How to Redact a Bank Statement Before Sharing It With Landlords or Lenders

When a landlord asks for proof of income or a lender requests three months of statements, they are checking two things: that the account is yours and that the balance or salary deposits are real. They do not need your full account number, your card transactions at the pharmacy, transfers to family members, or the merchant names that reveal where you shop and eat. Every extra line you hand over is data you can never take back, and rental applications are routinely forwarded, printed, and stored in unsecured inboxes for years.

The most common mistake is fake masking. People draw a black rectangle over the account number in an annotation tool, export the file, and assume the text is gone. It is not. An annotation sits on a layer above the text; anyone can select the hidden characters and copy them out, or simply delete the rectangle in an editor. The same trap applies to highlighting text in black or changing the font color to match the background. If the text still exists in the file, it is recoverable in seconds.

True redaction removes the underlying content itself. PdfWill's redact tool works this way: you mark the regions to remove, and the tool strips the text and image data beneath the marks before flattening the area into a solid block. After redaction, try selecting the blacked-out region — there should be nothing to copy. This is the diagnostic test you should run on any redacted document before sending it, whether you made it or received it.

For a document this sensitive, where the processing happens matters as much as how. Uploading an unredacted bank statement to a cloud service means the complete file, account numbers included, travels to someone else's server before the sensitive parts are removed. PdfWill runs entirely in your browser: the statement never leaves your device, nothing is uploaded, and closing the tab destroys the working data. That is the correct order of operations — redact locally first, share second.

A sensible workflow looks like this: download the statement, use redact to permanently remove account numbers and irrelevant transactions, keep only the deposit lines the reviewer actually needs, then run the file through protect to add AES encryption with a password you share through a separate channel. If you also want to note which deposits are salary, use the annotate tool to add labels — annotations are fine for adding context, just never for hiding it. Keep your original untouched copy in your own records.

Related tools