MiniPNG

Remove AI Metadata from Files Online

Strip Hidden AI Fingerprints, C2PA Credentials and All Metadata, and See Exactly What Was Removed

5
(10)
100% Free Secure & Private
Drag & Drop

or click to browse from your device

Remove AI Metadata From Any File — Even the Mark Hidden Inside a PDF’s Pictures

Every file remembers how it was made. An image generated by ChatGPT, DALL·E, Gemini or Adobe Firefly leaves the generator with a signed C2PA manifest and XMP provenance tags stitched into it — digitalSourceType, trainedAlgorithmicMedia, the model’s own name — and those travel with the file to every platform it lands on. Text written by an AI can arrive seeded with characters you cannot see: zero-width spaces and joiners that survive copy-paste and act as a watermark. This tool strips all of it, and it clears everything else the file was quietly carrying too. On a standalone image it does all of that without decoding a single pixel, so the picture that comes back is the one that went in.

It removes every trace of identity, not only the AI ones

AI provenance is the specialty, not the limit. The same pass clears the rest of what your file knows about you: author and creator names, GPS coordinates, camera make, model and serial number, lens data, creation and modification timestamps, and the editing history left behind by whatever software touched it last. A photo you publish should not tell a stranger which street you stood on or which laptop you edited it on. When the file comes back, it knows nothing about you, your device, or the tool that produced it.

The characters you cannot see in AI-written text

Text is the part most cleaners ignore entirely. Some models seed their output with zero-width spaces, zero-width joiners and word-joiners — invisible on screen, invisible in print, and perfectly intact after you copy the text into a document, an email or a CMS. They are a watermark in everything but appearance. This tool finds them and takes them out, and for plain-text files it offers two further passes you can switch on: normalising look-alike Unicode characters, and mapping confusable letters back to plain ASCII. Those two touch the text itself, so by design they apply only to text files — never to an image, a PDF or an Office document.

It reads the fingerprint before it deletes it

This is the part no other free metadata cleaner does. Before anything is removed, the file is inspected and the mark is identified, so the report names the generator behind it rather than saying that “something was removed”. When the file names its maker, you are told which one: OpenAI (ChatGPT / GPT / DALL·E), Google (Gemini / Imagen), Anthropic (Claude), Adobe Firefly, Midjourney, Stability AI (Stable Diffusion), xAI (Grok), Leonardo AI, Microsoft Copilot or Black Forest Labs (FLUX). A file whose mark names none of them is still fully cleaned — the report simply says the generator was not named inside the file.

And it tells you when there was nothing hidden at all

A cleaner that always says “done” teaches you nothing. This one answers the question you actually came with: was there an AI fingerprint in this file in the first place? Every job returns a per-file report. A file that was carrying a mark is labelled with the vendor and reads “Removed hidden AI provenance marks from this file”, naming the fingerprint. A file that was carrying nothing is marked Verified clean and says so outright: “No AI provenance marks were found in this file.” Both answers are useful — one confirms the trace is gone, the other confirms the file never had one — and both come with an itemised list, in plain language, of exactly what was taken out.

The mark hidden inside a PDF’s pictures

A scanned page or an exported report is a PDF wrapped around a picture, and a C2PA manifest can sit inside that picture rather than in the document’s own properties. Clean the document layer alone and the file looks spotless to a metadata viewer while the mark is still there, one level down. This tool opens the embedded images and clears those too, so a PDF whose document properties were already empty still comes back with nothing left to find.

Nothing is decoded, unless the mark is inside the picture

On a standalone image the file is never opened, re-drawn or re-compressed. Your PNG comes back with its pixel data byte-identical and your JPEG with its scan data untouched: same colours, same sharpness, no generation loss. PDFs keep their text, fonts and layout, and Office documents keep their content and formatting.

There is one exception, and we would rather name it than bury it. A mark sitting inside a picture embedded in a PDF cannot be reached without decoding that picture and writing it again, so in that one case its pixels change very slightly and the file usually grows. It happens only where a mark is actually found: an embedded picture that was already clean is passed through untouched, byte for byte. The result page counts how many images were re-encoded and names them, and it only tells you the file came back byte-for-byte identical when that count is zero.

