← Home
TOOL

Published · Updated

Blur Faces, License Plates and Private Details in a Video

Say what to hide and for how long. The agent measures the region off your real frames and covers it — softly, as a mosaic, or as a solid black bar.

To blur a face or a license plate in a video, upload it to Valmera and type where the thing is and when: "blur the face of the man on the left for the whole video", or "black out the license plate from 0:12 to 0:20". The agent looks at actual frames of your footage, reads the rectangle off a coordinate grid drawn on them, and burns a blur, a mosaic or a solid fill over that region. The censor lives in coordinates of your original frame, which is why it survives a later crop to 9:16 without sliding off the thing it was hiding. What it is not is a face detector: the region is fixed to a part of the picture, so a subject who walks across the frame needs a wider region or a second sentence.

Censor a Face or a Plate Free

No masks, no keyframes, no tracker. Describe what to hide and check the preview.

Try it free →
See pricing →

How to Blur a Face or License Plate in a Video

  1. 1
    Upload the footage
    Drag in any MP4, MOV, MKV or WebM up to 14 GB or 3 hours. Valmera runs a one-time analysis — a word-level transcript, silence and shot detection, and labeled frame tiles the agent reads directly — so it can already see who is in shot before you describe anything.
  2. 2
    Say what to hide, where, and for how long
    Name the subject, the part of the frame, the style and the span: "blur the face of the person on the left for the whole video", "pixelate the license plate at 0:42", "black out the bottom-right corner from 5:10 to 5:30". Anything you leave out the agent will either look for in the frames or ask you about.
  3. 3
    Check the preview at the covered moment
    The agent renders a preview and looks at the frames it produced, but you are the one who knows what must not be visible. Scrub to the moment and check the edges. Corrections are one sentence: "a bit lower", "make it wider", "make that a black box instead of a blur", "keep it up for the rest of the video".
  4. 4
    Export
    Export a full-quality H.264 MP4 rendered from your original upload. The censor is burned into the exported picture — there is no layer a viewer can peel off, and no metadata that describes what was underneath.

The one-time analysis runs with visible progress and is longer on long videos. Every censor after that is a chat message and a render.

EXAMPLE PROMPTS
  • "blur the face of the person on the left for the whole video"
  • "black out the license plate from 0:12 to 0:20"
  • "pixelate the customer name in the CRM sidebar for the whole recording"
  • "there are two people at the back table — blur both of their faces"
  • "make that a black box instead of a blur, and make it wider"
  • "also cut the two seconds where he says her surname"
Why a censor placed on the output frame slides off after a reframeTwo rows, each starting from the same 16:9 frame with a face on the left and a censor box over it. In the top row the censor belongs to the output frame, so when the video is cropped to a 9:16 vertical shape the picture shifts underneath the box and the face is exposed. In the bottom row the censor belongs to the source frame, so it is burned into the footage before the crop and the box and the face move together.CENSOR PLACED ON THE OUTPUT FRAME16:9, coveredcrop to 9:16face exposedthe box held its position onscreen; the picture movedunderneath itCENSOR PLACED ON THE SOURCE FRAME — VALMERAburned in firstcrop to 9:16still coveredthe box belongs to the footage,so the crop carries bothtogether — nothing to re-apply
The order of operations is the whole trick. Valmera burns censor regions into each source segment before any reframe or normalization runs, so a crop, a pad or a blurred pad moves censored footage as one piece.

How the Region Is Aimed — Measured, Not Estimated

A censor in the wrong place is worse than no censor: it obscures the picture and leaves the face. So the coordinates are not a vibe. Every frame the agent is shown carries a faint tenths grid with its origin at the top-left, and the censor takes its rectangle as four fractions of the frame — x and y for the top-left corner, w and h for the size, all between 0 and 1. A username in the top-right corner is x=0.6, y=0.02, w=0.38, h=0.1. Reading a coordinate off a printed grid is a measurement; guessing pixel values from a thumbnail is not, and the tool rejects pixel-scale numbers outright rather than quietly censoring a four-pixel square.

