What does this file reveal about you?

Every file carries fields nobody typed: a name, a camera serial, the exact spot on Earth where the shutter fired. Read the ones that point at a person, before you send it to one.

Drop a document or image here, or

PDF, Word, Excel, PowerPoint, JPEG, PNG, WebP, HEIC · max 10 MB

The file is sent over HTTPS, parsed in memory and discarded when the response is written. The report goes to your browser and stays there.

Nothing you want to upload? See what an ordinary photo gives away:

A fictional snapshot taken in a public park. Nobody typed any of it, and it names the photographer, her phone, that phone's serial number, and the spot on Earth she was standing on. Download it and check the findings in any tool you like.

We read your file. We never change it. Tamperlens has no code path that writes a document. The bytes are parsed in memory, the answer is JSON, and nothing survives the response. There is deliberately no "download a cleaned copy" button here: producing a stripped file is a different product with different promises, and this one's promise is that your file goes home exactly as it arrived. How that is enforced.

The file goes one way and the answer comes back. There is no branch off this path: not to a disk, not to a log, not to anyone else.
your browser the file you chose the parser bytes, held in memory the report JSON, and nothing else your browser and it stops here HTTPS parsed returned NOWHERE ELSE ON THE PATH a disk · a log · a queue · a person reviewing it · a third-party service · a geocoder The engine also has no code path that writes a document, so your file goes home exactly as it arrived. THE ONE THING THAT CAN LEAVE, AND ONLY IF YOU ASK IT TO A coordinate in the report is drawn as a link. Nothing is geocoded here and no map is embedded a third party learns where the photograph was taken only when you click.

How the write-side half of this is enforced in the code is on the security page; the retention side is in the privacy policy.

What actually leaks

Metadata is written by the software, not by you, which is why it so often says more than intended. None of what follows is exotic or hidden: it is what an ordinary save, an ordinary export and an ordinary phone camera write by default, and it is readable by anyone who receives the file and thinks to look.

Nobody typed any of this. Every field below is written by default, by an ordinary save, an ordinary export or an ordinary camera.
CONTAINER WHERE THE FIELDS THAT NAME A PERSON, A PLACE OR A DEVICE SIT PDF Info dictionary and XMP packet: Author · Creator · Company · Manager plus the original filename, and often a full path from the machine that wrote it JPEG · HEIC IFD0, Make · Model · HostComputer GPS IFD, latitude and longitude EXIF sub-IFD: BodySerialNumber · LensSerialNumber · ImageUniqueID IFD1: a second, smaller copy of the picture, updated on its own schedule PNG tEXt and iTXt chunks: anything at all may write into them generative tools write the model, the settings and frequently the prompt word for word .docx: a ZIP docProps/core.xml: creator · lastModifiedBy · revision timestamps word/media/. A pasted photograph keeps the EXIF its camera wrote, coordinates included Two of these are worth pairing: lastModifiedBy names whoever saved the file last, not whoever wrote it.

Your name, and the name of whoever really wrote it

Author, Creator, Company, Manager and, in Office files, lastModifiedBy, which records the person who saved the document last rather than the person who wrote it. That is the field that tells a hiring manager a CV was last touched by a recruiter, tells a counterparty which partner actually drafted the "client's" contract, and tells a reader of a published report which of three organisations produced it. Comment and tracked-change authors sit alongside it, and a document with the changes accepted can still name everyone who suggested one.

The machine, the account and the folder it sat in

Photographs carry HostComputer; PDFs and Office packages carry original filenames and, often enough, a full path from the machine that made them. A path is a sentence: the account name in Users\ is usually a real person's name, and the folder above the file is usually what the file is for. "Redundancy", "Lawsuit", "Offer B". The directory says what the document itself was careful not to.

Where the photograph was taken

Phones write latitude and longitude into the EXIF GPS block by default, in degrees, minutes and seconds, which Tamperlens decodes to signed decimal degrees. The precision is a building, not a city. A photograph of a room is a photograph of an address; a marketplace listing shot at home is your home; a document photographed on a kitchen table is that kitchen.

Which camera, and the fact that it is the same camera

Make and Model are the obvious pair. BodySerialNumber, LensSerialNumber and ImageUniqueID are the ones that matter: a serial number is a stable identifier for one physical device, so two photographs posted years apart under two different names can be tied to one camera. Anonymity that depends on nobody comparing files is not anonymity.

The thumbnail of the picture you cropped

EXIF carries a small preview of the image in a second directory, and some editors update the picture without updating the preview. A photograph cropped to remove a face, a screen or a document can therefore still carry a thumbnail of the frame before the crop. This has been a real, repeated source of accidental disclosure, and it is the one item on this page that most people flatly do not believe until they see it in their own file.

