What does this file reveal about you?

Every file carries fields nobody typed — a name, a camera serial, the exact spot on Earth where the shutter fired. Read the ones that point at a person, before you send it to one.

Drop a document or image here, or browse

PDF, Word, Excel, PowerPoint, JPEG, PNG, WebP, HEIC · max 10 MB · processed in memory, never stored

Nothing you want to upload? See what an ordinary photo gives away:

A fictional snapshot taken in a public park. Nobody typed any of it, and it names the photographer, her phone, that phone's serial number, and the spot on Earth she was standing on. Download it and check the findings in any tool you like.

We read your file. We never change it. Tamperlens has no code path that writes a document — the bytes are parsed in memory, the answer is JSON, and nothing survives the response. There is deliberately no "download a cleaned copy" button here: producing a stripped file is a different product with different promises, and this one's promise is that your file goes home exactly as it arrived. How that is enforced.

What actually leaks

Metadata is written by the software, not by you, which is why it so often says more than intended. None of what follows is exotic or hidden: it is what an ordinary save, an ordinary export and an ordinary phone camera write by default, and it is readable by anyone who receives the file and thinks to look.

Your name — and the name of whoever really wrote it

Author, Creator, Company, Manager and, in Office files, lastModifiedBy, which records the person who saved the document last rather than the person who wrote it. That is the field that tells a hiring manager a CV was last touched by a recruiter, tells a counterparty which partner actually drafted the "client's" contract, and tells a reader of a published report which of three organisations produced it. Comment and tracked-change authors sit alongside it, and a document with the changes accepted can still name everyone who suggested one.

The machine, the account and the folder it sat in

Photographs carry HostComputer; PDFs and Office packages carry original filenames and, often enough, a full path from the machine that made them. A path is a sentence: the account name in Users\ is usually a real person's name, and the folder above the file is usually what the file is for. "Redundancy", "Lawsuit", "Offer B" — the directory says what the document itself was careful not to.

Where the photograph was taken

Phones write latitude and longitude into the EXIF GPS block by default, in degrees, minutes and seconds, which Tamperlens decodes to signed decimal degrees. The precision is a building, not a city. A photograph of a room is a photograph of an address; a marketplace listing shot at home is your home; a document photographed on a kitchen table is that kitchen.

Which camera — and the fact that it is the same camera

Make and Model are the obvious pair. BodySerialNumber, LensSerialNumber and ImageUniqueID are the ones that matter: a serial number is a stable identifier for one physical device, so two photographs posted years apart under two different names can be tied to one camera. Anonymity that depends on nobody comparing files is not anonymity.

The thumbnail of the picture you cropped

EXIF carries a small preview of the image in a second directory, and some editors update the picture without updating the preview. A photograph cropped to remove a face, a screen or a document can therefore still carry a thumbnail of the frame before the crop. This has been a real, repeated source of accidental disclosure, and it is the one item on this page that most people flatly do not believe until they see it in their own file.

PNG text chunks, and prompts written out verbatim

PNG has a text section that anything may write into, and generative tools write a great deal: the model, the settings, and frequently the prompt word for word. Screenshot and editing tools add their own chains. It is metadata in the ordinary sense, and it is quoted back here exactly as stored.

Inside a Word file, another file's metadata

A .docx is a ZIP, and a photograph pasted into one keeps the EXIF the camera wrote — including the coordinates. Tamperlens opens the package and reads those too, so a document that has never been near a camera can still be carrying the location of the room a picture in it was taken in.

Who this actually matters to

"Check your metadata" is advice that sounds paranoid until it is specific. Five situations where the fields above have a concrete cost.

  • Job applicants. A CV is read by strangers at organisations you have not chosen yet. It commonly names your current employer's template, the machine you wrote it on during work hours, and — through revision timestamps — when.
  • Tenants, buyers and anyone answering a listing. The documents a landlord or agent asks for are payslips, statements and proofs of address, sent to a private individual with no data retention policy. Photographs of them carry the address the photograph was taken at, which is frequently the address you are trying to leave.
  • Lawyers, and their clients. A filing that names the drafting associate, the client folder and the internal matter number is a filing that told the other side about your practice. Exhibits assembled from photographs bring their own locations with them.
  • Journalists and their sources. A leaked document carries the machine it was copied on and often the account name of the person who copied it. Publishing the file as received has ended sources' careers, and the fields responsible were visible the whole time.
  • Teams publishing under GDPR or the LGPD. Author names, internal usernames and machine names in a published PDF are personal data you disclosed without deciding to. It is a small disclosure, it is entirely avoidable, and it is the kind that turns up in an audit rather than in a headline.

How to check a file here

Drop it above. The report opens with the personal summary — the entries that name a person, a place, a time or a device, grouped as who, where, when and which device — and the full container-by-container tables follow underneath, because a summary you cannot verify is a claim.

Coordinates are shown as a link, and the link is the only thing on this page that can send anything anywhere: nothing is geocoded, no map is embedded, and a third party learns your coordinates only if you choose to click. Where a file carries an embedded thumbnail with its own location, that row links to its coordinates rather than the photograph's — the two disagreeing is exactly the disclosure worth seeing.