Fractions rather than pixels is also what makes the region resolution-independent: the same rectangle is correct whether the file is 1080p or 4K, and it is converted to real pixels only at render time against the source's own dimensions. A rectangle that would fall almost entirely outside the frame is rejected with the reason, because the usual cause is a corner mix-up — for a box touching the right edge, x is 1 minus w.

After the write, the agent renders a preview and looks at the frames it produced. That closes the loop that most AI editors leave open: the check is against the picture, not against the instruction it just issued. And Valmera's replies are verified server-side against the edits actually recorded, so "I blurred the plate" corresponds to a censor that exists in the edit. Neither of those replaces you checking the covered moment yourself before you publish — but they mean a claim of coverage is not just confidence.

What blur, pixelate and black out each leave inside the regionThree copies of the same censored region. Blur applies a Gaussian low-pass, so the shape and color of the face remain as a smooth gradient. Pixelate downscales the region and scales it back with nearest-neighbor sampling, leaving a small grid of blocks in which each block is a real average of the pixels underneath. Black out fills every pixel with one constant color, leaving nothing. A bar under each panel shows how much of the original information survives.BLURGaussian low-passstructure attenuatedPIXELATEdownscale, then nearesteach block is a real averageBLACK OUTevery pixel replacedby one constantHOW MUCH OF THE ORIGINAL SURVIVES INSIDE THE REGIONa lot — a reversible transformof the same pixelssome — a few dozen genuinecolor samples of the subjectnonenothing left to recoverall three are one word in the request — the difference is what is left underneath
Blur and pixelate transform the region. Black out replaces it. That distinction is cosmetic in a vlog and load-bearing in a redaction.

Blur, Pixelate, Black Out — What Each One Does to the Pixels

Blur crops the region out, runs a Gaussian blur over it and composites it back. The radius scales with the region — roughly a sixth of its short side, floored so a small region is never left legible and capped so a very large one stays affordable to render. The cap is worth knowing: a censor covering most of the frame is proportionally softer than a small one, so check a big blur in the preview rather than assuming.

Pixelate shrinks the region down — the short side becomes about eight samples — and scales it back up with nearest-neighbor sampling, which is what produces hard-edged blocks instead of a smooth ramp. It reads unmistakably as censorship, which is often the point: a viewer should be able to tell that a decision was made rather than wonder whether the camera was out of focus.

Black out fills the rectangle with solid black. There is no crop, no filter and no compositing: the pixels are overwritten. It is the least elegant and the only one of the three that is a true redaction.

Multiple regions can sit on the same video, each with its own style and its own span — two faces at a back table are two rectangles in one request, and removing one later is a sentence. Nothing is destructive: your original upload is never modified, and asking for a censor to come off puts the picture back.

If This Is a Compliance Job, Read This Part

Plenty of people arrive at a page like this because filming happened in public, or a screen share had a real customer on it, or a recording has to go out and someone in it did not consent. Three things are worth being clear about, and none of them are things a tool vendor gains by saying.

Blurring is not automatically anonymisation. Under the GDPR the test is whether a person remains identifiable, directly or indirectly, by anyone with means reasonably likely to be used. A blurred face in a video that still shows build, gait, clothing, a tattoo, a name badge, a doorway, a car, a timestamp and a voice has usually been pseudonymised, not anonymised — and pseudonymised data is still personal data with the full set of obligations attached. Whether a given redaction is sufficient is a question about your footage and your jurisdiction, not about the filter.

Weak blurs and mosaics are a known attack surface. Both are deterministic, information-preserving transforms of the pixels underneath — that is exactly why the picture still looks like a person-shaped thing. In 2016 McPherson, Shokri and Shmatikov published Defeating Image Obfuscation with Deep Learning, training networks to identify subjects in pixelated and blurred images at rates far above chance, and the literature since has not made blurring stronger. For a face in the background of a travel vlog this is irrelevant. For a witness, a minor, a patient or a defendant it is the whole question, and the answer is a black box, sized generously.