The honest limit: a visible watermark stays visible

This tool works on the metadata layer — hidden tags, signed manifests, invisible characters. It does not erase a logo, a caption or a stamped mark that was burned into the pixels of your picture, because that mark is part of the image, and removing it would mean repainting the photo and degrading it. Any tool promising to wipe a visible watermark without altering your image is either not doing it or quietly handing you a blurred file. If what you need is the hidden provenance data and the invisible text marks, you are on the right page. If it is a visible logo, you need an image editor, not a metadata cleaner.

Which files it works on

The type is detected from the file’s own bytes rather than its extension, so a file saved with the wrong ending is still handled correctly and comes back in the right format. Original filenames are preserved — Arabic and Chinese names included — and a password-protected PDF is handled the usual way: supply the password and the cleaned copy comes out unlocked.

CategoryFormats
ImagesPNG · JPG / JPEG · WebP · AVIF · HEIC / HEIF · GIF · BMP · TIFF · SVG
DocumentsPDF
OfficeDOCX · XLSX · PPTX
Books and open formatsEPUB · ODT
TextHTML · Markdown · TXT

It checks its own work

Most cleaners save the file and assume the job is done. This one re-opens its own output and inspects it a second time, looking for the C2PA manifest and every AI tag it just removed. A file is reported clean only when they are verifiably gone — so “clean” here means proved, not promised. A file whose internal structure resisted a full rewrite is flagged honestly rather than handed back as a false success. The removal engine itself is the open-source, MIT-licensed watermarks-remover project, so the exact logic that touches your files is public and auditable rather than a black box.

What you get

  • C2PA and Content Credentials manifests, XMP provenance tags and “Generated by” strings removed from images, PDFs and Office files
  • Invisible zero-width characters stripped out of AI-written text, including the ones that survive copy-paste
  • Author names, GPS coordinates, camera and device details, timestamps and edit history cleared in the same pass
  • A per-file report that names the AI behind the fingerprint — or marks the file Verified clean when no AI provenance marks were found
  • Standalone images returned with their pixel data byte-identical: nothing is decoded, re-compressed or re-drawn
  • Marks hidden inside pictures embedded in a PDF found and cleared, with every re-encoded image counted and named on the report
  • Verified results — the output is re-inspected after cleaning, and files are deleted from the server an hour later

What changed recently

3 September 2026 — the cleaner now looks inside pictures that are embedded in a PDF, so an AI mark hiding in a scanned page is found and removed instead of being missed. The report was rebuilt at the same time: it names document properties as their own item, tells you when an embedded picture had to be re-encoded, and no longer lists anything it did not actually remove.

What’s next?

Need only the camera and location data off a photo? Remove Photo Metadata does exactly that. Working with a document instead? Remove PDF Metadata clears the author, producer and timestamps from a PDF, and Flatten PDF makes filled fields and annotations permanent before you send it out.

Frequently Asked Questions

It is the hidden record of how a file was made. Generate or edit an image with a tool like DALL·E, Gemini or Adobe Firefly and it embeds a C2PA / Content Credentials manifest — a cryptographically signed statement that the file is AI-made — plus XMP tags such as digitalSourceType and trainedAlgorithmicMedia and the model’s own name. AI-generated Office documents carry “Generated by” and generator strings in their properties, and AI-written text can contain invisible zero-width characters that act as a watermark. None of it is visible, all of it travels with the file, and any platform, employer or checker can read it back. Removing it is a privacy and hygiene step for content you own and are authorised to publish — the same reason people strip GPS coordinates out of their photos before posting them.

No — and any tool that claims it can without touching your image is misleading you. This works on the metadata layer: hidden tags, signed manifests and invisible characters. It never decodes or re-draws the picture, which is precisely why your image comes back pixel-for-pixel identical and loses no quality. A visible mark — a logo, a caption, a watermark burned into the pixels — is part of the image itself, and erasing it would mean repainting the photo and degrading it. We would rather state the boundary honestly than hand you a blurred file. For hidden provenance data and invisible text marks this is exactly the right tool; for a visible logo you need an image editor.

