- All supported privacy metadata covered by the active handler
- Supported descriptive fields, artwork and thumbnails
- Old PDF revisions through full rewrite
- Supported archive and package timestamps
HONEST LIMITS
What metadata removal cannot promise
A responsible metadata cleaner should state what it does not remove. KillMetadata verifies supported carriers, but it does not call a file “100% metadata-free” when information can exist in visible content, unsupported structures or systems outside the file.
THE CLEANING PLAN
Remove what exposes you. Keep what makes the file work.
Every field is shown before the rewrite and classified by action and coverage.
- Functional data needed for appearance and playback
- Structural file information
- Document content unless explicitly classified as metadata
- The original source file
- Visible text, faces, voices and landmarks
- Steganography and forensic remnants outside supported carriers
- Secure erase and filesystem xattrs
- Hidden Office content, attachments and embedded objects as a general redaction service
WHY THE ENGINE MATTERS
Partial and rejected are product features
A partial result means known removable fields were handled but coverage is incomplete. The exact gap is shown, and download requires confirmation. A rejected result never becomes downloadable.
Encrypted and password-protected documents and archives are rejected. Macro-enabled or disguised macro packages, DRM/CENC media and unsafe offset graphs are blocked. Signatures and C2PA provenance require confirmation because cleaning removes or invalidates them.
Explore the complete verification methodology →BEFORE YOU SHARE
A four-step privacy check.
Metadata cleaning is one part of a safe sharing workflow.
- 01Review visible content separately
- 02Inspect comments, revisions and hidden Office content
- 03Understand signature and provenance consequences
- 04Check filesystem and cloud-copy behavior after saving
QUESTIONS, ANSWERED
Know the boundary before you clean.
No vague “100% clean” claim.
Are my files uploaded?
No. The cleaner runs in your browser, has no upload endpoint, and only enables the file picker after its processor assets are available locally.
Is the original file changed?
No. KillMetadata reads the original and creates a separately named cleaned copy. It never overwrites the source file.
Does “verified-clean” mean 100% metadata-free?
No. It means no supported privacy metadata remains under full handler coverage. Visible content, steganography, filesystem attributes and previously shared copies remain outside that guarantee.
Why preserve some metadata?
Orientation, color, timing, codec headers, accessibility and required package fields can be necessary for the file to display, play or validate correctly.
The picker opens only after offline protection is active.