Cropping changes the picture. In some editors it does not change the preview, and the preview is a second picture in the same file.
ONE FILE · TWO PICTURES the main image: what any viewer shows the cropped frame IFD1: the embedded preview the part you cropped out the cropped frame A face, a screen or a document removed by a crop can still be sitting in the thumbnail of the file you sent. Where a thumbnail carries coordinates of its own, the report links to those rather than the photograph's. The two disagreeing is exactly the disclosure worth seeing.

PNG text chunks, and prompts written out verbatim

PNG has a text section that anything may write into, and generative tools write a great deal: the model, the settings, and frequently the prompt word for word. Screenshot and editing tools add their own chains. It is metadata in the ordinary sense, and it is quoted back here exactly as stored.

Inside a Word file, another file's metadata

A .docx is a ZIP, and a photograph pasted into one keeps the EXIF the camera wrote, including the coordinates. Tamperlens opens the package and reads those too, so a document that has never been near a camera can still be carrying the location of the room a picture in it was taken in.

Who this actually matters to

"Check your metadata" is advice that sounds paranoid until it is specific. Five situations where the fields above have a concrete cost.

“Check your metadata” sounds paranoid until it is specific. Each row is one field with a cost somebody actually paid.
WHO THE FIELD THAT COSTS THEM job applicants the current employer's template, the machine, and when you wrote it tenants and buyers the coordinates of the address you are trying to leave lawyers, and their clients the drafting associate, the client folder, the internal matter number journalists and sources the machine a document was copied on, and the account that copied it teams publishing under GDPR or the LGPD author names and internal usernames in a published PDF: personal data you disclosed without deciding to
  • Job applicants. A CV is read by strangers at organisations you have not chosen yet. It commonly names your current employer's template, the machine you wrote it on during work hours, and, through revision timestamps, when.
  • Tenants, buyers and anyone answering a listing. The documents a landlord or agent asks for are payslips, statements and proofs of address, sent to a private individual with no data retention policy. Photographs of them carry the address the photograph was taken at, which is frequently the address you are trying to leave.
  • Lawyers, and their clients. A filing that names the drafting associate, the client folder and the internal matter number is a filing that told the other side about your practice. Exhibits assembled from photographs bring their own locations with them.
  • Journalists and their sources. A leaked document carries the machine it was copied on and often the account name of the person who copied it. Publishing the file as received has ended sources' careers, and the fields responsible were visible the whole time.
  • Teams publishing under GDPR or the LGPD. Author names, internal usernames and machine names in a published PDF are personal data you disclosed without deciding to. It is a small disclosure, it is entirely avoidable, and it is the kind that turns up in an audit rather than in a headline.

How to check a file here

Drop it above. The report opens with the personal summary: the entries that name a person, a place, a time or a device, grouped as who, where, when and which device, and the full container-by-container tables follow underneath, because a summary you cannot verify is a claim.

Coordinates are shown as a link, and the link is the only thing on this page that can send anything anywhere: nothing is geocoded, no map is embedded, and a third party learns your coordinates only if you choose to click. Where a file carries an embedded thumbnail with its own location, that row links to its coordinates rather than the photograph's. The two disagreeing is exactly the disclosure worth seeing.

What to do when something leaks

This page will not clean the file, so the honest part of the answer is what to do elsewhere. Four options, with their real costs.

Every option that removes more than the first one takes something real away from the document. The costs are the point of the table.
WHAT YOU DO WHAT GOES WHAT IT COSTS re-export from the tool that made it the accumulated document history nothing export fresh; editing the old file keeps it print to PDF document metadata and revision history bookmarks · form fields · tagging · any digital signature export to flattened images everything, including the text layer searchable, selectable, screen-readable text: a real accessibility loss strip EXIF at the OS, or exiftool -all= the visible tags some tools leave the embedded thumbnail behind: re-check afterwards A fifth option costs nothing at all and cannot be forgotten: turn location tagging off in the camera.
  • Re-export from the tool that made it. The most reliable and the least destructive. In Word, Excel and PowerPoint: File → Info → Check for Issues → Inspect Document, remove what it lists, then export a fresh PDF. LibreOffice has Remove personal information on saving. The point is the fresh export: editing the old file leaves the old history in it.
  • Print to PDF. Genuinely effective against document metadata and revision history, and it is a real trade-off rather than a free win: you keep the text layer but lose bookmarks, form fields, tagging and any digital signature, and the new file names the print driver as its producer. Exporting to flattened images goes further and costs you searchable, selectable, screen-readable text, that is a genuine accessibility loss, not a footnote.
  • Strip EXIF at the operating system. On Windows, right-click the file → Properties → Details → Remove Properties and Personal Information. On macOS, the Photos app drops location when you turn it off in the share options, and exiftool -all= photo.jpg removes everything on any platform. Note that some tools remove the visible tags and leave the embedded thumbnail, which is why re-checking is worth the thirty seconds.
  • Turn it off at the source. Location tagging is a camera setting on every phone, and the photograph that never carried coordinates is the only one you cannot forget to clean.

