Privacy policy
MetadataRemover was built around a simple rule: your images never leave your device. This page explains what that means in practice.
What happens to your files
Every tool on this site — the metadata cleaner, analyzer, converters and editors — runs entirely in your web browser using the HTML5 File API and canvas. When you select an image, it is read into your browser's memory, processed locally, and saved back to your device by you. At no point is image data transmitted over the network. You can verify this with your browser's developer tools, or by using the tools while offline.
What we collect
- Images and metadata: nothing. We never receive, see, store or process your files on a server — there is no upload endpoint.
- Accounts: none exist. There is no registration, login or user database.
- Cookies and similar technologies: Plausible Analytics is cookieless and measures aggregate traffic. Microsoft Clarity may use cookies or similar technologies and is loaded only on this site's production hosts. You can use your browser or privacy tools to block or clear provider storage.
- Analytics: we use Plausible for cookieless aggregate traffic measurement and Microsoft Clarity for usability insights. Neither service receives file names, file contents or image metadata.
Analytics
We use Plausible Analytics, hosted at plausible.shipsolo.io, for cookieless aggregate traffic measurement. It processes limited request information such as the page URL, referrer, browser and device type, and country-level location derived from the network request. Plausible does not receive your images, file names or embedded metadata, and the events described below use an empty props object.
We also use Microsoft Clarity to see how visitors interact with pages — heatmaps and session recordings — so we can improve usability. Clarity masks sensitive content by default and never receives your images or their metadata. Clarity may use cookies or similar technologies and is loaded only on this site's production hosts. You can use browser or privacy controls to block or clear provider storage. How Microsoft processes this data is described in the Microsoft Privacy Statement.
To understand whether the tools work end to end, both services receive four product milestone events: file_scanned, metadata_viewed, clean_executed and download_completed. Each event is name-only. Plausible receives an empty props object; neither service receives a file name, file content, metadata value, GPS or other location from a file, file size or identifier. Duplicate milestones for the same image are discarded in your browser before anything is sent. These events are only dispatched on this site's production domain.
Third-party services
Some tools optionally load open-source libraries (for example for OCR, face detection or HEIC decoding) from a public CDN when — and only when — you use the corresponding feature. Those requests download code and model files to your browser; they do not contain your images. All computation still happens on your device.
Data retention
Local file bytes and embedded metadata are read and processed in your browser; they are not received or retained by MetadataRemover. Analytics providers may process limited request and milestone data under their own provider policies. This policy does not state a fixed retention period for that provider processing. Closing the tab clears the file data your browser held in memory.
Your rights
We do not offer accounts and do not receive your files. Aggregate or pseudonymous analytics may not identify an individual request, but questions about analytics or privacy can be sent to [email protected]. We will review your message and explain what information is available for the relevant provider to handle.
Changes
If this policy changes, the updated version will be posted on this page with a new revision date.
Contact
Questions about this policy? Email us at [email protected].