Photo SignalsAI Watermark Remover

AI Watermark Remover — and the six other things your file is carrying

Remove generator badges, Content Credentials and the prompt fields AI tools write into a picture — plus GPS, camera serial numbers and the files hidden inside. Paint over a visible mark and it fills in from the surrounding picture.

  • Visible watermarks
  • AI marks and C2PA
  • GPS and serial numbers
  • Hidden files inside

Open an image and paint over the mark

  • Nothing is uploaded
  • No account
  • Free, no limit
The problem

A photo file is mostly not the photo

You send a picture. You think you are sending a picture. You are also sending where it was taken, which camera body took it — that exact one, not the model — what the frame looked like before you cropped it, who your photo library thinks is in it, and on many phones a short video with sound from the seconds around the shot.

What one photo file is made of, and what survives cleaning A photo file drawn as a row of blocks. Camera metadata, editing history, a hidden thumbnail, a Content Credentials manifest, an unknown tracker block and an appended video are all removed. The block holding the picture itself is kept byte for byte, along with a thirty-two byte orientation block. YOUR FILE BEFORE EXIF GPS, serial XMP names, history THUMBNAIL pre-crop copy THE PICTURE compressed pixel data C2PA AI provenance TRACKER unknown VIDEO appended MP4 rebuilt from the parts we understood YOUR FILE AFTER THE PICTURE byte for byte identical ORIENTATION 32 bytes, kept Everything else is gone because it was never copied across — including block types nobody has named yet.
Most strippers delete the fields they know about. This one keeps only what it needs and rebuilds the file, so an unknown block dies because it is unknown.
Exactly what we remove

Eight families of signal, named one by one

Not "metadata". These are the specific things found in real files, and the badge on each card is what this tool will actually claim about it.

  • Watermarks you can see

    Removed — you mark it, it fills in

    • Stock-library tiling and corner logos
    • Burned-in dates and dashcam or CCTV timestamps
    • "Confidential", "Draft", "Sample" bars and diagonals
    • Channel bugs and app export badges
    • Screener and per-recipient overlays
  • AI generator marks

    Badges filled · manifests and fields removed

    • The Gemini and Nano Banana sparkle
    • Corner labels from Doubao, Jimeng, Qwen, Kling
    • Phone "AI edited" and Magic Editor badges
    • C2PA Content Credentials — Adobe, OpenAI, Cloudinary, camera makers, cloud image pipelines
    • Stable Diffusion's prompt, seed and model in the PNG text chunk
    • ComfyUI's whole workflow graph, filesystem paths included
    • China's TC260 AIGC labelling fields
  • Container metadata

    Removed — pixels untouched

    • EXIF — GPS with altitude, bearing and timestamp; make and model; body and lens serial numbers; shutter count; owner name from the firmware; timezone offset; how the fix was obtained; air pressure
    • XMP — editing history, document identifiers that link your files to each other, face regions naming the people in the frame, the original RAW filename, the pre-crop dimensions
    • IPTC — author, credit, city, contact details
    • MakerNotes — the manufacturer's private block
    • Photoshop IRB, JFIF, MPF and unknown APP segments
    • PNG chunks — tEXt, zTXt, iTXt, eXIf, tIME and anything unrecognised
    • GIF and WebP comment and application chunks
  • Whole files hidden inside the picture

    Extracted, shown to you, then removed

    • The embedded thumbnail — a copy from before you cropped or blurred
    • Motion photo video — an entire MP4 appended after the picture ends, with sound, covering the seconds either side of the shot
    • The MPF second full-size image some phones store
    • Ultra HDR gain maps and depth maps
    • Full-resolution previews inside RAW and DNG
    • PSD layers holding content you thought was deleted
    • Anything appended after the end marker, and the slack between segments
    • Payloads in fully transparent pixels, and messages in the low bits
  • Fingerprints of the software

    Removed by re-encoding at level 2

    • Compression tables that name the camera model or the program, with no metadata involved at all
    • Scan layout, subsampling and chunk ordering that identify the writer
    • ICC profiles named after a specific monitor calibration
  • Traces of the camera and the printer

    Printer dots removed · sensor noise reduced and measured

    • Printer tracking dots — the pale yellow grid colour printers add to every page, encoding the printer's serial number and usually the time of printing. Found in any scan of a printed page and removed at level 2, with the count and the lattice spacing reported
    • Sensor pattern noise — the signature of the individual camera body, not the model. Attenuated at level 4 and reported as a number, never claimed removed
    • Hot and dead pixel maps unique to one body
  • SVG, which is a document

    Removed by an allowlist

    • Beacons — references to an image on another server, contacted every time the file is opened
    • Executable script inside the image
    • Illustrator and Inkscape namespaces with layer names and local paths
    • Embedded raster images, which carry their own EXIF and are cleaned recursively
  • Writing inside the picture

    Found and pointed at — never read aloud

    • QR codes and barcodes on a badge, a boarding pass, a ticket or a parcel label. They usually encode a link with an identifier in it, a booking reference or a name — as readable to a stranger as the text beside them, and nobody thinks of them as writing
    • We say a code is there and where it is, so you can crop it or paint over it. We do not decode what it says: reading out what is on somebody's ticket is not this site's business
  • What nobody can remove

    Named and explained, never claimed

    • Imperceptible watermarks whose detector is held privately by its owner
    • Perceptual-hash databases platforms keep — not in your file, so nothing in your file changes them
    • A provider's own record of what it generated

    Why, and what our transforms actually do to them

By generator

Which tool marked your picture, and how

People search for one company's name. Here is what each actually attaches, because the answer differs and two of these attach nothing to an image at all.

