All tools run in your browser — your files never leave your device.
All tools154

PDF

Invisible text, stray comments and the myth of read-only

PDFs routinely carry content nobody intended to send, and the permission settings meant to control them are requests rather than locks.

The short answer. Invisible text is real and usually benign — OCR places a searchable text layer beneath a scanned image. Comments and tracked changes leak into exported PDFs unless explicitly excluded. And PDF permissions marking a file read-only are enforced only by cooperating software: they are a convention, not encryption, and any determined tool ignores them.

The invisible text layer

Select text on a scanned page and watch highlighting appear over what is plainly a photograph. That is the OCR layer.

When software recognises text in a scan it does not alter the image. It writes the recognised characters into the page in an invisible rendering mode, positioned over the matching part of the picture. You see the scan; search sees the text.

This is the correct design. It keeps the original scan intact — important for anything with legal weight — while making the document searchable and accessible to a screen reader. The consequence is that the searchable text and the visible text are separate, and OCR errors are therefore invisible: the page shows a clean "8" while the text layer holds a "3", and nothing indicates the mismatch.

Other uses, including one to be wary of

  • Accessibility. Invisible text can describe an image or provide reading order for a screen reader.
  • Watermarking. Invisible identifiers track which copy of a document leaked.
  • Metadata in the page. Job numbers and internal references placed for machines.
  • Keyword stuffing. Hidden text intended to influence search. This is a spam technique and search engines treat it as one.

The last is worth naming because the technique gets described neutrally in a lot of writing about invisible text. Hidden text added to manipulate ranking is a policy violation in every major search engine, and detection of it is neither new nor difficult.

Comments that escape into the PDF

Exporting a Word document with tracked changes visible produces a PDF containing every comment, every deletion and the name of everyone who made them. It is one of the more common ways confidential drafting leaks.

The export follows what is displayed, so the fix is at both ends: change the display, and set the export option.

  1. Accept or reject all changes, and delete all comments. This is the only route that actually removes them.
  2. Set Review → Display for Review to "No Markup". This hides them; it does not remove them.
  3. In the export dialog, Options, untick "Document showing markup".
  4. Run Document Inspector — File → Info → Check for Issues — to find comments, hidden text, and author metadata.
  5. Open the exported PDF and search it before sending. Thirty seconds, and it catches everything above.

The distinction in steps 1 and 2 matters. Hiding markup changes the display, and if the export path ever falls back to showing markup — a different Word version, a colleague re-exporting — the comments come back. Only accepting or rejecting them removes them from the document.

Read-only is a request, not a lock

PDF permissions can mark a document as not printable, not editable, not copyable. These are stored as flags and enforced by the reader that honours them.

That is the whole mechanism. Acrobat respects the flags; so do most mainstream readers. Any tool that chooses not to simply ignores them, and doing so requires no cracking, because there is nothing to crack — the restriction is a note in the file asking software to behave.

Read-only is a request, not a lock
GoalMethodActually enforced?
Discourage casual editingPermissions flagsBy cooperating readers only
Prevent openingPassword + encryptionYes, genuinely
Prevent editing absolutelyNot possible once sentNo
Detect alterationDigital signatureYes — shows tampering
Discourage reuseVisible watermarkSocial, not technical

The row that people want is the third, and it does not exist. Once someone has the file they can render every page to an image and rebuild it. The realistic goals are making alteration detectable, and making an altered copy obviously not the original — which is what signatures and watermarks do.

What to use instead

Match the mechanism to the actual worry, which is usually narrower than "stop them editing it".

If the concern is accidental change, permissions flags are entirely adequate. They stop the honest mistake, which is the realistic risk in most offices.

If the concern is a forged version circulating, a digital signature is the answer. It does not prevent editing; it makes any edit break the signature, so the recipient can tell. That is a stronger guarantee than prevention, because it survives the file being copied.

If the concern is unauthorised distribution, a visible watermark naming the recipient is more effective than any technical control, for the same reason numbered copies work on paper. Watermark PDF applies one across every page in the browser, so the document is not uploaded to add it.

Before you send anything sensitive

  1. Search the PDF for a phrase you know was in a deleted comment.
  2. Check document properties for author, company and original filename.
  3. Select all and copy into a text editor — this reveals invisible text.
  4. Check the page count against what you expect.
  5. If pages were removed, confirm the file was rewritten rather than incrementally saved.

The third check is the one that finds things. Copying the entire text out strips the rendering mode along with the layout, so anything invisible on the page appears in the paste — OCR errors, hidden identifiers and text under images all become visible at once.

Frequently asked questions

What is invisible text in a PDF?

Usually an OCR layer: recognised characters written into the page in an invisible rendering mode, positioned over a scanned image. You see the scan, search sees the text. It keeps the original image intact while making the document searchable and screen-reader accessible.

How do I see hidden text in a PDF?

Select all, copy, and paste into a plain text editor. That strips the rendering mode along with the layout, so anything invisible on the page appears in the paste — OCR text, hidden identifiers and text placed under images.

How do I stop Word comments appearing in my PDF?

Accept or reject all changes and delete all comments — that is the only step that removes them. Setting Display for Review to No Markup merely hides them. Also untick "Document showing markup" in the export options, and run Document Inspector before sending.

Can I make a PDF truly non-editable?

No. Permission flags are enforced only by readers that choose to honour them, and any tool can ignore them without cracking anything. Once someone has the file they can rasterise and rebuild it. Use a digital signature to make alteration detectable instead.

What is the difference between permissions and a password?

A password with encryption genuinely prevents opening the file — that is real cryptography. Permission flags on an unencrypted PDF are a note asking software to restrict printing, editing or copying, and carry no enforcement of their own.

Is invisible text bad for SEO?

Hidden text added to manipulate ranking is a policy violation in every major search engine and is straightforward to detect. An OCR layer is not — it is the normal, intended way a scanned document becomes searchable.

How do I check a PDF before sending it?

Search it for a phrase from a deleted comment, check document properties for author and original filename, and copy all the text into a plain editor to expose anything invisible. Thirty seconds, and it catches nearly every accidental leak.

Stop reading, start doing

Every tool in this guide is free.

154 browser-based utilities. No account, no upload, and no file size limit — your files are processed on your own device and never sent anywhere.

Browse all 154 tools