Detect sensitive information in images
Sensitive information gets into an image two ways: written into the file as metadata, or sitting in the picture where anyone can read it. Most tools only deal with the first. Both matter, and the second is the one that ends up on a screenshot.
This is a web app — nothing to install — and the detection runs on your own device.
Works today, in your browser. Photos open in the editor and Word documents are checked for hidden data; either way the file is read on your device and never uploaded.
Hidden in the file
Written by the camera or the editor, invisible when you look at the picture.
- GPS coordinates, usually to within a few meters
- Capture timestamps, to the second
- Camera make, model and serial number
- Editing software and version
- Author, copyright and description fields
Visible in the picture
This is the half that metadata strippers miss entirely. The detectors below work on anything legible in the frame, and each is a real test rather than a guess — a Luhn checksum for card numbers, mod-97 for IBANs, the check digits in a passport MRZ line. Where something is a heuristic, the result says so.
- Payment card numbers, checksum-validated rather than pattern-matched
- IBANs and bank account numbers
- Passport machine-readable zone lines
- National identifiers such as US Social Security numbers
- Email addresses, phone numbers and street addresses
- API keys and access tokens, the sort that leak in a screenshot of a terminal
- QR codes and barcodes, including boarding passes that carry your booking reference
- Faces, so you can cover people who did not agree to be posted
Checksums, not guesswork
A detector that matches any sixteen digits will flag order numbers, tracking codes and part numbers, and after the third false alarm people stop reading the results. That is how a privacy tool fails: not by missing something, but by being ignored.
So every detector ships with tests for the things it must *not* match, as well as the things it must. False positives are treated as bugs.
What is not switched on yet
Reading text out of a photograph — OCR — is available through the API but not yet in the browser version. In the browser, text detectors run over text the file already contains rather than text rendered into pixels. The toggle on the checker says so rather than quietly doing nothing.
Questions
No. Detection runs in a web worker on your device using a library that cannot make a network request. The one request the page makes after a check is an anonymous count — which categories fired, not what they found, and never the file.
No, and that is deliberate. It finds that a face is present and where it is, so you can cover it. It does not recognize anyone, does not estimate age, and does not build any kind of profile. Every face is reported regardless of who it belongs to.
No, and anyone claiming otherwise is selling something. It catches the categories listed above, in the formats it knows. We report "no issues found" rather than "safe" for exactly this reason.
It is a web app, so there is nothing to install and nothing to keep updated. A mobile app and a browser extension are in progress; both will work the same way, on device.
Related
- Photo privacy checkerCheck a photo for GPS coordinates, camera details, timestamps and faces before you post it. Runs in your brows…
- PII detection in images, with OCRFind PII in images — card numbers, IBANs, passport MRZ lines and national IDs, validated by checksum. OCR runs…
- File privacy scannerScan a file for personal data, hidden metadata, author names and edit history before you share it. Runs in you…
We report no issues found, never “safe”. Absence of detections is not proof of absence, and detection is best-effort.