The picture is not the only channel. The most common failure in a careful redaction is a soundtrack that says the name, an unblurred reflection in a monitor or a window, the same face visible in a wider shot ninety seconds later, and a second screen in the corner of a screen recording. Valmera indexes a word-level transcript during analysis, so removing a spoken name is a request in the same chat: cut those seconds, or mute that span. Ask for it — the agent will not infer that hiding a face means you also wanted words taken out.

None of the above is legal advice, and the rules differ by country and by context. If a project turns on the question, ask a lawyer rather than a video editor.

When It Goes Wrong, and What to Do

The subject moves out from under it
There is no tracker. Size one region to cover the whole path, or step it along: "blur the left third from 0:10 to 0:18, then the center from 0:18 to 0:26". If they only cross frame for a second, cutting that second is faster than either.
An edge of the face still shows
The commonest defect, and the reason to check the preview at the exact moment rather than at a nearby one. "Make it wider and a bit lower" adjusts the existing region. Err large: an oversized censor costs you nothing.
The time window drifted after a cut
A censor's optional start and end are output-timeline seconds, so removing material earlier in the video shifts what falls inside them. Do your cutting first and censor last, or censor for the whole video and skip windows entirely.
A spliced-in clip is not covered
Censor regions apply to your main footage. B-roll, images and generated clips inserted into the timeline are not censored by a region on the main video — they need their own treatment before they go in.
The blur looks too soft to trust
Blur strength is capped, so a very large region is proportionally gentler. Switch to pixelate or black rather than asking for "more blur" — the mode change is the reliable fix.
You wanted it gone, not hidden
A censor is visibly a censor. If the goal is that nobody can tell anything was there, that is an erase, which repaints the pixels and rebuilds the background.

Cover It, or Take It Out Entirely

Valmera ships both, and they are different jobs. A censor is a visible cover: the viewer sees a blur, a mosaic or a bar and understands a decision was made. That is what you want for a face or a plate — an invisible removal of a bystander would be stranger, not better.

An erase repaints the pixels and reconstructs what was behind them, so the thing is gone rather than covered. It is the right answer for a name label in a UI, a burned-in caption, a sticker or a logo — anything where a black bar would look like a mistake. Several marks go into one repaint pass, the repaint always derives from your untouched original rather than from a previous repaint, and any erase can be put back. It is not magic: a large object on a moving, detailed background can leave a soft patch, and the honest move there is to cover it instead. Full detail on removing an object or a person and on removing burned-in text and watermarks.

There is a third option people forget: reframe the shot. Cropping a 16:9 video to 9:16 removes both edges of the frame, which frequently takes a corner bystander or a parked car out of the picture entirely and costs nothing to try.

How People Do This Without Valmera

Adobe Premiere Pro. The strongest answer for a moving subject. Apply Gaussian Blur or Mosaic to a clip, draw an ellipse or free-draw mask around the face, and let mask tracking follow it forward through the shot; recent releases also add AI-assisted subject selection to shorten the drawing part. If you already pay for Creative Cloud and you have one hero shot to fix, this beats a fixed region outright. The costs are the subscription, the tracking pass, and doing it per shot per subject.

DaVinci Resolve. Magic Mask does the same AI subject isolation and pairs with a Pixelize or Blur node. The catch to know before you download: Magic Mask runs on the Neural Engine and is a Studio feature, so the free build leaves you drawing Power Windows and tracking them by hand. Studio is a one-off licence rather than a subscription, which makes it good value if you censor often.

ffmpeg. Free, scriptable, exact. A fixed blur is one filter chain — crop the box, blur it, overlay it back, optionally wrapped in enable='between(t,12,20)' for a time window. There is no detection: you supply the pixel coordinates yourself, which usually means exporting a frame and measuring it in an image editor first. For a batch of files shot on a fixed camera, this is the correct tool and nothing else comes close.