  • Google Gemini · Nano Banana

    A visible sparkle in the corner, plus an imperceptible mark and provenance metadata. The badge fills in and the metadata is removed; the imperceptible part is the one nobody outside Google can verify.

  • OpenAI · ChatGPT images

    C2PA Content Credentials in the container, naming the model and the time. Removed by the rebuild, and the removal is proven by re-reading the result.

  • Adobe Firefly

    Content Credentials, and often an edit history in XMP naming every step and the original file. Both removed.

  • Stable Diffusion · ComfyUI

    The prompt, the seed, the model and — from local workflows — the entire node graph with filesystem paths in it, written into a PNG text chunk. None of it is EXIF, so EXIF-only tools miss all of it.

  • Cloudinary and image pipelines

    Content Credentials attached on transform, so a picture that was merely resized by a service can arrive carrying a signed record of that service. Removed like any other manifest.

  • Midjourney, Canva, Chinese generators

    Corner labels and export badges from Doubao, Jimeng, Qwen and Kling, plus China's TC260 AIGC fields. Badges fill in, fields are removed.

  • Claude and Codex

    Neither generates images, so neither marks one. If a picture came out of a workflow involving them, whatever rendered or exported it is what attached the mark — a screenshot tool, a design app, an image service. Open the file and the report will name it.

  • Your phone's AI editing

    Magic Editor and equivalents add their own flags, and often a second image plane. Both are removed, and the second plane is shown to you first.

  • Whoever keeps the detector

    Where the mark is imperceptible and its detector is private, no honest tool can tell you the result. We say so rather than guess.

Three steps

How the watermark part works

  1. Open the image

    It is read into this tab. There is no endpoint on this site to send it to.

  2. Paint over the mark

    Cover it and a little of its edge — the fill needs to see where the mark stops.

  3. Fill, then look

    Compare against the original before you keep it. If the patch shows, undo and paint a smaller area. The same three steps, written out.

Where it works and where it does not. Filling continues the surrounding picture inward, so consistent surroundings — a sky, a wall, a document, a flat background — come out clean. Detail does not. Paint over a face and you get a smooth patch anyone can see is a patch. This tool will not invent a face that was never in the frame.

Into the picture itself

What level 2 reaches, and what it costs

Removing metadata never touches the picture, which is why it is free of consequences — and why it cannot reach anything carried in the pixels. Level 2 decodes and re-encodes, and then three more things come off.

  • The software fingerprint

    Compression tables and scan layout identify the camera model or the program that saved the file, with no metadata involved at all. A re-encode replaces them with ordinary ones.

  • Printer tracking dots

    The pale yellow grid on every page from a colour printer, encoding its serial number and the time of printing. We report how many were found and the spacing of the lattice — and if there is no lattice, nothing is changed and we say so rather than guessing.

  • Anything in the low bits

    Messages hidden in the least significant bit of each colour do not survive a re-encode.

And a number instead of a promise. After re-encoding we measure the picture's perceptual fingerprint before and after and tell you how far it moved, in bits out of sixty-four. That is the honest answer to "will a platform still recognise this": below about ten bits it certainly will, above twenty it probably will not, and nobody outside the company running a specific matcher can tell you more than that. Why we will not pretend otherwise.

Nudging individual pixels does none of this. Measured on our own test picture: one pixel changed moves the fingerprint 0 bits, a thousand pixels changed moves it 0 bits, a global dither moves it 0 bits. The fingerprint is computed from a 32×32 average of the picture, so single pixels are gone before it is calculated. Geometry is what moves it.

After the strip

An empty header is itself unusual

Almost every photograph in the world carries some camera metadata. A picture with none is remarkable, and remarkable is exactly what someone trying not to stand out cannot afford — in some situations "this person ran an anti-forensics tool" is worse than the metadata it replaced.

  • Orientation only

    The smallest honest header: which way up the picture goes, and nothing else. Thirty-two bytes.

  • An ordinary-looking header

    A common make and model and a coarse date, so the absence does not stand out. No GPS, no serial numbers, no owner name — nothing that could belong to a real device or a real person.

  • Nothing at all

    The cleanest result, and the most conspicuous one. Sometimes that is the right trade.

What the decoy is not. It does not survive comparison with the original, which anyone holding it can make. It does not touch the picture, so the sensor's own noise and any imperceptible mark are exactly where they were — a decoy header on a file whose pixels still identify the camera is a comfort, not a defence. And it is not evidence of when or where anything happened; using it as any is the thing the terms forbid.

How deep

You choose how far it goes

Removing metadata never touches the picture. Reaching the signals carried in the pixels does, and the cost is stated before you pay it.

  • L1Rebuild the container. Metadata, hidden files, appended video, provenance manifests.Pixels byte-for-byte identical
  • L2Re-encode. Also removes the software fingerprint and anything hidden in the low bits.One generation of compression
  • L3Resample and shift. Breaks the grid many imperceptible schemes lock onto.Visible on close inspection
  • L4Denoise and re-noise. Attacks the sensor's own noise signature.Softens fine detail — you will see it
What we will tell you

Three answers, and never the word "clean"

  • Removed

    Proven

    Absent from the output, and proven by re-reading our own result with the same parser that found it.

  • Reduced

    Measured

    Measurably weakened and reported as a number. The number is the claim — not the word "clean".

  • Not verifiable

    Named, never claimed

    Nobody outside the owner of a private detector can tell you the answer, so we do not guess.