Metadata strip: a privacy step with a side effect
A metadata strip deliberately removes attached information from a file. It is ordinary privacy hygiene, it is built into many publishing pipelines, and it takes provenance records with it. As of 2026-09-22.
| The term | Metadata strip |
|---|---|
| What it names | Deliberately removing attached information from a file |
| What it is not | An attack on a provenance mechanism |
| Where the register uses it | One vendor's published caveat about its own check |
Inclusion rule. Words this site uses in a narrow sense, where the ordinary sense would lead a reader to misread a cell. No vendor statement appears on this page. Order. Fixed order: what the word names, what it excludes, then where it is used here.
1Two good reasons that collide
Stripping metadata protects people. Location, device identifiers, account names and editing history all live in attached blocks, and removing them before publication is responsible practice that many tools do by default. Provenance records live in the same place.
So a publisher following privacy advice destroys provenance evidence, without intending to and often without knowing the evidence was there. Nothing in this register addresses that tension, and one vendor at least acknowledges the outcome.
2Why selective stripping is hard to rely on
In principle a pipeline can remove some blocks and keep others. In practice the tools that strip metadata are often the simple ones, applied in bulk, configured once, and run by somebody who is not thinking about provenance at all.
A workflow that depends on a manifest arriving therefore needs the stripping step to be deliberate about what it keeps, which is a requirement on an organisation rather than on a vendor. This register records what vendors publish and can only point at the gap.
3What it cannot touch
Anything in the picture. A burned-in mark and an in-picture signal are unaffected by any operation on attached blocks, which is the whole reason the two layers behave differently and the reason this register keeps them in separate facts.
That makes a visible mark the layer that survives a privacy-conscious pipeline, and it is also the layer most vendors sell the removal of. The two facts together are the sharpest thing this register has to say about the subject.
Nothing on this page is a vendor statement; the values it helps read are on the support table, with the page and the date each one was read from. See also the machine-readable column, what survives an export. Nearby terms: container, crop, reframe.