What to do when something leaks

This page will not clean the file, so the honest part of the answer is what to do elsewhere. Four options, with their real costs.

  • Re-export from the tool that made it. The most reliable and the least destructive. In Word, Excel and PowerPoint: File → Info → Check for Issues → Inspect Document, remove what it lists, then export a fresh PDF. LibreOffice has Remove personal information on saving. The point is the fresh export: editing the old file leaves the old history in it.
  • Print to PDF. Genuinely effective against document metadata and revision history, and it is a real trade-off rather than a free win: you keep the text layer but lose bookmarks, form fields, tagging and any digital signature, and the new file names the print driver as its producer. Exporting to flattened images goes further and costs you searchable, selectable, screen-readable text — that is a genuine accessibility loss, not a footnote.
  • Strip EXIF at the operating system. On Windows, right-click the file → Properties → Details → Remove Properties and Personal Information. On macOS, the Photos app drops location when you turn it off in the share options, and exiftool -all= photo.jpg removes everything on any platform. Note that some tools remove the visible tags and leave the embedded thumbnail — which is why re-checking is worth the thirty seconds.
  • Turn it off at the source. Location tagging is a camera setting on every phone, and the photograph that never carried coordinates is the only one you cannot forget to clean.

Stripping is visible too. An image with no metadata at all is itself a signal in the fraud report, because a camera writes plenty and a stripped file writes none. That is not an accusation of anything — it is one of the eighteen signal families, reported with its benign causes attached. But if the file is going to somebody who screens documents, a clean re-export from the authoring tool reads more naturally than an original with its metadata scraped out.

What this cannot tell you

A privacy checker that implies more coverage than it has is worse than none. Five limits, stated plainly.

  • It reads the file's fields, not its content. A face in the background, a street sign, a screen with an email open, a name in the body text — none of that is metadata, and none of it is here. The most damaging thing in a photograph is usually in the photograph.
  • Text under a black box is a different failure. Covering a name with a rectangle hides it from a reader and removes nothing from the file. That has its own page: the redaction check.
  • There is no score and no "safe to share" verdict. Whether an author name is a leak depends entirely on who receives the file, and this product does not issue verdicts about your situation. You get the list; the judgment is yours.
  • An empty report is not proof of a clean file. It may mean the metadata was stripped, that the producing tool writes none, or that the format carries little. Absence of evidence is reported as absence of evidence.
  • A very large file is summarised, not exhausted. Caps exist so one document cannot occupy the service, and when one bites the report says so. The count is then a floor rather than a total.

The same parse, three questions

One engine reads the file; which page you are on decides which question it answers. This one asks what the file says about you. The metadata viewer is the same report without the framing — every key in every container, for when you want the whole picture rather than the personal subset. The free checker asks the opposite question — whether the document was edited after signing, whether its dates contradict each other — and runs eighteen signal families to answer it. And the redaction check answers the other half of "what is in this file that you did not mean to send": whether the words under the black bars are still readable.

In the API

POST /api/v1/metadata returns the same report as JSON, including the personal array this page leads with and a decoded gps pair when the file carries one. It costs one document from your monthly quota and works without an API key, exactly like the checker. See the reference.

Common questions

How do I remove metadata from a PDF?

Not here — this page reads files and never writes them. In Word, Excel and PowerPoint use File → Info → Check for Issues → Inspect Document, and remove what it finds, then export a fresh PDF. In LibreOffice, tick Remove personal information on saving. Exporting a fresh PDF from the authoring tool rather than editing the old one is what actually drops the accumulated history, because the history lives in the file you are replacing.

Does my photo have GPS coordinates in it?

Drop it above and you will see. Phones write location into the EXIF GPS block unless location tagging was turned off for the camera, and the coordinates are precise enough to name a building rather than a city. Messaging apps and most social networks strip EXIF on upload; email attachments, cloud drives, marketplace listings and files sent to a person do not.

Is my file uploaded or stored?

The file is sent over HTTPS, parsed in memory and never written to disk. The report goes back to your browser and is kept nowhere. Coordinates are part of that report, so they travel back to you and no further: nothing is geocoded, no map is embedded, and a coordinate opens a third-party map only when you click it. The privacy policy spells this out.

Does stripping metadata make a document look suspicious?

It can, and that is worth knowing before you strip. An image with no metadata at all is itself a signal in the fraud report, because a camera writes plenty and a stripped file writes none. That is not an accusation of anything, but if the file is going to a reviewer who checks such things, a clean re-export from the authoring tool reads more naturally than a stripped original. The field guide covers that family.

Can you give me a cleaned copy of the file?

No, and there is no plan to hide one behind a paid tier. Tamperlens has no code path that writes a document. Producing a stripped file is a different product with a different promise, and a sanitiser that quietly corrupts a signed PDF is worse than one that does not exist. This page tells you what is in there; the fix belongs in the tool that made the file.