ONYRI Sanitize tutorial: anonymize your first document, step by step
Follow this illustrated ONYRI Sanitize tutorial: choose a file, review the masks, add what detection missed and download a flattened PDF.
In this ONYRI Sanitize tutorial, you anonymize one document from start to finish. Our example is a fictitious expense refund letter. You need a PDF, a Word file (.docx) or an image, and a browser on a computer or a phone.
Open the upload window and choose your file
Open the documents page and click “Anonymize a document”. In the window, drag your file in or click “Choose a file”. The app accepts PDF, Word (.docx) and images or scans, but not the older .doc format. A file dropped anywhere on the page skips the window: the analysis starts at once.

Then set two options. “Detection profile” starts on “Default”, which recognises the document’s country, so you can leave it. “Black marker” paints solid bars. The “Token” card swaps values for labels and needs Pro: on the Free plan, it shows a lock and a Pro label.
Click “Anonymize” and read the result
Click “Anonymize”. The app reads the file in your browser. A PDF with a text layer is read directly. A scan, an image or a PDF page without text goes through OCR on your device, which can take a few seconds.

Check three places. The file bar shows the count: “12 masked items” for our letter. The preview shows a black bar over each detected value. On a wide screen, the right column holds the Export panel, the recognised country and the “Detected data” list. Each value there has a label and a checkbox. Uncheck a box to leave that value visible.
On a computer with a mouse or trackpad, a name-recognition model also looks for person and company names. It runs on your device. The file bar then shows “looking for more names…”, and the Download button stays inactive for up to 90 seconds. Phones, tablets and slow or data-saving connections use the rules alone, as in our screenshots. On a computer, your count may be higher.
Mask what the rules missed
Detection is not complete. In our letter, “Nautilus” is a project code name, and no rule knows it. On a computer, the name-recognition model may read “Project Nautilus” as a company name and mask it. For a word that stays visible, use the bar above the page: choose “Select text”. Then highlight the word with your mouse, or tap it on a touch screen.

A bubble says that “Nautilus” appears 4 times. Click “Mask all 4 occurrences” to hide them all. In our letter, the file bar then reads 16 masked items. “Only this one” hides just the spot you selected. The bar above the page has more tools, and they work on every plan:
- “Draw an area”: drag a rectangle over a signature, a logo or a photo.
- “Search the document”: type a term, then mask all the results in one click.
- Click a mask and choose “Don’t mask” to remove it.
- “Undo” or Ctrl/Cmd+Z: take back your last action with these tools.
Detection does not find signatures, logos, stamps, faces, photos, barcodes, QR codes or handwriting. It also skips diagnoses in words, religion and salaries without a currency. Mask these by hand.
Switch to Token mode if readers must tell values apart
This step is optional and needs Pro. In the Export panel, under “Masking mode”, click “Token”. Each value becomes a label such as [NAME1] or [MAIL1]. An identical value gets the same label everywhere, so a reader can usually follow who is who. A variant is a new value: “Ms. Jane Example” and “Jane Example” get two labels.
![The same letter in Token mode: labels such as [NAME1], [MAIL1] and [+1] replace the values, and the file bar reads 16 masked items](/blog-photos/tutorial-token-en-960.webp)
A term you mask with “Also mask”, “Mask all N occurrences” or “Mask all N results” gets [+1], [+2] and so on. “Only this one” gives [M1], [M2]. A drawn area gives [Z1].
The Token card in the upload window says “Reversible”. That word means that whoever holds your original file can link each label back to its value. That is pseudonymisation. Article 4(5) of the GDPR defines it, and Recital 26 says such data remains personal data. The app has no restore button and no key file, and it keeps nothing after your session. Keep your original.
Check the preview, then download
Before you click “Download PDF”, read the preview as a stranger would. Then run through this list.
- Read every page. Each sensitive value should sit under a bar or a label.
- Scan “Detected data”. Uncheck any value that should stay visible.
- Look for a warning that a detected value could not be placed. That value is not masked, so mask it by hand.
- On a computer, wait until “looking for more names…” disappears.
- Click “Download PDF”.
The download is a new PDF built from page images. The masks are painted into the pixels, so there is no text layer and nothing hides under a bar. A Word file comes back as a PDF, and a single image as a PNG. The UK data protection authority (ICO) warns that text merely covered by a black shape stays in the file. That is why the export is flattened.
The file keeps its original name plus “-anonymized”, so rename it if the name is sensitive. The output is not searchable text. The app blocks the download if a page cannot be read or the document holds no readable text. Nothing would be masked there. Read the downloaded file once more before you share it.
Need the file again? The “This session” list keeps up to 5 documents, each with “Download again”. They live in memory only and vanish when you refresh the page.
Know the limits and the plans
ONYRI Sanitize reduces exposure. It does not guarantee anonymity or GDPR compliance, and the review stays yours. Detection is not exhaustive. OCR reads English, French and German, plus Spanish, Italian or Dutch if your browser uses one. Handwriting is not read.
| Feature | Free | Pro |
|---|---|---|
| Documents | 3 per day (resets at 00:00 UTC) | Unlimited |
| Pages per document | 10 | Unlimited |
| Masking mode | Black marker | Black marker and Token |
| Technical secrets (API keys, cloud tokens) | Not masked | Masked |
A document counts when it is anonymized, not when you download it. Pro costs €9.90 per month or €99 per year, excluding VAT (USD 11.90 or USD 119). It starts with a 7-day trial, for a first subscription only. You enter a card and nothing is charged today. The first payment comes when the trial ends, unless you cancel first. Team features are coming soon.
Frequently asked questions
Is my document uploaded to your servers?
No. The file stays in your browser. Only counters reach our server: the kind of document, the number of pages and the number of masks.
Can I get the original back from a Token mode file?
No. The app has no restore button and no key file, and it keeps nothing after your session. Only whoever holds your original can link a label to its value.
Is the downloaded file anonymous under the GDPR?
Not automatically. Masking reduces exposure but guarantees neither anonymity nor compliance. A job title or a rare event can still point to a person. Read the result as a stranger would.
Why did my download not start?
On a computer, the Download button stays inactive while the app looks for more names, up to 90 seconds. It also blocks the download when a page is unreadable or the document has no readable text. Try a sharper scan or another file.
Sources & references
- Regulation (EU) 2016/679 (GDPR), Article 4(5) and Recital 26EUR-Lex
- How do we avoid an accidental breach when redacting information?Information Commissioner's Office (ICO), United Kingdom
- EDPB adopts pseudonymisation guidelines (17 January 2025)European Data Protection Board
- L'anonymisation de données personnelles (in French)CNIL