Skip to content
Available now

Detect sensitive information in images

Sensitive information gets into an image two ways: written into the file as metadata, or sitting in the picture where anyone can read it. Most tools only deal with the first. Both matter, and the second is the one that ends up on a screenshot.

This is a web app — nothing to install — and the detection runs on your own device.

Works today, in your browser. Photos open in the editor and Word documents are checked for hidden data; either way the file is read on your device and never uploaded.

Hidden in the file

Written by the camera or the editor, invisible when you look at the picture.

  • GPS coordinates, usually to within a few meters
  • Capture timestamps, to the second
  • Camera make, model and serial number
  • Editing software and version
  • Author, copyright and description fields

Visible in the picture

This is the half that metadata strippers miss entirely. The detectors below work on anything legible in the frame, and each is a real test rather than a guess — a Luhn checksum for card numbers, mod-97 for IBANs, the check digits in a passport MRZ line. Where something is a heuristic, the result says so.

  • Payment card numbers, checksum-validated rather than pattern-matched
  • IBANs and bank account numbers
  • Passport machine-readable zone lines
  • National identifiers such as US Social Security numbers
  • Email addresses, phone numbers and street addresses
  • API keys and access tokens, the sort that leak in a screenshot of a terminal
  • QR codes and barcodes, including boarding passes that carry your booking reference
  • Faces, so you can cover people who did not agree to be posted

Checksums, not guesswork

A detector that matches any sixteen digits will flag order numbers, tracking codes and part numbers, and after the third false alarm people stop reading the results. That is how a privacy tool fails: not by missing something, but by being ignored.

So every detector ships with tests for the things it must *not* match, as well as the things it must. False positives are treated as bugs.

What is not switched on yet

Reading text out of a photograph — OCR — is available through the API but not yet in the browser version. In the browser, text detectors run over text the file already contains rather than text rendered into pixels. The toggle on the checker says so rather than quietly doing nothing.

Questions

  • No. Detection runs in a web worker on your device using a library that cannot make a network request. The one request the page makes after a check is an anonymous count — which categories fired, not what they found, and never the file.

Related

We report no issues found, never “safe”. Absence of detections is not proof of absence, and detection is best-effort.