Metadata is only one privacy layer
A screenshot may show email addresses, browser tabs, QR codes, messages or account names directly in the pixels. Metadata cleaning cannot remove those visible details.
- Crop unrelated screen areas
- Check notifications and browser tabs
- Blur personal identifiers before sharing
- Then inspect metadata
Why the result uses plain language
The result separates signals that support a screenshot workflow from camera-related fields and neutral facts. This is more useful than presenting an unsupported percentage.
Separate weak hints from stronger workflow evidence
A filename containing “Screenshot” is easy to rename and a 16:9 PNG can come from many sources. Those are useful hints for organizing files but weak evidence of origin.
A capture-application field is more direct workflow evidence, while camera make, lens and exposure fields point in another direction or may have been copied. The checker displays the competing signals rather than averaging them into a probability.
- Filename: weak and editable
- Format and dimensions: neutral facts
- Capture software: workflow clue
- Camera fields: conflicting evidence
- Missing metadata: inconclusive
Why the checker does not display an AI-style score
A credible percentage needs a representative data set, known ground truth and validated error rates. Ordinary filenames and metadata fields are editable, so a 92% screenshot claim would manufacture precision that the evidence cannot support.
The rule test instead returns plain categories and cautions. This helps a non-expert understand exactly what was found and gives an expert the underlying fields for independent interpretation.
The four controlled profiles
The first profile used only a screenshot-like filename; the second was a plain PNG without metadata. Both remained inconclusive. A capture software value triggered a screenshot pattern, while camera EXIF produced a camera-related signal.
These profiles test the decision boundaries, not how often each case appears on the internet. Real prevalence would require a documented cross-platform corpus and sampling method.
Privacy fields outside the screenshot question
Software, creator, comment and text chunks can reveal an application or person even when they do not prove the file is a screenshot. Dimensions and color profiles are usually technical facts, while GPS would be a high-priority finding.
The user’s goal is often safer sharing, not origin classification. The result therefore keeps privacy findings visible even when screenshot evidence is inconclusive.
A fast pre-share routine
Check metadata, then scan all visible pixels. Crop notifications, tabs and unrelated documents; replace rather than merely cover sensitive areas when the editor supports removable objects.
Export a new file, reopen it and inspect the metadata again. Share that final copy, keep the original privately and avoid claiming the checker proved how the screenshot was created.
Four questions behind every result
Was a strong workflow clue found? Was conflicting camera evidence found? Did the file expose private fields regardless of origin? Did the parser complete successfully? Keeping these questions separate makes the answer easy to understand without losing technical honesty.
A neutral result is useful when it explains why certainty is unavailable. It tells the user to concentrate on visible privacy and the exact sharing task instead of chasing a questionable classification score.
When signals conflict, the interface shows both. Hiding the camera evidence to preserve a screenshot label would be less helpful than admitting that metadata may have been copied, rewritten or produced by a mixed workflow.
- Evidence for capture workflow
- Evidence for camera workflow
- Independent privacy findings
- Parser and format confidence
What this does not prove
A metadata result describes the fields and structures that the supported parser could read. It does not, by itself, prove authenticity, intent, authorship or the truth of the visible scene.