Privacy
Your files and your text are never transmitted anywhere, with one exception you have to ask for by name: the Deep clean option in the image tool. Everything else is a consequence of how the site is built, not a policy someone could change quietly. This site does carry advertising, and this page is specific about where it runs, what it collects, and about that one exception, because a privacy page that omits the awkward part is worth nothing.
What happens to your file
When you drop a file in, the browser reads it into memory in the page you already have open. Every parser runs there: EXIF, PNG chunks, RIFF chunks, SVG, C2PA. The cleaned file you download is assembled in the same place. At no point is there a request carrying your data.
There is now a server, and this paragraph used to say there was not. It holds accounts, credit balances and the queue for the one feature that needs a GPU, and it is described in full further down. It is not on the path of any file handled above: those never leave the tab, whether or not you have an account.
The same is true of text. Analysis and normalization are ordinary functions running on the string in your browser tab.
The workspace is sealed
Every page under /app is served with a second, stricter security policy. No third-party script can load there, no advertising runs there, and nothing can open a connection to another site. Your browser enforces that before any of our code gets a say, so it is a rule rather than a promise.
The certificate lists used to check Content Credentials ship with the site as static files for the same reason. Fetching them from a third party at the moment you inspect a file would leak the fact that you were inspecting one.
Advertising, and where it runs
The site is free and is paid for by Google AdSense. Advertising runs on the home page, on How it works, and on the four focused tool pages: /text, /image-watermark-remover, /metadata-remover and /provenance-inspector. It does not run in the /app workspace, and it does not run on this page.
Be clear about what that means on the focused tool pages, because they run the real tool. Your text and your files are still never transmitted by this site, and there is still no server to transmit them to. A Google advertising script does sit in the page alongside them, though. If you would rather have none of that, the same tool is at /app with no third-party code in the document at all.
What the advertising itself does is standard and not ours to change. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visits to this site and other sites on the internet.
You can opt out of personalised advertising in Google’s Ads Settings, or opt out of a third-party vendor’s use of cookies for personalised advertising at aboutads.info. In the EEA, the UK and Switzerland personalised advertising is only served if you agreed to it, in a dialog from Cookiebot, a consent platform certified by Google and registered with the IAB Transparency and Consent Framework. Nothing is requested from Google until you have answered it.
Withdrawing has to be as easy as agreeing, so it is one button and it is on this page:
What is stored in your browser
By this site: two things, both trivial and both local. Your theme choice, under the localStorage key aaw-theme, and whether you dismissed the notice at the top of the page, under aaw-notice. Neither leaves your device and clearing site data removes both.
By Google, on the pages that carry advertising: cookies and local storage belonging to Google, subject to your consent choice. There is no tag manager, no tracking pixel of our own, and no font loaded from another domain.
Page views are counted, using Simple Analytics. It sets no cookie and writes nothing to your device, which is why it is not part of the consent choice above and why refusing advertising does not switch it off. It records the page visited and where the visit came from, and there is no profile of you anywhere for that to be added to.
If you have an account, two more cookies exist. A session cookie, which is how the server knows it is you and which nothing but the server can read; and naw_plan, which holds one word naming your plan and is readable by the page. That second one authorises nothing and the server never trusts it. It exists so a paying visitor is not shown a flash of the advertising they paid to remove while the real answer is still arriving.
Four third-party scripts exist on this site and no others: Google's advertising tag, the Cookiebot dialog that decides whether it is allowed to run, that page counter, and the Cloudflare Turnstile check on the sign-up form. None of the four reaches the /app workspace, where the second policy above forbids them outright, and only the last reaches /account.
Payment is handled by Stripe, on Stripe's own pages. Your card details are never on this site and never reach this server, which is the reason paying happens somewhere else rather than in a form here.
What this tool expects of you
It is built for content you own or are authorised to process. Removing provenance metadata from someone else’s work, or stripping credentials to disguise where something came from, is not what this is for. The tool is deliberately incapable of forging a signature or making a modified file appear untouched.
Changes
Advertising was added on 12 August 2026, and this page was rewritten the same day rather than after someone noticed. This paragraph used to end by promising that if some feature genuinely required a server, the interface would say so at the point of use and not only here. One now does, and it does.
Accounts and payment were added on 16 August 2026, and three sentences on this page stopped being true the moment they were: that there is no backend, no database and no storage; that there is no account; and that exactly three third-party scripts exist. All three are corrected above rather than quietly dropped, because a privacy page that omits the awkward part is worth nothing. What did not change is the part that matters: every tool except the one that redraws a photograph still runs entirely in your browser, still uploads nothing, and still needs no account.
Removing a learned watermark such as SynthID means regenerating the picture through a diffusion model. Filtering pixels does not reach it, at any strength, because it is trained against exactly that; and the model is far too large to run on most devices. So the image tool sends your picture to this same domain, has it redrawn, and sends it back. You are asked first, in a dialog naming what is about to happen, every time.
The work takes minutes rather than seconds, so the picture is held in storage on this site’s own account while it runs, and the GPU is given a link that reaches that one file, for one hour, and nothing else. Your browser only ever talks to this domain.
What is kept, and for how long: the upload is deleted the moment its job finishes, the result is deleted as you download it, and anything still there for any reason is gone within 24 hours. Nothing is logged and nothing is used for training. Every other tool on this site still transmits nothing at all, and that is enforced by the policy above rather than promised here.