Privacy policy

MetadataRemover was built around a simple rule: your images never leave your device. This page explains what that means in practice.

What happens to your files

Every tool on this site — the metadata cleaner, analyzer, converters and editors — runs entirely in your web browser using the HTML5 File API and canvas. When you select an image, it is read into your browser's memory, processed locally, and saved back to your device by you. At no point is image data transmitted over the network. You can verify this with your browser's developer tools, or by using the tools while offline.

What we collect

Web Pro waitlist

If you join the optional Web Pro waitlist on the pricing page, MetadataRemover stores your normalized email address, your selected billing preference (monthly or annual), your optional fixed feature preference, the consent version and the time you consented, a fixed source label, your contact status, and record timestamps. This is stored in Cloudflare D1, Cloudflare's managed database service.

The purpose is to notify you when Web Pro becomes available and to prioritize launch work. Joining the waitlist is not account creation, payment, advertising-profile enrichment, or a promise of access, and it does not create an account. Web Pro is not available to buy yet and no payment is collected.

The waitlist is separate from analytics: your email address, preferences, consent values and any form values are never sent to Plausible or Clarity. The waitlist does not upload your images or embedded metadata — the free tools continue to process everything in your browser.

You can unsubscribe or request deletion or correction of your waitlist entry at any time by emailing support@metadataremover.dev. We will remove or update your entry when the reviewed contact process is in place; until then your request is handled through that support address.

Analytics

We use Plausible Analytics, hosted at plausible.shipsolo.io, for cookieless aggregate traffic measurement. Plausible's event API requires page attribution; we limit that field to the canonical origin and path. The query string and URL fragment are not sent, so they cannot carry an email address or another waitlist form value. Referrer attribution is likewise reduced to origin and path. Plausible's automatic outbound-link, form-submission and file-download capture are disabled; only page lifecycle measurement and the approved events listed below are accepted. Plausible also processes limited request information such as browser and device type and country-level location derived from the network request. Plausible does not receive your images, file names or embedded metadata.

Microsoft Clarity is currently disabled in the denied path: the site establishes an in-page API shim and queues a Consent V2 denied signal for both ad storage and analytics storage in page memory, but it does not load the remote Clarity tag or send page telemetry to Microsoft. As a result, this path creates no Clarity first-party or third-party cookies and no persistent cross-visit identifier. Clarity may be re-enabled only after the authorized project owner verifies the required cookie and Consent Mode controls in the Clarity dashboard and a clean-browser test confirms the same no-cookie behavior. Clarity never receives your images or their metadata.

To understand whether the tools work end to end, the site uses four product milestone names: file_scanned, metadata_viewed, clean_executed and download_completed. Plausible receives an empty props object plus the canonical page attribution described above. The name-only Clarity calls remain queued only in page memory while the remote tag is disabled. Neither provider receives a file name, file content, metadata value, GPS or other location from a file, file size or identifier. Duplicate milestones for the same image are discarded in your browser before anything is sent. These events are only handled on this site's production domain.

The pricing page additionally records four commerce events: pricing_viewed, billing_period_selected, plan_selected and waitlist_submitted. Plausible receives only the provider-required canonical page attribution and closed fixed properties — for example which billing period you selected (monthly/annual) and whether a waitlist submission was newly accepted or already registered. The corresponding name-only Clarity calls remain in page memory while its remote tag is disabled. Email addresses, consent values and any other waitlist form values are never sent to Plausible or Clarity.

Third-party services

Some tools optionally load open-source libraries (for example for OCR, face detection or HEIC decoding) from a public CDN when — and only when — you use the corresponding feature. Those requests download code and model files to your browser; they do not contain your images. All computation still happens on your device.

Data retention

Local file bytes and embedded metadata are read and processed in your browser; they are not received or retained by MetadataRemover. Waitlist records (email address, preferences and consent details described above) are kept until the Web Pro launch notification and any follow-up verification are complete, or until you ask us to delete them — whichever comes first. The current fail-closed Clarity path sends no telemetry to Microsoft; its in-page queue ends with the page visit. Plausible may process limited request and milestone data under its provider policy; this policy does not state a fixed retention period for that provider processing. Closing the tab clears the file data your browser held in memory.

Your rights

We do not offer accounts and do not receive your files. Aggregate or pseudonymous analytics may not identify an individual request, but questions about analytics or privacy can be sent to support@metadataremover.dev. We will review your message and explain what information is available for the relevant provider to handle.

Changes

If this policy changes, the updated version will be posted on this page with a new revision date.

Contact

Questions about this policy? Email us at support@metadataremover.dev.