Photo privacy notes/

Photo metadata is not the same as an AI watermark

EXIF and XMP describe a file. A pixel-level watermark is embedded in the image. Learn why removing one does not remove the other.

People often use “metadata” to mean every hidden detail in a photo. That makes it easy to assume one metadata cleanup will remove every trace of where an image came from. It will not. A photo can carry several different kinds of information, and each one works differently.

File metadata describes the image

EXIF, IPTC and XMP are common ways to store details alongside image data. Depending on the camera and software, those details may include the camera model, exposure settings, the date and time, GPS coordinates, a caption, copyright information or an editing program. Some fields help photographers organize and preserve their work. Location and device details can also reveal more than a person meant to share.

These fields are part of the file structure. An image editor or metadata tool can read, change or remove some of them. A service that removes metadata should say which fields it handles. “Metadata removed” is too broad if the result is not checked across the formats and fields the service claims to support.

A watermark can live in the pixels

An invisible watermark such as SynthID is embedded in image content. Google DeepMind describes SynthID as a watermark designed to remain detectable after some common changes, including cropping, filters and lossy compression. That makes it different from a text field that can be removed from the file header.

Saving a copy without EXIF or XMP does not, by itself, remove a mark embedded in the pixels. It also does not show whether a watermark is present. A separate, capable detector would be needed to assess a watermark, and a result would still need clear limits.

Credentials are another kind of record

Content Credentials use a signed manifest to record information about an asset. The C2PA specification distinguishes a hard binding, which ties a manifest to specific file content, from a soft binding, which may help find a credential for a related rendition. It also treats ordinary asset metadata such as EXIF or XMP separately from the manifest.

Changing a file can affect the relationship between its pixels and its credential. Removing metadata may also remove a place where a credential was stored. A new copy should not be described as verified unless its credential has actually been checked.

What a clean copy can tell you

A copy with fewer metadata fields can reduce the extra details attached to a photo. It cannot establish who took the photo, whether AI was used, or whether an invisible watermark remains. Keep the original if its capture information or credentials may matter later. Compare the output, and describe only the change you can verify.

In the deprint preview, the SynthID step is simulated. It does not inspect or remove SynthID. The demo is there to show a possible workflow, not to make a claim about an image.

Sources

  1. Google DeepMind: SynthID
  2. C2PA Content Credentials Specification