YouTube Studio. If the video is going on your own channel, YouTube's editor has a built-in blur that detects and tracks objects and faces, free and with nothing to install. It is genuinely good for its case. Its limits are its case: your channel, an already-uploaded video, YouTube's processing queue, and no way to use the result anywhere else.

Online censor tools. A crowded category. Most do one thing well and gate the rest: upload caps, watermarked output, or automatic face blurring that works until a face turns sideways. Check what happens at the moment your subject moves, and check whether the export carries a mark, before you commit a deadline to one.

Valmera's claim against that field is narrow. It is the option where you never draw a mask, where the censor is placed by describing it and survives everything else you do to the video afterwards, and where the same conversation also does the cuts, the captions and the reframe. It is not the option with the best tracking — that is Premiere, and it will be for a while.

Honest Limits

No detection, no tracking. Valmera does not run a face detector and does not motion-track. The agent can find a face in the frames it looks at and place a rectangle over it; the rectangle then stays where it was put. Static subjects — seated, parked, on a screen — are a single request. Moving subjects need a wider region, several windows, or a cut.

Rectangles only. There are no shaped masks, no feathered ovals and no per-frame keyframed mask paths. A rectangle is what you get, and for hiding a face it is almost always enough.

Time windows are program time. The rectangle is anchored to your source footage and is unaffected by cuts. The optional start and end are in output-timeline seconds, and are only trimmed to fit if a later edit makes the video shorter — they do not re-anchor to the content they were aimed at. Censor after cutting, or censor for the whole video.

Inserted material is not covered. A region censors the main footage. Clips, stock, images and generated video spliced into the timeline pass through untouched.

Uploads and export. Up to 14 GB or 3 hours per file, MP4, MOV, MKV or WebM. Exports render from your original file at source quality as an H.264 MP4. Free-plan exports carry a small Valmera mark in the top-left corner; Creator, Pro and Frontier exports carry no watermark at all. Every export closes with a brief (~2.5-second) end card after your video.

Who Censors Video, and Why

Product demos with real data
A customer name, an email, an account number in a CRM. Static text in a fixed panel — the best case for a region, and a common reason to reach for a recorded demo instead of a live one next time.
Filming in public
Bystanders, shopfronts, house numbers, parked cars. Usually several small regions across a few spans rather than one big one.
Support and onboarding video
A recorded call turned into a help video without exposing the account it was recorded on.
Research, education, journalism
Where a subject consented to the content but not to their face. This is the case where the black box is the right choice and the blur is a comfortable mistake.

Part of the Same Conversation

Censoring is rarely the whole job. The same chat can cut any moment you describe, add word-accurate captions, reframe the video for another platform, redraw the mouse cursor in a screen recording and mix music that ducks under speech — and one request can carry several: "black out the plate, cut the bit where he says the address, and make me a 9:16 version". Browse the tools hub, or read exactly how regions behave in the effects documentation and reframing docs.

The censor tools are also exposed over Valmera's MCP server, so Claude can place, adjust and remove them on real footage from inside a conversation. And if you want the general version of this page rather than the privacy one, see blur part of a video.

Hide It in One Message

Describe the region, pick blur, mosaic or a black bar, check the preview.