Stripping is visible too. An image with no metadata at all is itself a signal in the fraud report, because a camera writes plenty and a stripped file writes none. That is not an accusation of anything. It is one of the nineteen signal families, reported with its benign causes attached. But if the file is going to somebody who screens documents, a clean re-export from the authoring tool reads more naturally than an original with its metadata scraped out.

What this cannot tell you

A privacy checker that implies more coverage than it has is worse than none. Five limits, stated plainly.

This reads the file's fields. It does not read the picture, and the most damaging thing in a photograph is usually in the photograph.
READ: THE FILE'S FIELDS Author, Creator, lastModifiedBy GPS latitude and longitude camera, lens and image serial numbers PNG text chunks, quoted verbatim the embedded thumbnail NOT READ: THE CONTENT ITSELF a face in the background a street sign, a door number a screen with an email open a name written in the body text words under a black box: a separate check There is no score and no “safe to share” verdict: whether a name is a leak depends on who receives the file. An empty report is not proof of a clean file: the format may carry little, or somebody stripped it already.
  • It reads the file's fields, not its content. A face in the background, a street sign, a screen with an email open, a name in the body text. None of that is metadata, and none of it is here. The most damaging thing in a photograph is usually in the photograph.
  • Text under a black box is a different failure. Covering a name with a rectangle hides it from a reader and removes nothing from the file. That has its own page: the redaction check.
  • There is no score and no "safe to share" verdict. Whether an author name is a leak depends entirely on who receives the file, and this product does not issue verdicts about your situation. You get the list; the judgment is yours.
  • An empty report is not proof of a clean file. It may mean the metadata was stripped, that the producing tool writes none, or that the format carries little. Absence of evidence is reported as absence of evidence.
  • A very large file is summarised, not exhausted. Caps exist so one document cannot occupy the service, and when one bites the report says so. The count is then a floor rather than a total.

The same parse, three questions

One parse of one file. The page you are on decides which question gets asked of it: the bytes read are the same bytes every time.
one parse of one file /privacy-check “what does this file say about me?” the personal subset, grouped who / where / when / which device /metadata “show me everything that is in there” every key in every container, no framing / “was this document changed after issue?” eighteen signal families, with their benign causes /redaction-check “are the words under the bars readable?” paint order in the page content stream The other half of “what is in this file that I did not mean to send” is the right-hand box: a black bar removes nothing.

One engine reads the file; which page you are on decides which question it answers. This one asks what the file says about you. The metadata viewer is the same report without the framing: every key in every container, for when you want the whole picture rather than the personal subset. The free checker asks the opposite question (whether the document was edited after signing, whether its dates contradict each other), and runs eighteen signal families to answer it. And the redaction check answers the other half of "what is in this file that you did not mean to send": whether the words under the black bars are still readable.

In the API

POST /api/v1/metadata returns the same report as JSON, including the personal array this page leads with and a decoded gps pair when the file carries one. It costs one document from your monthly quota and works without an API key, exactly like the checker. See the reference.

Common questions

How do I remove metadata from a PDF?

Not here. This page reads files and never writes them. In Word, Excel and PowerPoint use File → Info → Check for Issues → Inspect Document, and remove what it finds, then export a fresh PDF. In LibreOffice, tick Remove personal information on saving. Exporting a fresh PDF from the authoring tool rather than editing the old one is what actually drops the accumulated history, because the history lives in the file you are replacing.

Does my photo have GPS coordinates in it?

Drop it above and you will see. Phones write location into the EXIF GPS block unless location tagging was turned off for the camera, and the coordinates are precise enough to name a building rather than a city. Messaging apps and most social networks strip EXIF on upload; email attachments, cloud drives, marketplace listings and files sent to a person do not.

Is my file uploaded or stored?

The file is sent over HTTPS, parsed in memory and never written to disk. The report goes back to your browser and is kept nowhere. Coordinates are part of that report, so they travel back to you and no further: nothing is geocoded, no map is embedded, and a coordinate opens a third-party map only when you click it. The privacy policy spells this out.

Does stripping metadata make a document look suspicious?

It can, and that is worth knowing before you strip. An image with no metadata at all is itself a signal in the fraud report, because a camera writes plenty and a stripped file writes none. That is not an accusation of anything, but if the file is going to a reviewer who checks such things, a clean re-export from the authoring tool reads more naturally than a stripped original. The field guide covers that family.

Can you give me a cleaned copy of the file?

No, and there is no plan to hide one behind a paid tier. Tamperlens has no code path that writes a document. Producing a stripped file is a different product with a different promise, and a sanitiser that quietly corrupts a signed PDF is worse than one that does not exist. This page tells you what is in there; the fix belongs in the tool that made the file.