You have one month. The bundle is four hundred pages. Every third-party name, address, phone number and reference has to come out — consistently enough that nobody can be reconstructed from what is left.
eleyed reads the whole bundle in one pass, including scanned and photographed pages, and takes the personal data off the page permanently. You review what it found. The finding is done.
No card required. Purchased credits never expire.
Where the month goes
A request that surfaces four thousand emails is not a search problem. It is a review problem, and organisations routinely discover this in week three — after the point where the two-month extension could still have been claimed.
The failure mode is rarely a wrong judgement call. It is fatigue on page three hundred: the same name missed once in a footer, an email address left in a header, a date of birth inside a scanned letterhead. One hit is one too many, and it is the misses that become incidents.
Automated detection changes where your attention goes. Reviewing what a tool has found is a different task from finding it all yourself, and it is the part where judgement actually adds something.
Worth being precise about, because a tool that claims to do the second column is a tool you should not put a response bundle into.
eleyed does this
eleyed does not do this
No automated system is perfect. Always review redacted output before it leaves the organisation — the same position we take in our FAQ and terms.
Data handling
A response bundle is the most sensitive set of documents your organisation will handle that month. Where it goes, what is kept, and who else sees it are the questions that decide whether a tool can be used at all.
Nothing you upload is stored
Files are processed in memory and discarded when the job finishes. No document store, nothing written to disk, no backups of submitted content.
No third-party AI
Detection runs on our own infrastructure. Your bundle is never sent to OpenAI, Anthropic, Google or any other outside model — the requirement that rules most redaction tools out of this work.
Removal, not concealment
Content comes off the page rather than being covered by a shape that lifts off in a PDF editor. The recovered-text failure is the one that becomes a disclosure incident.
Only the audit trail is kept
Operation type, credits used, timestamps and counts of what was detected — never the matched text itself. Enough to evidence the work, nothing more.
No software to install, no procurement cycle to start.
Names, variants, initials, email addresses, reference formats. Add them as custom terms and patterns — the list is what makes redaction consistent across a large bundle.
Upload the PDFs, native or scanned. eleyed detects personal data across every page and removes it, applying your list alongside its own detection.
You get the redacted files and a breakdown of what was found, by type. Check the judgement calls, verify the output, and send.
The same detection is available over a REST API if the work belongs inside an existing case management process rather than a browser.
Credits, bought outright. No subscription, no seat licences, no minimum term.
| Bundle size | Credits | Approx. cost |
|---|---|---|
| 20 pages | 101 | $1.12 |
| 100 pages | 501 | $5.57 |
| 500 pages | 2,501 | $27.79 |
Costed at the Business pack rate (4,500 credits for $50.00). PDFs cost 1 credit per job plus 5 per page. Packs start at $5.00 and purchased credits never expire. Re-running an identical document is free.
No. Files are processed in memory and discarded when the job finishes. There is no document store, nothing is written to disk, and there are no backups of submitted content. We keep the transaction record — operation type, credits used, timestamps, and counts of what was detected — but never the text itself.
No. Detection runs entirely on our own infrastructure. Content is never passed to OpenAI, Anthropic, Google or any other outside model. This is usually the question that rules other redaction tools out of subject access work.
No, and it should not. eleyed finds and removes personal data. Whether the third-party exemption applies, whether disclosure is reasonable without consent, and what to do with mixed data remain judgement calls for the person handling the request.
Yes. OCR is built in, so scanned pages, faxes and photographed documents saved as PDF are read and redacted without a separate conversion step. Response bundles are rarely all native PDFs, which is where a lot of tools fall down.
Permanent. The content is removed from the page itself rather than covered with a shape that can be lifted off in a PDF editor or recovered with copy and paste. Covering rather than removing is the failure that has caused real disclosure incidents.
Yes. Everything available in the browser is available over a REST API with the same detection and the same retention model, so it can sit inside an existing case management or ticketing process.
More in the full FAQ, or email support@eleyed.com.
Related guidance
SAR and DSAR redaction: what UK organisations must remove
What has to come out, what must stay in, and where the third-party exemption actually applies.
FOI redaction: what UK public authorities must remove
The same mechanics, the opposite default — information goes out unless an exemption applies.
Why drawing a black box is not redaction
The failure mode behind real disclosure incidents, and how to check your output does not have it.
What still leaks after you redact a PDF
Metadata, filenames, comments, tracked changes and OCR layers that survive a clean-looking redaction.
Ten free credits on signup — enough to redact a page and read the output before you decide anything. No card, and nothing you send is kept.
Try it — 10 free credits →