Start free →
See pricing →

Frequently Asked Questions

Upload the video to Valmera and describe the face and the span: "blur the face of the woman on the left for the whole video", or "pixelate the man's face in the background between 1:10 and 1:35". The agent looks at real frames of your footage, measures the rectangle off a coordinate grid drawn on those frames, and places a blur, a mosaic or a solid black bar over it. It then renders a preview and looks at the frames it produced to check the region actually covers what you named.
Same request, different subject: "black out the license plate from 0:12 to 0:20". A plate is the easiest case there is when the car is parked and the camera is steady — one rectangle, one message. A plate on a car that drives across the frame is the hard case, because the censor is a fixed region rather than a tracked object; either size the region to cover the whole path the car takes, or step it along in two or three time windows.
No, and this is the limit worth understanding before you start. There is no face detector and no motion tracking. The agent sees your frames and can find the face in them to place a rectangle, but that rectangle is then fixed to a part of the picture for the span you gave it. A seated interviewee, a bystander at a table, a parked car, a name in a screen recording — all one request. A subject walking across frame needs either a generous region covering their whole path, several time-windowed regions, or a cut.
Blur is the softest and reads as natural in documentary footage. Pixelate is the familiar mosaic and reads clearly to a viewer as deliberate censoring. Black out is a solid fill. If the reason you are censoring is aesthetic or editorial, any of them work. If the reason is that a real person is identifiable and must not be, choose black: it is the only one of the three that replaces the pixels with a constant instead of transforming them, so there is nothing left in the region to recover.
Not automatically, and nobody selling you a blur tool should say otherwise. Under the GDPR the question is whether a person can still be identified, directly or indirectly — and blurring a face often produces pseudonymised data rather than anonymous data, because the picture still carries build, clothing, tattoos, a voice, a location, a timestamp and everything else in the shot. Weak blurs and mosaics are also a known target for machine reconstruction: a 2016 paper by McPherson, Shokri and Shmatikov trained networks that recovered identities from pixelated and blurred images at high rates. When the stakes are real, use a black box, cover generously, check the audio as well as the picture, and take actual legal advice — this page is not it.
The rectangle does, because it is expressed in coordinates of your original frame and burned into each source segment before any reframe happens. Crop a 16:9 video to 9:16 for Shorts and the covered footage moves as one piece, with nothing to re-apply. One honest caveat: if you gave the censor a time window, that window is in output-timeline seconds, so cutting material out afterwards shifts it. The reliable order is to finish your cuts first and censor last, or to censor for the whole video rather than a window.
Yes — that is a different tool with a different result. A censor hides a region and is visible as a censor. An erase repaints the pixels and reconstructs the picture behind them, so the thing is gone rather than covered. Erasing is the right answer for a burned-in caption, a watermark, a logo or a name label; censoring is the right answer for a face or a plate, where you usually want the viewer to see that something was deliberately hidden.
Valmera's free plan is 50 credits granted once at signup with no card, and a censor is one of the cheapest requests there is — credits are charged in proportion to the AI work actually done. Free-plan exports carry a small Valmera mark in the top-left corner; Creator ($30/month, 2,000 credits), Pro ($50/month, 4,000) and Frontier ($100/month, 10,000) export with no watermark at all, and paid plans open with a 3-day trial. Every export closes with a brief (~2.5-second) Valmera end card after your video.
Censoring the picture does nothing to the soundtrack, and this is the mistake that ruins otherwise careful redactions. Valmera builds a word-level transcript of your footage during analysis, so the fix is a separate sentence in the same chat: cut the seconds where the name is spoken, or mute that span. Ask for it explicitly — the agent will not assume that blurring a face means you also wanted words removed.

Blur Faces and Plates in Your Video

The agentic AI video editor — describe the edit, review the preview, download the export. 50 free credits, no card.

Start your free trial →
See pricing →

Related Articles

Blur Part of a Video
The same censor, framed around regions generally — usernames, documents, anything in a rectangle.
Remove an Object or a Person from a Video
When you want the thing gone rather than hidden — the pixels are repainted and the background rebuilt.
Remove Burned-In Text & Watermarks
The same repaint aimed at thin ink: subtitles, usernames, logos.
Resize Video for Any Platform
16:9, 9:16, 1:1 or 4:5 — censors move with the footage through the reframe.
Docs: Effects & Censoring
How region censoring, grades and stylize effects behave in the render.
All AI Video Editing Tools
Every editing job Valmera can do, one page each.