Audit everything a viewer can see

Find and cover private details in an image

Inspect hidden metadata and visible text, add your own solid-pixel covers, and optionally ground faces, plates, screens, labels and codes with a local browser vision model.

Run the privacy firewall
Completely free No account or payment Image stays on this device
USE THIS WHENUse this before sharing an image that may expose people, screens, documents, labels, addresses or hidden file data.SUPPORTED INPUTOne JPEG, PNG or WebP · 32 MP
What you will getA clear result before technical detail
01A layered hidden-data and visible-risk review
02Editable solid-pixel privacy covers
03A re-scanned image copy and evidence graph
Private analysis labFiles stay inside this browser
1 image · 32 MP · optional 350–700 MiB model
Choose one image to audit before sharingJPEG, PNG or WebP · 25 MiB · 32 MP privacy-workflow limit
Selection is processed locally
Hidden dataGPS, device, time and creator fields
Visible textContact, identity, address and account patterns
Optional visual groundingFaces, plates, screens, labels and codes
Session diagnosticsNo processing errors

Stored only in this browser tab. Image bytes, filenames and metadata are never included.

No tool error has been recorded in this tab.
No upload or account Originals remain unchangedReview methodology
Useful and careful

What is built into the result.

Important findings come first. Technical fields remain available without taking over the page.

01

Combines deterministic file checks, local OCR and optional WebGPU vision

02

Never loads the large vision model until you explicitly request it

03

Re-reads metadata and visible text after creating the redacted copy

Understand the method

A useful result with its reasoning attached.

This page explains what the lab measures, how to interpret it and where human review remains essential.

01

Check the file and the visible scene separately

Removing EXIF does not hide a face, delivery label, computer notification or street sign. Cropping visible details does not remove GPS, device serial fields or a precise capture time stored inside the file. The privacy firewall keeps these evidence layers separate so one successful check cannot be mistaken for a complete privacy verdict.

The deterministic pass validates the real file signature, reads supported metadata and classifies location, device, creator and time fields. A local OCR pass then looks for specific contact, coordinate, network, address, identity and payment-card patterns. Every marked text region remains a review candidate because optical character recognition can confuse letters and numbers.

  • Real file signature and dimensions
  • EXIF, XMP and container markers
  • Visible text with bounded pattern rules
  • Clear source and confidence for each finding
02

Use advanced vision only when the extra evidence is worth the download

The optional Florence-2 pass is not a generic image-caption demo. It grounds a focused privacy vocabulary—such as faces, registration plates, identity documents, screens, shipping labels, street signs and machine-readable codes—against regions in the selected image. Dense region captions provide additional review candidates, while a scene summary helps a person notice context the automated rules did not classify.

The model is never fetched during ordinary page load or the initial OCR review. The interface states the approximate model size before download and uses a dedicated worker so inference does not block the page. Model files may be cached by the browser; the selected image is passed to the worker as local bytes and is not attached to a network request.

  • Explicit model-download consent
  • WebGPU inference in a dedicated worker
  • Task-specific region grounding
  • Human review instead of a false privacy guarantee
03

Replace sensitive pixels and verify the new copy

A blur or decorative overlay can leave recoverable detail. This workflow draws opaque pixels into a newly encoded image. Detected boxes can be included or excluded, and the reviewer can draw manual covers for reflections, children, keys, documents or any other area that automated analysis should not decide.

Before download, AnalyzeImage re-parses the new file and runs text recognition again. The result reports remaining identifying metadata and sensitive-looking text patterns instead of displaying an unqualified success message. A downloadable JSON record preserves finding sources, covered regions, verification counts, model source and the zero-image-upload access ledger without embedding the source image or its filename.

  • Opaque pixel replacement
  • Original file remains unchanged
  • Metadata and text re-scan
  • Versioned evidence graph with explicit limitations
Three simple steps

Know what happens before you start.

Use this before sharing an image that may expose people, screens, documents, labels, addresses or hidden file data.

  1. InspectRead supported metadata and visible text without loading a large AI model.
  2. GroundOptionally add local WebGPU visual regions, then review every suggested box.
  3. Cover and verifyCreate a solid-pixel copy and re-scan its metadata and visible text.
RESULT ORDER
01 · A layered hidden-data and visible-risk review02 · Editable solid-pixel privacy covers03 · A re-scanned image copy and evidence graph04 · Limits and next step
Clear before you rely on it

Questions this tool should answer upfront.

Short answers keep important privacy, evidence and professional-use limits visible.

01Is blurring enough to redact a private detail?

AnalyzeImage does not rely on blur for this workflow. Selected areas are replaced with solid pixels in a separately encoded copy because blur can preserve recognizable structure.

02Does the image go to Hugging Face when the optional model loads?

No. During the localhost development configuration, model files can be downloaded from Hugging Face, but the selected image remains a local File passed to the browser worker. Production will use same-origin model assets before this route is released.

03Does a clear re-scan prove the image is anonymous?

No. It confirms that supported metadata and configured text patterns were not found in the new copy. People, locations and context can remain identifiable in ways the automated passes do not recognize.

04Can I cover a region the automated checks missed?

Yes. Turn on manual cover mode and draw a box over any visual area. Manual regions appear in the evidence record and are treated exactly like selected automated covers.

Continue when useful

Your next step, without starting over.

Move to another page only when its outcome matches what you need.

Important limitations

OCR and vision regions can miss clues or mark harmless content, so human review remains required · A low-risk result does not prove that a person or place cannot be identified · Advanced vision requires WebGPU and approximately 350–700 MiB of first-use model and browser-runtime assets

Full limitations