Transparent method

How the local watermark checker works

Watermark Tidy is a static browser application. It checks a defined set of text code points and PNG/JPEG metadata structures, reports exact supported findings, and removes only reviewed ranges. It does not upload content or claim universal watermark detection.

Use the watermark checker

Text inspection

The text path iterates through Unicode code points and classifies supported zero-width characters, joiners, bidirectional controls, tag characters, variation selectors, and unusual spaces. Results include the character name, code point, count, and first positions. Contiguous Unicode tags and variation-selector byte sequences are decoded into bounded, readable previews. A separate review-only pass flags common Greek or Cyrillic lookalikes only when they are mixed into a Latin-script token.

Every finding is preserved by default. After review, you can explicitly select supported character types to remove or normalize in a separate output. The selected types are scanned again before copy. The original input is not overwritten because matched characters can have legitimate uses in emoji, scripts, and typography. Recognized emoji joiners, word-joining non-joiners, variation sequences, and emoji flag tags are reported but protected from cleanup.

PNG and JPEG inspection

The image path checks magic bytes and validates container boundaries before reading metadata. PNG inspection validates chunk order and CRCs, then decodes bounded text metadata, including compressed zTXt and iTXt. JPEG inspection parses marker segments up to the image scan and reconstructs supported JPEG-XT/JUMBF groups.

A JPEG C2PA finding requires the manifest-store structure, exact C2PA UUID, and c2pa label. Fragment groups are checked for declared length and the C2PA contiguity rule. Extended XMP is reconstructed only when its GUID, total length, offsets, and coverage are consistent.

When an embedded C2PA candidate is present, the official CAI browser validator checks the claim signature and binding to the exact asset. It then evaluates signer trust against a pinned, self-hosted snapshot of the official C2PA Conformance Trust List. Structural presence, cryptographic validity, asset binding, and signer trust remain separate results.

Targeted removal and re-checking

Removal operates on byte ranges identified during inspection. Dedicated PNG metadata chunks and complete C2PA groups can be removed; shared XMP is review-only because deleting the entire packet could discard unrelated information. PNG IDAT data and the JPEG scan are copied byte-for-byte.

The cleaned file is parsed and decoded again before download. This verifies that supported removable findings are gone and that the browser can still decode the result. The tool does not canvas-reencode images, strip every metadata block, or alter pixels.

Local processing and defense in depth

  • No application server, upload route, account, database, analytics, or remote model.
  • A Content Security Policy limits connections to self-hosted verifier assets and blocks form submissions.
  • Browser spellcheck, autocorrect, autocomplete, and form serialization are disabled for text.
  • File limits cap compressed bytes and decoded image dimensions before preview.
  • Object URLs are revoked when files change or the page closes.

Read the complete privacy explanation.

What a result means

ResultWhat it meansWhat it does not mean
Supported text matchA listed Unicode or mixed-script pattern existsAI authorship or intentional watermarking
C2PA container foundA supported manifest-store structure existsA valid signature, trusted signer, or AI origin
C2PA validThe official validator accepted the credential and asset bindingThat the signer is trusted unless shown separately
Signer trustedThe valid signer chains to the pinned C2PA Conformance Trust ListThat every provenance claim is factually true or AI-generated
AI metadata field foundA recognized source field/value existsPixel-level AI detection
No supported findingThe implemented checks found nothingWatermark-free, authentic, or human-made

References and implementation history

The initial rules were adapted from Guillaume Meyer's MIT-licensed watermarks-remover project. It has been re-audited through the upstream v0.4.0 release. Watermark Tidy adopted its four-level finding-confidence taxonomy while keeping confidence separate from attribution and from the image evidence method. This browser does not parse command-line output: it validates container structure, binds recognized metadata values to their fields, bounds decompression, separates C2PA from AI claims, and uses targeted removal rather than stripping most metadata. Upstream's external SynthID scorer, LLM rewrite, and CtrlRegen backend are not bundled because they do not fit the local browser, verification, or license contract. Watermark Tidy instead maintains a native, oracle-verified SynthID Text reference engine. A lazy local worker tokenizes pasted text and reports statistics for an explicit test profile; provider attribution stays fail-closed until a compatible profile and calibration are reproducible.

Method last reviewed August 14, 2026.