Legal document
Privacy Policy
How AI Metadata Remover inspects, removes, and edits supported image and PDF metadata locally and handles limited site analytics and operational data.
The short version
The browser tools process supported image files and PDF document properties on your device. Files placed in a metadata workbench are not uploaded to a Metadata Remover processing API. The public file tools do not require an account; Pro and the optional Feedback workspace use an account. A Feedback attachment is uploaded only after you explicitly select it and submit the feedback form, as described below.
File processing
- Selected, dropped, pasted, and sample files are read by code running on your device.
- The homepage image cleaner rewrites supported metadata containers in your browser without decoding or re-encoding the compressed image data. PDF property processing uses qpdf WebAssembly in a browser worker.
- The image Metadata Editor re-encodes a new copy, discards the old metadata container, and writes only the title, description, creator, copyright, and keyword values you enter into a fresh local XMP packet.
- The PDF Metadata Editor rewrites a new copy, replaces the Info dictionary with the non-empty title, author, subject, keywords, creator, and producer values you enter, and removes catalog-level XMP before re-scanning the output.
- Cleaning creates a new local copy. It does not overwrite the original file.
- Verification re-scans the new copy on your device.
- Downloads are created directly by your browser. We do not receive or retain the file or its metadata.
- Refreshing or closing the page clears the current in-browser workbench session.
PDF tools are limited to the standard Info dictionary and catalog-level XMP. Encrypted PDFs are rejected, and signed PDFs require explicit consent before any rewrite because rewriting invalidates the existing signature. This policy does not describe PDF sanitization or hardening because the current tools do not provide those features.
Feedback attachments are a separate support channel, not a server-side metadata-processing feature. No file from a remover, viewer, or editor is attached automatically.
Site and operational data
Our hosting provider may process standard request information such as IP address, browser type, requested URL, timestamp, and security events to deliver and protect the website. We use Pageview and Google Analytics 4 for aggregate page-traffic measurement. These services may receive the requested page URL, referrer, timestamp, approximate location derived from network information, and browser or device information.
Google Analytics is initialized with analytics and advertising storage denied, Google signals and advertising personalization disabled, and ad-data redaction enabled. When you select, drop, or paste a local file, the page also disables Google Analytics before subsequent file-workflow interactions. We do not configure either analytics service to receive file contents, file names, metadata values, file hashes, cleaned-file download names, or report contents.
We do not sell personal information. The public file tools do not require payment details or an account.
Accounts and Pro billing
Pro requires an account and an active subscription. Account, payment, entitlement, and subscription requests never contain file content, file names, metadata values, file hashes, or report contents. A configured payment provider may process account, billing, transaction, and subscription information under its own privacy policy. The file cleaner continues to run locally after your entitlement is checked.
Feedback and optional attachments
A signed-in user may submit a feedback subject, description, follow-up messages, and up to three optional JPEG, PNG, WebP, or PDF attachments. Attachments are limited to 5 MB each and 10 MB in total. The site uploads only the files you explicitly add to that feedback form; it never copies a workbench file, metadata value, report, or download into feedback automatically.
Feedback attachments are stored in a private Cloudflare R2 bucket without a public object URL. Opening an attachment requires an authorized account and a link to the relevant feedback thread. The original local filename is replaced before upload and is not retained. PDF attachments are delivered as downloads rather than embedded as active documents. The feedback text and private attachment are used to investigate and respond to the issue you submitted. Do not include passwords, payment-card details, or unnecessary personal information.
Browser storage and cookies
The file tools do not need cookies to process files. Google Analytics is configured without analytics or advertising storage. The site may store a language or theme preference on your device. The free image cleaner also stores one local record containing the current local calendar date and the number of images used so the homepage image tool, EXIF Remover, and Midjourney Metadata Remover can share a limit of ten images per day. That record contains no file name, file content, metadata value, result, hash, or account identifier and is not sent to our servers or analytics. The Midjourney page's random filename token exists only in the current browser session and is not stored or reported. The count resets when a new local calendar day begins; if local storage is unavailable, file processing remains available. If you sign in for Pro, essential session and security storage may be used to keep you authenticated and check the subscription. Those records remain separate from the local file workbench.
Third-party services
The website relies on Cloudflare for hosting, security, and private storage of explicitly submitted feedback attachments; Pageview provides pageview measurement, and Google Analytics 4 provides aggregate traffic measurement. When Pro is available, the configured payment provider processes billing and subscription requests. Those providers process the limited request, measurement, account, billing, or feedback-storage information described above under their own policies. Files selected in a metadata workbench are not sent to these providers by the tools.
Retention, account deletion, and legal records
While an account is active, we keep the account and subscription data needed to authenticate you, show Billing, and enforce the current entitlement. Feedback threads and their explicitly submitted attachments are kept while needed to investigate, reply, and maintain the support history. Payment webhook records contain only the provider event identifier, lifecycle type, processing status, attempt count, and processing timestamps; they do not store the raw payment payload or customer email.
You may permanently delete your account from Profile. The deletion flow first confirms cancellation of future subscription renewal, then removes private feedback attachments, revokes sessions and sign-in credentials, and deletes feedback threads, the account, and associated product data. We retain only minimized transaction fields reasonably required for accounting, fraud prevention, disputes, tax, or other legal obligations, such as provider and transaction references, product, amount, currency, and payment date. These records are separated from the deleted account and contain no local account user ID, email, name, payment payload, file information, feedback content, or workbench result. Provider transaction references may remain linkable within the payment provider's legally retained records.
You may also request access, correction, or deletion assistance at info@aimetadataremover.net. We may need to verify control of the account before acting on a request.
Security and your choices
Keeping file processing local reduces transfer and storage exposure, but no browser or device can be guaranteed perfectly secure. Use a trusted, up-to-date browser and a device you control. You can leave the page at any time to clear the current session and can choose not to download a cleaned or edited copy.
Changes
We may update this policy when the product or its data practices change. The date above identifies the latest version.
Contact
For privacy questions, email info@aimetadataremover.net. Do not attach files or include metadata values in email; the contact channel is separate from the browser tool's local-processing workflow. This policy describes the current public service at aimetadataremover.net.