Black marker or Token mode: which one should you choose?
Black marker hides a value for good. Token mode swaps it for a label like [NAME1]. When each mode fits, what the GDPR says, and which plan has it.
Choose Black marker when the copy leaves your hands for good: a disclosure, a publication, an exhibit. Choose Token mode when someone still has to follow the story, such as a colleague, an auditor or an AI assistant. Black marker paints an opaque bar over each value. Token mode writes a label such as [NAME1] in its place.
Both are masking modes of ONYRI Sanitize, a web app that handles PDFs, Word files, scans and images inside your browser. Both produce a flattened file with nothing hidden under the masks. Black marker is in every plan. Token mode is a Pro feature.
What does each mode put on the page?
Take a line from a fictitious loan letter: Jane Example will repay John Sample by transfer to IBAN GB00 0000 0000 0000 0000 00. With Black marker, both names and the account number become solid bars. This cannot be undone. The reader sees that something was removed, not what it was.
With Token mode, the line reads: [NAME1] will repay [NAME2] by transfer to IBAN [IBAN1]. Each label gives the type of value and a number. The sentence still makes sense. You know one person owes another. You do not know who.
| Point | Black marker | Token mode |
|---|---|---|
| What replaces the value | An opaque black bar | A label such as [NAME1] or [IBAN1] |
| What the reader learns | That something was removed | The type of value, and which mentions match |
| GDPR reading | Masking. Anonymity depends on what is left | Pseudonymization. Still personal data |
| Plan | Every plan, including Free | Pro and Team |
Which mode fits your use case?
Ask one question: must the reader tell the people apart? If not, use Black marker. It reveals the least. If yes, use Token mode, and treat the copy as personal data.
| Use case | Mode | Why |
|---|---|---|
| Access request when the file names other people | Black marker | The requester should not learn who they are |
| Publishing a report, a decision or minutes | Black marker | A public copy is out of your control |
| Exhibit for an opposing party or an insurer | Black marker | Irreversible. Nothing extra is revealed |
| Contract given to an AI assistant for a summary | Token mode | It must follow who owes what to whom |
| File sent to an outside expert for analysis | Token mode | The expert needs roles, not identities |
Why do consistent labels matter?
In Token mode, the same value gets the same label across the whole document. If Jane Example is [NAME1] on page 2, she is still [NAME1] on page 40. John Sample stays [NAME2]. A reader, or an AI assistant, can follow a long contract without mixing up the parties.
Two cautions. The rule works on identical values: if a name is spelled two ways, check the preview. And it covers one document. [NAME1] in another file may be someone else.
Is Token mode anonymization under the GDPR?
No. It is pseudonymization. Article 4(5) of the GDPR defines it as processing personal data so that it can no longer be attributed to a specific person without additional information, kept separately. Here, that information is your original file. Under Recital 26, such data is still information on an identifiable person. The GDPR applies.
It is still worth doing. Recital 28 says pseudonymisation can reduce the risks to the people concerned. Opinion 05/2014 calls it a useful security measure, but not a method of anonymisation. Guidelines that the European Data Protection Board adopted for public consultation in January 2025 say it again: pseudonymised data remains personal data.
Black marker is not a legal status either. The values are gone, but a rare job, a small town or a unique event may still point to someone. Opinion 05/2014 made the point for datasets: if you keep the original and hand over a part with identifiers masked, the result is still personal data. The app calls the feature Anonymize a document. That is everyday language. In GDPR terms, you get a masked or a pseudonymized copy.
What do both modes have in common?
- A flattened export: a PDF or PNG made of images, with no text layer and nothing under the masks. A Word file comes back as a PDF. The UK ICO warns that text merely covered by a black rectangle stays in the file.
- Work done in your browser. The file is never uploaded. The server only receives counters (documents, pages, masked items) to apply your plan.
- The same detection for a given plan: about 40 detectors in 6 families, plus your custom rules and one-off terms under Also mask. Technical-secret detectors need Pro.
- A preview you review item by item before you download.
- No way back. Neither mode can restore the original. Keep your original file.
Know the limits. Detection is not exhaustive. There is no detector for medical terms, salaries as such, or company names: add them yourself. Scans go through on-device OCR (English, French, German). It is slower, and accuracy depends on scan quality. Handwriting is not read. Masking reduces exposure. It does not, by itself, make a document anonymous or make you compliant with the GDPR.
Which plan includes Token mode?
As of September 2026, Token mode comes with Pro: €9.90 per month or €99 per year, excluding VAT (USD 11.90 or USD 119). Pro also brings unlimited documents and pages, technical-secret detectors (API keys, cloud tokens) and unlimited custom rules and profiles. It starts with a 7-day trial. Your card is on file, and nothing is charged when the trial starts.
Team costs €24.90 per user per month or €249 per user per year, excluding VAT (USD 28.90 or USD 289), with 3 seats minimum. Each seat gets Pro and priority email support. A shared workspace, invitations, roles and audit logs are not available yet. Free keeps Black marker, base detectors and 3 custom rules.
Frequently asked questions
- Can I turn a Token mode copy back into the original?
- No. Neither mode has a restore feature, and the export carries no hidden text and no key. To know who [NAME1] is, you need your original file. Keep it where only the right people can open it.
- Is a Black marker copy anonymous?
- Not automatically. The rest of the text can still identify someone. Read the copy as a stranger would, and mask the job title, the place or the date if they give the person away.
- Can I send a Token mode copy to an AI assistant?
- Token mode was built for this: the assistant follows roles, not identities. But for you, the copy stays personal data, because you hold the original. The UK ICO says the same of anyone who holds the additional information. For a recipient, it may differ. In EDPS v SRB (C-413/23 P, 4 September 2025), a case under the rules for EU bodies, the Court of Justice held that pseudonymised data is not necessarily personal data for everyone. Check the assistant's terms and your confidentiality duties first.
Sources & references
- Regulation (EU) 2016/679 (GDPR), Article 4(5), Recitals 26 and 28 — EUR-Lex
- Opinion 05/2014 on Anonymisation Techniques (WP216), adopted 10 April 2014 — Article 29 Data Protection Working Party
- EDPB adopts pseudonymisation guidelines (17 January 2025) — European Data Protection Board
- Anonymisation guidance: Pseudonymisation — Information Commissioner's Office (ICO), United Kingdom
- Disclosing documents to the public securely: how do we avoid an accidental breach when redacting information? — Information Commissioner's Office (ICO), United Kingdom
- Judgment of 4 September 2025, EDPS v SRB, C-413/23 P — Court of Justice of the European Union (EUR-Lex)
Mask a document without uploading it
ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.