Generators sign their output three ways — an invisible pixel watermark, a cryptographic provenance manifest, and plain metadata tags. SynthGuard processes supported media locally, but these systems differ and no verifier or platform outcome can be guaranteed.
A clean metadata panel feels like success — but the strongest AI watermark isn't in the metadata at all. SynthID is woven into the pixels and survives stripping, cropping and compression. There are really three separate things to deal with:
C2PA, Content Credentials, EXIF/XMP “Made with AI”. Easy to strip — and where most tools stop.
SynthID, embedded in the image itself. Survives metadata deletion. Needs signal disruption, not a delete button.
Even with no watermark, detectors score the diffusion fingerprint. The full humanizer rebuilds camera authenticity.
SynthGuard can rebuild metadata and adjust selected image characteristics with the full photo humanizer. Read the deep-dives on SynthID, C2PA and Content Credentials.
The part that genuinely comes off
C2PA is the one layer where “removal” is the accurate word. A Content Credentials manifest is a signature over an exact set of bytes — change the bytes and the manifest no longer validates, so it is not carried into a newly encoded export. That is a property of the standard, not a trick. The same is true of the plain EXIF, XMP and IPTC “Made with AI” fields: they are ordinary metadata and can be deleted outright.
What this does not touch is an embedded watermark such as SynthID, which lives in the pixels rather than the container — see what SynthID is and whether it can be removed for the mechanics. Nor does it change how a pixel-level classifier scores the image.
Run it through the free in-browser detector first, so you know whether the exposure is a manifest, plain metadata, or the pixels themselves.
Open the detectorThe EXIF remover deletes GPS, device and timestamp fields in your browser. A full re-encode through the photo humanizer rebuilds the file itself, so a signed manifest is not carried over.
Remove EXIF freeCheck the export again. Metadata being gone is not the same as an image reading as camera-made — and platform disclosure rules still apply to you either way.
Photo humanizerDedicated C2PA removers exist and do this one job well — how SynthGuard compares to UnmadeWithAI sets out where a metadata-only tool is enough and where it is not.
What gets inspected and changed
Generators rarely sign their output just once. Here's each marker, what it is, and how the pipeline handles it.
INVISIBLE · PIXEL-EMBEDDED
Google DeepMind's watermark, embedded in the pixels of Imagen, Veo and Gemini output (and the tokens of Gemini text). Survives JPEG compression, cropping, scaling and colour shifts — which is exactly why deleting metadata does nothing to it.
PROVENANCE · CRYPTOGRAPHIC MANIFEST
The signed provenance manifest attached by DALL·E 3, Adobe Firefly and a growing list of cameras and editors. Platforms read it to decide whether to show an "AI Info" label — it's the single easiest signal for them to act on. SynthGuard does not read, parse or target C2PA: a manifest is bound to the exact bytes it was signed over, so any re-encode leaves it behind.
METADATA · EXIF / XMP TAGS
Generators also write plain metadata flags — EXIF, XMP, IPTC fields and the "digitalSourceType: trainedAlgorithmicMedia" hint. Trivial to read, trivial to strip — but on their own they're only half the picture.
VISIBLE · BURNED-IN OVERLAY
The on-screen logo overlay some tools burn into video frames is a different problem from invisible watermarks — it's pixels in the picture, not a signal. Removing it is a crop or inpaint step, separate from the humanization pipeline.
Provenance signals
How it runs
The whole flow stays inside your browser tab — no file ever reaches a server.
Image or video — single file or batch. Nothing uploads; the file stays in your browser tab.
Rebuild export metadata and adjust selected pixel-level signals. C2PA, SynthID and private classifiers use different mechanisms.
Compare the export with the free in-browser AI Image Detector. Its eight-signal result is diagnostic, not proof of origin.
Check the exported metadata, visual quality and the current disclosure rules of the platform where you plan to publish.
By generator
Each generator signs its output differently. The right tool depends on whether you're working with a still image or video.
