DALL-E 3 outputs carry two layers of provenance: a C2PA Content Credentials manifest in the PNG caBX chunk, and an invisible cryptographic watermark embedded at pixel level (announced by OpenAI in 2024). GhostMeta strips the C2PA layer via canvas re-encode — the most common signal third parties read. The pixel-level watermark survives re-encoding by design and would require destructive editing to remove. DALL-E 3 reaches you through several surfaces — the ChatGPT app, the OpenAI API, Microsoft Copilot and the old Bing Image Creator — and each one attaches the same caBX-encoded C2PA manifest, so a file saved from Copilot carries the identical OpenAI provenance as one saved from ChatGPT. Because PNG is lossless, GhostMeta's canvas re-encode preserves the pixel values without JPEG-style requantization: the image stays visually identical (within the 4096px processing cap) while the metadata chunks are rewritten clean. After processing, the downloaded PNG keeps just the structural chunks (IHDR, IDAT, IEND) — the caBX provenance chunk and any tEXt/iTXt blocks are gone.
Three mechanisms hide behind the word "fingerprint": the C2PA manifest, in the file; the pixel watermark, in the image; the similarity fingerprint, at the issuer. Only the first is within reach of browser-side processing, and that is the one GhostMeta removes, along with EXIF, XMP layers and PNG text chunks.
Applied to a generated image, the word points at three mechanisms best kept apart. The C2PA manifest is metadata written into the file. A pixel watermark is a subtle modification of the pixels. A similarity fingerprint is a digest kept by the issuer, and it does not travel with the file.
Only the first is within reach of browser-side processing. That is the one GhostMeta removes, along with the EXIF and XMP layers and the PNG text chunks that come with it.
Rather than trusting a promise, drop the file into the viewer before cleaning: the fields found are listed and graded by risk. You see what your image actually contains, not what a marketing page assumes it contains.
Read it again on the cleaned copy to confirm what disappeared. That check is local, it costs nothing, and it is the only honest way to establish the scope of a tool like this.
Reading locally shows you the file's metadata. It tells you nothing about what is kept elsewhere: an image digest held by the issuer stays invisible from your machine, and no browser tool can observe it.
That is the honest boundary of the exercise. What is in the file can be checked; what sits on a third-party server cannot, and nobody should claim otherwise.
| Mechanism | Where it sits | Removed here |
|---|---|---|
| C2PA manifest | In the file | Yes |
| PNG text chunks | In the file | Yes |
| Pixel-level watermark | In the pixels | No |
| Similarity fingerprint | At the issuer | No |
No. OpenAI's pixel watermark is embedded in image data and survives canvas re-encode. GhostMeta strips the C2PA metadata layer, which is what most C2PA viewers read.
DALL-E 2 outputs without a C2PA manifest are passed through. DALL-E 3 outputs carry the manifest and are flagged.
The C2PA manifest does not contain the user prompt by default, but the assertion list may include the model version, which can hint at the prompt class.
Yes. Whatever the surface — ChatGPT, the OpenAI Images API, Microsoft Copilot or Bing Image Creator — the DALL-E 3 backend writes the same C2PA manifest into the PNG caBX chunk, naming OpenAI as the claim_generator. The delivery channel does not change the embedded provenance, so GhostMeta strips that metadata layer identically in every case.
No. PNG is a lossless format, so the canvas re-encode preserves the pixel values without JPEG-style requantization — the image you download is visually identical to the original (images above 4096px are scaled down to that cap to stay memory-safe on mobile). Only the caBX provenance chunk and any text chunks are dropped; IHDR, IDAT and IEND remain.
Open the cleaned PNG in any C2PA viewer such as Content Credentials Verify (verify.contentauthenticity.org) — it will report no manifest found instead of OpenAI. At the byte level, the file no longer contains a caBX chunk; a chunk inspector will show only IHDR, IDAT and IEND. Note that this confirms removal of the metadata layer only, not the separate pixel-level watermark, which survives any re-encode.
Partner : M.E Expert Serrurier