Our privacy commitments, what guarantees them technically, how to verify them yourself, and what we do not claim to do.
GhostMeta rests on a single principle: your photos never reach us. Cleaning runs in your browser, on your device. This is not a policy we chose to apply, it is a constraint the architecture imposes on us — and one you can verify yourself in seconds.
Most privacy services ask you to trust them. They receive your data, then undertake to look after it. That undertaking may be sincere, but it stays unverifiable: you will never know what was logged, cached or backed up between receipt and the promised deletion.
We took the problem from the other end. The image is decoded in the tab's memory, redrawn through the browser's Canvas API, then exported again. The canvas returns pixels and nothing else: every metadata block is lost on write, by construction rather than by filtering. There is no server to trust, because there is no server in the loop.
A commitment you cannot check is worth nothing. Every row below therefore says how to verify it without taking our word for it.
| Commitment | What guarantees it | How to verify |
|---|---|---|
| Your images are not uploaded | Processing is executed by the browser | Process an image in airplane mode, or watch the Network tab |
| No image is retained | No image is received | Follows from the point above |
| Cleaning requires no account | No authentication anywhere in the flow | Open a tool in a private window and process an image |
| Audience measurement is consent-gated | No tracker loads before you agree | Decline, then watch the Network tab |
| Fonts are self-hosted | No call to a third-party font service | No request to an external domain on load |
'If it's free, you're the product' describes a common reality, not a law. The saying holds when a service needs your data to exist. Here the model is explicit: cleaning one image and reading its metadata are free, batch processing is paid, and subscriptions fund the whole thing.
Your photos cannot be the monetised resource, for a simple reason: we do not have them. That is not a commercial promise, it is a technical consequence.
Honesty means not hiding behind a slogan. 'Zero data' would be false: a service with subscriptions necessarily has a database. Here is what it holds.
Payment is handled by an external provider, which therefore sees your billing details: we have no access to them and do not store them. The full terms are in our privacy policy.
A credible manifesto states its limits too. GhostMeta removes metadata — EXIF, IPTC, XMP and C2PA provenance manifests. It does not remove markings written into the pixels themselves, such as the invisible watermarks some image generators apply: those survive re-encoding, and claiming otherwise would be a lie.
Equally, stripping metadata does not anonymise what the image shows. A visible address, a plate or a reflection locates you just as reliably as coordinates. The full scope is set out in the questions hub.
Subscriptions. Cleaning one image and reading its metadata are free and need no account; batch processing is for subscribers. Your photos are never the monetised resource, for the simple reason that they never reach us.
No images, ever: they do not leave your browser. If you create an account, the associated email address and the subscription status are stored, because a subscription has to belong to someone. Audience measurement is conditional on your consent.
No. Metadata analysis and cleaning one image work with no account and no email address. An account only becomes necessary for batch processing, because a subscription has to be tied to someone.
That is precisely the point of the architecture. A database of photos would be a transferable asset: there isn't one. An acquirer would inherit accounts and subscriptions, never a history of your images, which has never existed anywhere.