When a file names its generator in the marks it carries, the report identifies it by vendor: OpenAI (ChatGPT / GPT / DALL·E), Google (Gemini / Imagen), Anthropic (Claude), Adobe Firefly, Midjourney, Stability AI (Stable Diffusion), xAI (Grok), Leonardo AI, Microsoft Copilot and Black Forest Labs (FLUX). A file whose mark names none of these is still fully cleaned — the report just says the generator was not named in the file. And the naming is honest: a vendor is listed only when its fingerprint was genuinely present before cleaning and genuinely gone after, because the tool re-inspects its own output rather than guessing from the input.

All of it. AI provenance is the specialty, not the scope. In the same pass the file loses its author and creator names, GPS coordinates, camera make, model and serial number, lens and exposure data, creation and modification timestamps, and the editing history left by the software that last touched it. If you want only one of those jobs there are narrower tools here — Remove Photo Metadata for a photo’s EXIF, Remove PDF Metadata for a document’s properties — but this page is the one that clears everything at once and reports on the AI layer specifically.

Almost never, and when it does we say so on the report. A standalone image is never decoded: your PNG comes back with byte-identical pixel data and your JPEG with its scan data untouched, so there is no generation loss and the file size barely moves. PDFs keep their text, fonts and layout, and Office files keep their content and formatting. The single exception is an AI mark sitting inside a picture embedded in a PDF, which cannot be reached without rewriting that picture; its pixels then change very slightly and the file usually grows. Every image that happened to is counted and named on the result page, and the tool only tells you your file came back byte-for-byte identical when it happened to none.

The tool proves it rather than assuming it. After cleaning each file it re-opens the output and inspects it again for C2PA and AI tags, and reports the file as clean only when they are verifiably gone; a file whose structure resisted a full rewrite is flagged honestly instead of being handed back as a false success. You get a plain-language summary of what was removed — for example “Removed hidden AI provenance marks from this file - the fingerprints identify: OpenAI (ChatGPT / GPT / DALL·E)” — plus an itemised list with counts and a per-file breakdown. A file that had nothing hidden is labelled Verified clean and reads “No AI provenance marks were found in this file.”, so you never have to guess which of the two happened.

Yes, and that is the part most cleaners miss. A C2PA manifest can live inside the embedded picture rather than in the PDF's own document properties, so a tool that clears only the document layer hands back a file that looks spotless while the mark is still one level down. This one opens the embedded images and clears them as well, so a PDF whose document properties were already empty still comes back with nothing left to find. Reaching a mark down there means rewriting that picture, so those files are flagged as re-encoded on the report rather than quietly changed.

Using Remove AI Metadata is quick and easy: upload up to 5 file(s) (.png, .jpg, .jpeg, .webp, .avif, .heic, .heif, .gif, .bmp, .tiff, .tif, .svg, .pdf, .docx, .xlsx, .pptx, .epub, .odt, .html, .htm, .md, .markdown, .txt) from your device, Google Drive, or a direct URL, adjust the settings to fit your needs, then click the 'Remove AI Metadata' button. Your files are processed in seconds and ready to download right away.

Absolutely. Your files are uploaded over a secure encrypted connection (HTTPS) and processed automatically — no one ever views them. All files are automatically deleted from our servers within 1 hour, and you can remove any file instantly yourself using the trash icon.

Yes! Remove AI Metadata is completely free. No registration, no email address, and no hidden costs — simply upload your files and download the results.

No downloads or installation required. MiniPNG works entirely online in your web browser, so you can use it on any desktop, laptop, tablet, or phone — Windows, Mac, Linux, Android, or iOS.

You can upload files up to 100MB each. This limit keeps processing fast and reliable for everyone.

We'd love to hear from you! Whether you found a bug, need help, or want to suggest a new tool, reach out through our Contact Us page and our team will get back to you quickly.