PicSafelyon-device privacy for your photos

What we clean, and what we don’t

Every cleaned copy is read back by a second, separate check before it is called ready. If that check cannot confirm the result, the file is never offered as clean.

Supported formats

JPEG

Removed

EXIF (incl. GPS and dates), XMP, IPTC/Photoshop blocks, comments, maker notes, other APP blocks, C2PA

Kept on purpose

Pixels, dimensions, ICC colour profile, JFIF density, orientation (rewritten as the only remaining tag)

PNG

Removed

eXIf, tEXt / zTXt / iTXt text blocks (incl. XMP), tIME, unknown blocks

Kept on purpose

Pixels, dimensions, transparency, ICC profile, gamma, animation (APNG) blocks

WebP

Removed

EXIF and XMP chunks; the metadata flags in the file header are cleared

Kept on purpose

Pixels, dimensions, transparency (ALPH), animation (ANIM/ANMF), ICC profile

HEIC / HEIF (iPhone)

Removed

Everything: the photo is decoded on your device and redrawn as a new JPEG, which carries no metadata. That JPEG then goes through the normal clean and check.

Kept on purpose

What you see (pixels and upright orientation). Not kept: the HEIC format itself, depth maps, Live Photo motion, HDR gain maps, and the colour profile (converted to standard sRGB). The result is labelled as converted.

Files above 40 MB are refused rather than processed slowly or partially.

Not supported in this release

RAW (CR3, NEF, ARW, DNG…)

Maker-specific containers; metadata is entangled with image data and cannot be removed reliably.

GIF

Not implemented or tested in this release.

TIFF

Metadata and image data share the same directory structure; removal is not yet verifiable.

Live Photos, video

Multi-part and container formats out of scope for release 1.

Known limits

  • Content Credentials (C2PA) are treated as metadata and removed, which breaks provenance and authenticity checks. We warn you when a file contains them.
  • A JPEG that was saved sideways keeps a single orientation tag so it still displays correctly. That tag says nothing about you.
  • Metadata stored in ways no public parser reads cannot be detected, so “no metadata detected” means “none that we can read”.
  • Speed and “faster than other tools” claims are not published here, because they have not been measured on agreed test devices yet.

Common questions

Are my photos uploaded?
No. Reading, cleaning and checking happen inside your browser. No photo bytes, file names or metadata are sent anywhere.
Do I need an account? What do you store about me?
No account, no email, no password. Nothing personal is stored. If you buy credits, your device keeps a private restore code; our server keeps only a one-way scrambled version of it with your credit balance and plan. Stripe handles payment details and receipts; PicSafely never sees them.
Which formats can PicSafely clean?
JPEG, PNG and WebP are cleaned in place. iPhone HEIC photos are converted to a clean JPEG on your device, and we tell you when that happens. RAW, TIFF, GIF, Live Photos and video are marked unsupported.
Does cleaning change how the picture looks?
No. Pixels, dimensions, colour profile, transparency and animation are kept; only hidden details are removed.
Can PicSafely make a photo anonymous?
Not on its own. Cleaning removes hidden metadata only. Use the Blur tab to hide faces; addresses, documents or landmarks visible in the picture stay visible unless you cover them with a manual blur area.
Can PicSafely blur faces?
Yes. In the Blur tab, faces are found on your device. Choose which to blur (or Select all), add blur areas for faces it missed, and set the strength for each. The original photo is never changed.
Are photos or faces uploaded for blurring?
No. Face finding and blurring run in your browser. Face positions and photos are never sent or stored. For a watermark-free export, only a one-way code of the photo is stored so you are never charged twice for it.
Is blurring free?
Yes. The blurred download with a PicSafely watermark is free and needs no account. A watermark-free export costs 1 credit per photo, charged only after it succeeds, and is included with Unlimited.
Is cleaning metadata free?
Yes. The free cleaned copy has a small “Cleaned with PicSafely” label at the bottom, drawn into the picture and saved again as a high-quality JPEG (PNG for PNGs). The untouched cleaned file without the label costs 1 credit per photo, charged only after it is made and never twice for the same photo, and is included with Unlimited.
Can a blurred face be recovered?
PicSafely rebuilds the image from blurred pixels, so the original face is not stored in the file. Very low blur strength may still leave someone recognisable — check the preview before sharing.