Track Privacy Redactor
Redact sensitive portions of a track, including edges that cross a zone between two safe samples. The output is newly constructed from retained coordinates; source names, author, elevation, times, extensions and GeoJSON properties are not copied.
Key features
- Accept GPX 1.1 tracks or GeoJSON LineString/MultiLineString up to 1 MB and 5,000 points
- Use circles, simple closed polygons and inclusive RFC 3339 time windows; add a metre buffer to spatial rules
- Remove sensitive samples and split crossings between safe samples so an exported line does not bridge a hidden zone
- Discard isolated points, original names, timestamps, elevation, extensions and properties from downloads
- Recheck every retained point and edge against all rules before export
- Download rebuilt GeoJSON, GPX, SVG and a statistics-only JSON check report
How to use
- Load a local GPX or GeoJSON track, or use the demonstration track.
- Edit JSON redaction rules: circles have lon, lat and radiusM; polygons are closed arrays of lon/lat pairs; timeWindows have start and end.
- Run the redaction and review removed samples, split edges, retained segments and residual checks.
- Inspect the tile-free route preview and download a rebuilt track plus the statistics-only report.
- Review the remaining route before sharing; approximate boundaries and recognizable residual shapes can still reveal locations.
Use cases
- Remove a home-area portion before sharing a running GPX track
- Split a route crossing a sensitive facility even when no recorded sample lies inside it
- Delete a time interval from a fieldwork route
- Strip personal metadata and elevations from a GeoJSON path export
Frequently asked questions
Does the tool hide a zone crossed only between GPS samples?
Yes. It checks every edge as well as every sample against buffered circles, polygon boundaries and inclusive time windows. A crossing splits the route into separate segments. Very short leftover runs are discarded rather than exported as a single revealing point.
What redaction shapes and distances are supported?
Circles and one outer ring per simple Polygon are supported, with a 0–2,000 m buffer. Polygon holes and antimeridian-crossing edges are not supported. Local equirectangular distance uses mean Earth radius 6,371,008.8 m, requires latitude within ±80° and is an approximation, not a survey boundary.
How are time windows handled?
Start and end timestamps are inclusive. All points in a segment must have strictly increasing RFC 3339 times when a time rule is used; missing or reversed times stop the redaction. A track edge spanning the interval is split even if no sample falls inside it. Exports drop every timestamp.
What data is retained in downloads?
Only retained two-dimensional lon/lat coordinates and the newly separated segment structure are exported. GPX metadata, waypoints, routes, elevation, time, extensions and GeoJSON properties are not copied. The report contains only counts and policy text.
Is redaction a privacy guarantee?
No. Retained route shapes and endpoints may still reveal a private place by inference. The buffer and crossing checks lower direct coordinate leakage but cannot guarantee anonymity. Review each output before sharing.
Are tracks uploaded or stored?
No track upload, external map tile request or automatic storage is used by this tool. File decoding and redaction happen in the current browser tab; downloads start only when you click a button.
Privacy
Sensitive tracks are processed in this browser tab only. Downloads are rebuilt from retained coordinates. Check all outputs before sharing; this is not a guarantee against location inference.
Comments & questions