Scope and the short version
This Privacy Policy explains how KillMetadata handles information when you visit killmetadata.com or use its browser-based file processor. The processor is designed so selected file bytes remain on your device. KillMetadata does not operate a file-upload endpoint, account system, advertising platform, or analytics service.
This policy covers the website and processor. It does not cover another website, browser extension, cloud-sync provider, operating system, or application that you choose to use before or after KillMetadata.
Files and metadata you select
Your browser reads the selected File or Blob and passes it to a dedicated local worker. Scanning, rewriting, and output verification happen in that browser session. Input bytes, detected metadata, and output bytes are not sent to KillMetadata, Cloudflare, or the origin server by the processor.
KillMetadata does not store selected files or scan reports in cookies, localStorage, IndexedDB, Cache Storage, or a server database. Cache Storage is used only for the static application code needed for offline operation. Temporary in-memory objects are released when a task ends, is cancelled, or the page is closed, subject to normal browser memory management.
Website request and security data
Like any website, delivery of a page can expose ordinary network data such as IP address, request time, requested URL, user-agent information, TLS details, and security signals to the hosting network and content-delivery provider. KillMetadata disables origin access logs for this site. Cloudflare may add Network Error Logging or similar security-reporting headers and may process and retain resulting network and security data under its own policies and settings.
The processor itself uses a Content Security Policy with connect-src set to none. Once offline protection is active, its application assets are served cache-only and it has no network fallback.
United States notice at collection
The categories of personal information involved in operating this service are limited to internet or other electronic network activity generated when a page is requested, identifiers such as an IP address that accompany that request, and contact or message content only when a person voluntarily sends correspondence. The sources are the visitor’s browser, hosting and security infrastructure, and the person who sends a message.
Network and security information is used to deliver the requested page, protect the service, diagnose failures, prevent abuse, and comply with law. Correspondence is used for the request, security, recordkeeping, dispute resolution, and legal obligations. Retention is described below. These categories are not sold or shared for cross-context behavioral advertising, and they are not used for targeted advertising or legally significant profiling.
Selected file bytes, metadata reports, and cleaned outputs are not collected by KillMetadata. Information that exists only inside a locally processed file is therefore not part of KillMetadata’s collection. KillMetadata does not use or disclose sensitive personal information to infer characteristics about a visitor.
Messages you send us
If you email KillMetadata, we receive the address, message, and any information you choose to include. We use it to respond, keep the service secure, resolve disputes, and meet legal obligations. Do not attach a private file for cleaning or include sensitive content that is not needed for your request.
How information is used
- Deliver, secure, troubleshoot, and maintain the website and its static application assets.
- Respond to questions, privacy requests, vulnerability reports, and legal notices.
- Prevent abuse and comply with binding legal process.
- Evaluate service reliability using local testing and aggregate operational information that is not tied to selected file contents.
Retention
Selected files, scan reports, and cleaned outputs have no server-side retention period because KillMetadata does not receive them. Origin access logging is disabled for killmetadata.com. Infrastructure providers control their own security-log retention. Correspondence is retained only as long as reasonably necessary for the request, security, recordkeeping, dispute resolution, and legal obligations, then deleted or de-identified when practical.
Retention decisions consider the amount and sensitivity of the information, the purpose for which it was received, security needs, applicable limitation periods, and legal requirements.
United States privacy rights
Depending on where you live and whether an applicable law covers the activity, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, opt out of certain sales, sharing, targeted advertising or profiling, and appeal a denied request. KillMetadata will not discriminate against you for exercising an applicable privacy right.
Because KillMetadata has no account and does not receive your files, it usually cannot identify a visitor from use of the processor alone. A request must describe the information or correspondence involved. We may ask for proportionate verification and may deny or limit a request where permitted by law. You may submit a request or appeal by email.
Where applicable, you may use an authorized agent. KillMetadata may request proof of the agent’s authority and may verify your identity directly unless law provides otherwise. You may also request this policy or a response in an accessible alternative format.
Global Privacy Control and Do Not Track
KillMetadata does not sell or share personal information for behavioral advertising. When a browser sends a legally recognized opt-out preference signal such as Global Privacy Control, KillMetadata treats it as an opt-out of sale, sharing, and targeted advertising. Because those activities are already disabled for every visitor, no cookie or account state is needed and the processor experience does not change. Browser Do Not Track signals likewise do not change the service because KillMetadata performs no cross-site behavioral tracking.
Children
KillMetadata is a general-audience utility and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child sent personal information in correspondence, contact us so it can be reviewed and deleted as appropriate.
Sensitive and health-related information
The local processor may technically operate on a file that contains sensitive information, but KillMetadata does not receive the file. The service is not a medical-record system, is not offered under a HIPAA business associate agreement, and is not a substitute for professional redaction or a regulated records workflow. It does not remove visible text, faces, voices, document content, or every unsupported carrier.
Do not use KillMetadata as the sole safeguard for protected health information, consumer health data, legal evidence, classified material, or another high-risk record. Review the cleaned output, the coverage status, visible content, filesystem attributes, and downstream storage before sharing.
Security and service boundaries
KillMetadata uses local workers, cache-only offline execution, restrictive browser security headers, bounded parsers, and a separate verification worker. No method of software delivery or local processing is infallible. Keep your browser and operating system current, retain the original until you verify the copy, and do not bypass a partial or rejected result.
Changes to this policy
This policy may change as the service, infrastructure, or law changes. The updated version will be posted here with a new “Last updated” date. Material changes will be highlighted on the website when reasonably required.
Please include the request type and the email address connected with any prior correspondence. Never attach a file you intended to clean.