Privacy model
Pixel data stays in browser memory and is not uploaded for processing; account and quota metadata may still be recorded.
Disruption runs in a sandboxed worker thread — disable your network and it still works.
The local workflow does not store media content on a processing server.
Drop many files at once; each processes locally on its own thread.
Adjust pixel signals, inject PRNU, rebuild camera-style EXIF.
Raise burstiness and perplexity while preserving meaning.
Geometry, colour, codec and container rewrite for AI video.
Strip zero-width characters and odd spaces from AI text — free.
Free verification — scores any image 0–100 confidence.
Strip GPS, camera and timestamp data from any photo — free.
FAQ
A C2PA manifest is a signature over an exact byte sequence, so it is not carried into a newly encoded file — re-encoding an image leaves it behind. Plain EXIF, XMP and IPTC “Made with AI” fields are ordinary metadata and can be deleted directly with the free in-browser EXIF remover. Neither step affects a pixel-embedded watermark such as SynthID.
Several, including SynthGuard. Both the EXIF remover and the photo humanizer run entirely in your browser with no upload: the EXIF tool deletes attached EXIF fields such as GPS and device data, while a full re-encode through the humanizer rebuilds the file so a signed provenance manifest is not carried over. Dedicated metadata-only removers exist too and are a reasonable choice when provenance data is all you need gone.
Metadata removal can omit C2PA, Content Credentials and ordinary EXIF/XMP fields from a new export. It does not by itself address pixel-embedded systems such as SynthID. SynthGuard adjusts selected image characteristics but cannot certify removal against a current or future verifier.
A visible watermark is a logo or text burned into the picture (the on-screen mark some video tools add). An invisible watermark like SynthID is a statistical pattern woven into the pixels that only a verifier can read. SynthGuard targets the invisible and provenance markers plus metadata. A visible burned-in logo is a separate crop or inpaint step — handle that first, then humanize the result.
SynthGuard adjusts selected spatial and frequency characteristics, but SynthID verification is controlled by Google and can change. The tool cannot certify that a watermark has been removed or that a current or future verifier will not detect it.
Any re-encode can change pixels or compression. Default settings aim to keep changes subtle, but inspect the exported file at full size and retain the source if visual fidelity or provenance matters.
Partly. The video humanizer re-encodes and replaces container metadata, so container-level provenance is not carried over. It does not run the image pipeline's per-frame layers, so a pixel-embedded watermark such as SynthID is not addressed on video. For audio, the soundtrack is rebuilt by default — resampled through an intermediate rate, EQ-nudged and re-encoded — which changes the signal without being a certified removal; dropping the track entirely is the only reliable option and is available as a one-click mode.
Products differ: some only edit visible marks, some remove metadata, and some process files on a server. SynthGuard processes supported image and video media locally and combines re-encoding, metadata handling and selected pixel-level adjustments.
Not necessarily. Labels can depend on provenance metadata, creator disclosure, visible context and private platform systems. Editing a file does not guarantee that a label will be removed or that disclosure is no longer required.
Laws, contracts and disclosure duties vary by jurisdiction and use case. Only process content you are entitled to use, preserve required disclosures and follow current platform rules. SynthGuard does not provide legal advice or identity-impersonation features.
Open the humanizer, inspect the source, process it locally and compare the exported metadata and image signals. Verifier and platform outcomes are not guaranteed.
All third-party names, logos and trademarks (e.g. Hive, Optic, Sensity, Sightengine, Illuminarty, GPTZero, Instagram, TikTok, OnlyFans, Fanvue, SynthID, C2PA) are the property of their respective owners. SynthGuard is an independent service and is not affiliated with, endorsed by, sponsored by, or partnered with any of these companies or platforms. Detector and platform names are used solely for descriptive comparison under § 6 UWG / Art. 4 Directive 2006/114/EC.
We use a small number of cookies to keep you signed in. With your consent we'd also like to load privacy-friendly analytics so we can improve SynthGuard. See our Privacy Policy.