NullKit

Photo privacy, in plain language

Remove Photo Metadata & AI Content Credentials

Remove EXIF, GPS, and optional AI Content Credentials locally. Your photo is not uploaded.

Inspect and remove supported EXIF, GPS, editing, and AI provenance metadata from a photo, then create a verified clean copy without uploading the file. JPEG, PNG, WebP, and GIF files are supported up to 25 MiB and 40 megapixels.

On-device workspace

Choose. Review. Clean.

  1. 01Choose
  2. 02Review
  3. 03Clean

Ready. Choose one supported photo to begin.

A local check

See what travels with your photo.

The file is inspected in a browser worker on this device. Analytics and browser connection APIs are disabled on this route.

  • Plain-language privacy findings
  • Separate provenance and C2PA context
  • A verified clean copy and receipt
No photo ready?

Open a built-in sample to see the full flow.

JPEG, PNG, WebP, or GIF · Up to 25 MiB and 40 megapixels · One file at a time

Beyond the pixels

What photo metadata can reveal.

Metadata can make a file easier to organize, display, edit, and verify. The same context can reveal more than you intended when the file leaves your device.

Supported files

A conservative format policy.

“Clean” means the selected, recognized metadata was removed and the output passed a local rescan. It never means that every unknown byte or every possible clue has disappeared.

FormatInspector checksCleaner can remove
JPEG.jpg, .jpegEXIF/GPS, XMP, IPTC, comments, and identified C2PA containersSupported EXIF/GPS, non-appearance XMP, IPTC, and comments; C2PA only when selected
PNG.pngeXIf, text and time chunks, plus identified caBX/C2PA containersSupported eXIf, text, and time data; caBX/C2PA only when selected
WebP.webpEXIF, XMP, and identified C2PA containersSupported EXIF/GPS and non-appearance XMP; C2PA only when selected
GIF.gifComments, supported application metadata, and safe plain-text blocksComments, supported XMP, and safe plain text; identified C2PA application data only when selected

Always conservative: the tool preserves encoded pixels or frames, ICC color information, animation controls, required orientation behavior, unfamiliar structures, and appearance-critical data. Malformed or excessively complex files fail closed instead of producing a guessed output.

Requires JavaScript and Web Worker support in a modern desktop or mobile browser.

Four local steps

How to inspect and clean a photo.

  1. 01

    Choose a photo

    Select a JPEG, PNG, WebP, or GIF up to 25 MiB and 40 megapixels, or open the built-in demonstration. The file is read on this device.

  2. 02

    Review the findings

    Read the plain-language privacy summary, provenance clues, technical details, and the exact structures the browser recognized.

  3. 03

    Choose what to clean

    Review the supported privacy metadata selected for standard cleanup. Content Credentials and other identified C2PA data are a separate choice because provenance can be valuable.

  4. 04

    Download the verified copy

    The cleaner creates a new file without re-encoding image data, rescans it locally, and shows a receipt of what was removed and preserved before download.

AI photo metadata and provenance

Remove AI metadata without mistaking it for an AI verdict.

Metadata may contain an AI-related label or a C2PA provenance container. Either can be copied, stripped, incomplete, invalid, or absent.

This tool identifies containers

It reports supported metadata and structurally identified C2PA data. It does not validate signatures, certificates, issuers, trust chains, or assertions.

It is not an AI detector

No AI label does not prove human authorship. Pixel-level or invisible watermarks such as SynthID are not detected or removed.

Removal loses provenance

Content Credentials may help a recipient understand a file's history. Remove identified C2PA data only when that privacy tradeoff is intentional.

Browser privacy

What “on this device” means here.

This route uses a deliberately smaller network boundary than the rest of the marketing website.

  1. You choose a local file

    The page reads it through the browser's file API. It does not receive a path it can use to browse other files.

  2. A local worker checks bytes

    Parsing and cleanup run off the main page thread. Limits of 25 MiB, 40 megapixels, 10,000 container structures, and 1 MiB of decoded metadata text bound the work.

  3. Connection APIs are blocked

    Its Content Security Policy disables analytics, Fetch, XHR, WebSocket, and similar connections. The page itself and its required scripts, styles, icons, and demo image are static assets served from nullkit.app.

  4. You save a new local copy

    The original is not changed. The download becomes an ordinary file under your browser and operating system's storage rules.

Outside this boundary: NullKit cannot control a compromised browser or operating system, installed extensions, screenshots, backups, sync folders, a file you uploaded earlier, or details visible in the image itself.

Clear answers

Photo metadata questions.

Does my photo leave this device?

No. Inspection, cleaning, and verification run in a browser worker on this device. Analytics are disabled on this tool route, and its page-specific security policy blocks Fetch, XHR, WebSocket, and similar connection APIs. The page and its static assets still load from nullkit.app. Your browser, operating system, and installed extensions remain outside NullKit's control.

Does cleaning re-encode the image?

No. For a supported, valid file, the cleaner removes selected recognized metadata containers without decoding and re-encoding the image or animation frames. The file size can change, and minimal orientation data may be rewritten so the photo keeps its intended display direction.

Will every piece of metadata be removed?

No. The cleaner is deliberately conservative. Color profiles, orientation, animation controls, secondary-image or HDR data, appearance-critical fields, and unfamiliar structures may be preserved. The result receipt lists what the tool removed and what it intentionally kept.

Can I remove metadata from an AI-generated photo?

Yes, when the image is a supported JPEG, PNG, WebP, or GIF. Standard cleanup removes supported EXIF, GPS, comments, and non-appearance metadata. Identified C2PA or Content Credentials data is a separate opt-in choice because removing it also removes useful provenance. Pixel-level and invisible AI watermarks are not detected or removed.

Can this tool tell whether a photo was made by AI?

No. It can report supported AI-related labels or provenance containers that are present, but it does not classify pixels. Missing metadata is not proof that a photo was made by a person, and pixel watermarks such as SynthID are not detected or removed.

Does it verify Content Credentials or C2PA signatures?

No. The inspector identifies supported C2PA containers and reports their presence, but it does not validate a signature, certificate, trust chain, issuer, or assertion. Use a dedicated, current verification service when authenticity decisions matter.

Which photo formats are supported?

JPEG, PNG, WebP, and GIF are supported for inspection and conservative cleaning. HEIC, HEIF, AVIF, RAW camera files, PDFs, videos, and files above 25 MiB or 40 megapixels are not accepted by this version.