manual boxes over what the scan missed. The thirty seconds of review is the anonymization.
Blur the faces of people who haven’t chosen to be identified. People speaking at the microphone, organizers who publish under their names, or people who’ve asked to be shown are a different call — that’s editorial judgment, not a technical rule.
Step 3: know what face blurring doesn’t hide
An honest list, because overconfidence gets people hurt:
- Tattoos, birthmarks, scars. Highly identifying, frequently visible, rarely blurred. Box them on people who are the subject of the photo.
- Clothing and gear. A distinctive jacket plus a public social account wearing the same jacket is an identification. So are printed shirts, flags and bags.
- Context. Who someone stands next to, what corner they’re on, what time the light says it is. A small crowd narrows candidates fast.
- Gait and body shape have been matched in research conditions. Rare in practice, real in principle.
- Your caption. Names, handles, “my friend at the front” — text undoes pixels instantly.
- Signs and screens. A held phone or a sign with a phone number identifies its owner in full resolution.
None of this argues against blurring faces — it argues against stopping there when someone’s safety is the point. The black box works on a backpack exactly as well as on text.
Step 4: strip the metadata
Phone photos embed GPS coordinates, capture time and device identifiers in their EXIF data — for a protest photo, that’s where you stood, to the minute. Major social platforms strip EXIF from public copies, but direct sends (email, messaging apps in original quality, cloud links) usually don’t, and the platform itself reads the data before discarding it. Every export from this site is re-encoded with no metadata at all, automatically; the metadata guide explains how to verify that on any photo.
Step 5: use a tool that can’t collect what it processes
For most photo edits, where the processing happens is a detail. For protest photos it’s the threat model: a server-side “free blur tool” receives, however briefly, an unblurred archive of who attended — exactly the dataset nobody should be assembling. The fix isn’t finding a tool with a nicer privacy policy; it’s using one where upload is architecturally impossible. BlurLocally is a static site: detection runs in your browser, there is no endpoint to receive a photo, and the tool works with your connection off — the two-minute verification shows how to confirm that yourself, here or anywhere.
The checklist, compressed
- Redact before anything is shared anywhere; keep originals off auto-sync if they’re truly sensitive.
- Auto-scan, then manually review every face in every row. Strength high.
- Box non-face identifiers on people who matter: tattoos, distinctive clothing, held signs and screens.
- Export through a metadata-stripping path (automatic here).
- Reread your caption as an adversary would.
- Post the export, never the camera-roll original — and never a screenshot of the original.
The pattern in all six: the pixels are only part of the photo. What identifies people is the whole object — image, file, words — and it takes about three minutes per photo to handle all three. For photos of people exercising rights they may pay for later, that’s cheap.