GateTrue

What each generator documents about marking its output

Metadata strip: a privacy step with a side effect

A metadata strip deliberately removes attached information from a file. It is ordinary privacy hygiene, it is built into many publishing pipelines, and it takes provenance records with it. As of 2026-09-22.

What a privacy-conscious pipeline removesLocation data, device identifiers and editing history live in attached blocks, and removing them before publication is responsible practice. Provenance records live in the same blocks, so a pipeline doing the right thing for privacy removes the evidence in the same pass.One pass over a fileRemoved togetherLocation, device identifiers, account names, editing history,provenance records.Why it happensPrivacy hygiene, configured once and applied in bulk by whoeverpublishes.What is untouchedAnything in the picture: a burned-in mark, or an in-picturesignal.The sharp pointThe surviving layer is the one most vendors sell the removal of.Two good practices in direct conflict
Fig. 1 The layer that survives such a pipeline is the visible one, which is also the layer most vendors sell the removal of.
How this register uses the term, and what it excludes. Written 2026-09-22.
The termMetadata strip
What it namesDeliberately removing attached information from a file
What it is notAn attack on a provenance mechanism
Where the register uses itOne vendor's published caveat about its own check

Inclusion rule. Words this site uses in a narrow sense, where the ordinary sense would lead a reader to misread a cell. No vendor statement appears on this page. Order. Fixed order: what the word names, what it excludes, then where it is used here.

1Two good reasons that collide

Stripping metadata protects people. Location, device identifiers, account names and editing history all live in attached blocks, and removing them before publication is responsible practice that many tools do by default. Provenance records live in the same place.

So a publisher following privacy advice destroys provenance evidence, without intending to and often without knowing the evidence was there. Nothing in this register addresses that tension, and one vendor at least acknowledges the outcome.

2Why selective stripping is hard to rely on

In principle a pipeline can remove some blocks and keep others. In practice the tools that strip metadata are often the simple ones, applied in bulk, configured once, and run by somebody who is not thinking about provenance at all.

A workflow that depends on a manifest arriving therefore needs the stripping step to be deliberate about what it keeps, which is a requirement on an organisation rather than on a vendor. This register records what vendors publish and can only point at the gap.

3What it cannot touch

Anything in the picture. A burned-in mark and an in-picture signal are unaffected by any operation on attached blocks, which is the whole reason the two layers behave differently and the reason this register keeps them in separate facts.

That makes a visible mark the layer that survives a privacy-conscious pipeline, and it is also the layer most vendors sell the removal of. The two facts together are the sharpest thing this register has to say about the subject.

Nothing on this page is a vendor statement; the values it helps read are on the support table, with the page and the date each one was read from. See also the machine-readable column, what survives an export. Nearby terms: container, crop, reframe.