---
title: Photo Share-Safe
emoji: ๐ท
colorFrom: yellow
colorTo: gray
sdk: static
pinned: true
app_file: index.html
license: apache-2.0
short_description: Strip photo GPS/EXIF, blur faces & plates, in-browser
thumbnail: https://huggingface.co/spaces/cleanroom-ai/photo-exif-privacy/resolve/main/assets/social-preview.png
models:
- PaddlePaddle/PP-OCRv6_tiny_det
- PaddlePaddle/PP-OCRv6_tiny_rec
- opencv/face_detection_yunet
tags:
- exif
- metadata
- exif-remover
- gps
- photo-privacy
- face-blur
- license-plate
- privacy
- anonymization
- image-privacy
- gdpr
- ocr
- onnx
- in-browser
---
# Photo Share-Safe

[](https://github.com/cleanroom-ai/photo-exif-privacy/actions/workflows/ci.yml)
[Hugging Face demo](https://huggingface.co/spaces/cleanroom-ai/photo-exif-privacy)
**Strip GPS & hidden metadata, blur faces and plates โ before you post. Runs 100% in your browser.**
## Why
Real photos often carry precise GPS coordinates that can reveal a home, school, workplace, or travel routine. Cropped photos can also contain embedded thumbnails that still show the original uncropped scene. Photo Share-Safe reports those risks before sharing and exports a verified clean copy.
## Features
- Parses JPEG EXIF/XMP (including Extended XMP)/IPTC/ICC/APP/thumbnail data, PNG text/eXIf/trailing chunks, and WebP EXIF/XMP metadata locally.
- Ranks GPS, serial numbers, owner/copyright, capture time, comments, thumbnails, and XMP edit history.
- Uses bundled cleanroom-ai OCR + YuNet face detection in a Web Worker.
- Flags short plate-like OCR text and standalone digit strings such as house numbers.
- Lets you untick or manually draw boxes, then blur, pixelate, or black-box them.
- Exports a clean copy or STORE-only ZIP; re-parses output to verify GPS/camera/thumbnail data is gone.
- Optional JPEG lossless metadata strip keeps original pixels when no visual redactions are selected, using a strict rendering-marker allow-list.
## How it works
```
photo bytes โโบ metadata parsers โโบ privacy report
canvas pixels โโบ PP-OCRv6 + YuNet โโบ review boxes โโบ redacted canvas / lossless strip โโบ verified export
```
No CDN, analytics, external fonts, map, or geocoding service is used. A strict CSP and browser E2E test check that photos are never uploaded.
## Run locally
```bash
npm ci
npm run vendor
npm run examples
npm test
node node_modules/@cleanroom-ai/core/scripts/serve.mjs .
```
Then open (or the port printed by the server).
## CI/CD
CI runs unit tests, vendors the shared engine, launches a real browser, checks no uploads/third-party requests, and uploads screenshots. Deployment to Hugging Face Spaces is optional and only runs when `HF_TOKEN` is configured.
## Limitations
- HEIC display depends on browser decoding support.
- OCR can miss tiny, stylized, blurry, or low-contrast text; always review manually.
- The app does not reverse geocode GPS coordinates and intentionally avoids map services.
- Lossless JPEG stripping cannot rotate pixels; photos with EXIF orientation are re-encoded on export.
## Part of cleanroom-ai
**Clean it before you share it.** Six free privacy tools built on one shared engine. Every model runs
in your browser, so nothing you open is ever uploaded.
| | Tool | Cleans | Demo | Code |
|---|---|---|---|---|
| ๐ถ๏ธ | **Screenshot Redactor** | API keys, passwords, emails, card numbers, names, faces & QR codes in screenshots | [โถ Try it](https://huggingface.co/spaces/cleanroom-ai/pii-privacy-redaction) | [GitHub](https://github.com/cleanroom-ai/screenshot-redactor) |
| ๐งฝ | **Log Scrubber** | tokens, cookies, passwords & PII in logs, `.env`, JSON and HAR files | [โถ Try it](https://huggingface.co/spaces/cleanroom-ai/log-secret-scrubber) | [GitHub](https://github.com/cleanroom-ai/log-secret-scrubber) |
| ๐ | **PDF Redactor** | PII & secrets in PDFs, flattened and verified so no text survives | [โถ Try it](https://huggingface.co/spaces/cleanroom-ai/pdf-redaction) | [GitHub](https://github.com/cleanroom-ai/pdf-redaction) |
| ๐ | **Audio Redactor** | bleeps names, phone & card numbers and secrets in recordings | [โถ Try it](https://huggingface.co/spaces/cleanroom-ai/audio-pii-redaction) | [GitHub](https://github.com/cleanroom-ai/audio-pii-redaction) |
| ๐ท | **Photo Share-Safe** ๐ *you are here* | GPS & hidden EXIF metadata; blurs faces and license plates | [โถ Try it](https://huggingface.co/spaces/cleanroom-ai/photo-exif-privacy) | [GitHub](https://github.com/cleanroom-ai/photo-exif-privacy) |
| ๐ฌ | **Video Redactor** | keys, names, emails & faces tracked through screen recordings | [โถ Try it](https://huggingface.co/spaces/cleanroom-ai/video-redaction) | [GitHub](https://github.com/cleanroom-ai/video-redaction) |
| โ๏ธ | **@cleanroom-ai/core** | the shared on-device engine: OCR, secret/PII rules, NER, face detection | โ | [GitHub](https://github.com/cleanroom-ai/cleanroom-core) |
All tools: [Hugging Face](https://huggingface.co/cleanroom-ai) ยท [GitHub](https://github.com/cleanroom-ai)
## Author
Built by **Parag Sawant** [@paragpsawant](https://github.com/paragpsawant) ยท [parags.dev](https://parags.dev) ยท [LinkedIn](https://www.linkedin.com/in/paragsawant/)
## Credits & licenses
Part of **cleanroom-ai**. Apache-2.0. Uses [@cleanroom-ai/core](https://github.com/cleanroom-ai/cleanroom-core), PP-OCRv6 tiny, YuNet, and ONNX Runtime Web. License texts are copied by `npm run vendor` into `licenses/` and model license files into `models/LICENSES/`.