Transparent method
How the local watermark checker works
Watermark Tidy is a static browser application. It checks a defined set of text code points and PNG/JPEG metadata structures, reports exact supported findings, and removes only reviewed ranges. It does not upload content or claim universal watermark detection.
Use the watermark checkerText inspection
The text path iterates through Unicode code points and classifies supported zero-width characters, joiners, bidirectional controls, tag characters, variation selectors, and unusual spaces. Results include the character name, code point, count, and first positions. Contiguous Unicode tags and variation-selector byte sequences are decoded into bounded, readable previews. A separate review-only pass flags common Greek or Cyrillic lookalikes only when they are mixed into a Latin-script token.
Every finding is preserved by default. After review, you can explicitly select supported character types to remove or normalize in a separate output. The selected types are scanned again before copy. The original input is not overwritten because matched characters can have legitimate uses in emoji, scripts, and typography. Recognized emoji joiners, word-joining non-joiners, variation sequences, and emoji flag tags are reported but protected from cleanup.
PNG and JPEG inspection
The image path checks magic bytes and validates container boundaries before reading metadata.
PNG inspection validates chunk order and CRCs, then decodes bounded text metadata, including
compressed zTXt and iTXt. JPEG inspection parses marker segments up
to the image scan and reconstructs supported JPEG-XT/JUMBF groups.
A JPEG C2PA finding requires the manifest-store structure, exact C2PA UUID, and
c2pa label. Fragment groups are checked for declared length and the C2PA
contiguity rule. Extended XMP is reconstructed only when its GUID, total length, offsets, and
coverage are consistent.
When an embedded C2PA candidate is present, the official CAI browser validator checks the claim signature and binding to the exact asset. It then evaluates signer trust against a pinned, self-hosted snapshot of the official C2PA Conformance Trust List. Structural presence, cryptographic validity, asset binding, and signer trust remain separate results.
Targeted removal and re-checking
Removal operates on byte ranges identified during inspection. Dedicated PNG metadata chunks
and complete C2PA groups can be removed; shared XMP is review-only because deleting the entire
packet could discard unrelated information. PNG IDAT data and the JPEG scan are
copied byte-for-byte.
The cleaned file is parsed and decoded again before download. This verifies that supported removable findings are gone and that the browser can still decode the result. The tool does not canvas-reencode images, strip every metadata block, or alter pixels.
Local processing and defense in depth
- No application server, upload route, account, database, analytics, or remote model.
- A Content Security Policy limits connections to self-hosted verifier assets and blocks form submissions.
- Browser spellcheck, autocorrect, autocomplete, and form serialization are disabled for text.
- File limits cap compressed bytes and decoded image dimensions before preview.
- Object URLs are revoked when files change or the page closes.
What a result means
| Result | What it means | What it does not mean |
|---|---|---|
| Supported text match | A listed Unicode or mixed-script pattern exists | AI authorship or intentional watermarking |
| C2PA container found | A supported manifest-store structure exists | A valid signature, trusted signer, or AI origin |
| C2PA valid | The official validator accepted the credential and asset binding | That the signer is trusted unless shown separately |
| Signer trusted | The valid signer chains to the pinned C2PA Conformance Trust List | That every provenance claim is factually true or AI-generated |
| AI metadata field found | A recognized source field/value exists | Pixel-level AI detection |
| No supported finding | The implemented checks found nothing | Watermark-free, authentic, or human-made |
References and implementation history
The initial rules were adapted from Guillaume Meyer's MIT-licensed watermarks-remover project. It has been re-audited through the upstream v0.4.0 release. Watermark Tidy adopted its four-level finding-confidence taxonomy while keeping confidence separate from attribution and from the image evidence method. This browser does not parse command-line output: it validates container structure, binds recognized metadata values to their fields, bounds decompression, separates C2PA from AI claims, and uses targeted removal rather than stripping most metadata. Upstream's external SynthID scorer, LLM rewrite, and CtrlRegen backend are not bundled because they do not fit the local browser, verification, or license contract. Watermark Tidy instead maintains a native, oracle-verified SynthID Text reference engine. A lazy local worker tokenizes pasted text and reports statistics for an explicit test profile; provider attribution stays fail-closed until a compatible profile and calibration are reproducible.
- C2PA Content Credentials specification
- Official CAI JavaScript and WebAssembly validator
- Unicode Standard, Chapter 23
- Google DeepMind SynthID overview
Method last reviewed August 14, 2026.