Skip to content
Toolars
Explore
Published workflowRuns locally

Privacy sanitizer workspace

A cleaned copy with supported metadata checked again.

Review location, device, time, author, and software metadata before sharing a file.

01

1. Add files

Choose or drop files after the local workspace opens.

Your files will start here

The local file picker and queue load only after you open the workspace.

02

2. Set the result

Result constraints and advanced options will appear here without changing the fixed operation order.

Processing plan

  1. Scan locally
  2. Choose fields
  3. Clean and re-check

Preset storage is local and versioned. Files, file names, inputs, outputs, and history are excluded by schema.

File controls load after an explicit action. Processing and downloads stay in this browser tab.

What the privacy workspace inspects and cleans

Input

  • Up to 12 JPEG, PNG, or PDF files and 96 MB per mixed batch
  • Images up to 12 MB each and PDFs up to 30 MB each
  • Files the browser can parse locally without a password

Output

  • A new copy with only the metadata scopes you selected removed
  • A local risk review for location, device, author, timestamps, text, comments, and supported custom fields
  • A re-read verification receipt labeled Verified clean or Verified with limits

Local processing boundary

Source files, metadata values, selected fields, cleaned bytes, and run history remain in this browser tab. Toolars analytics and storage do not receive them.

Visible test method

The release matrix scans a generated JPEG containing GPS, camera, serial, and time fields plus a PDF with document information, cleans selected scopes, then reopens both outputs before enabling download.

  1. Detect the true file type from bytes and classify supported findings by risk.
  2. Remove only the selected namespaces while preserving image pixel data whenever orientation does not require re-encoding.
  3. Reopen the output, check requested fields again, and report unsupported namespaces as unchecked rather than safe.

Important limitations

  • PDF XMP streams, attachments, and embedded-object metadata are not fully parsed and remain explicitly unchecked.
  • Removing EXIF orientation from a rotated JPEG requires re-encoding; the workspace discloses when that safety step broadens cleanup.
  • Removing an ICC profile may change color appearance, so it is excluded from the recommended image selection.
  • A clean result covers selected supported namespaces only; it is not a forensic guarantee that no hidden data exists.

Common failures and recovery

The file type is unsupported or damaged

Remove it and retry with an unlocked JPEG, PNG, or PDF from the original source.

The result is Verified with limits

Review the unchecked namespaces and use a specialist document tool when complete forensic removal is required.

The browser runs out of memory

Reduce the batch size, close unused tabs, and run the files in smaller groups.

Privacy cleaning FAQ

Are files or metadata uploaded to Toolars?

No. Scanning, cleaning, verification, ZIP creation, and download run in the active browser tab.

Does Verified clean mean the whole file is guaranteed metadata-free?

No. It means every selected, supported namespace was absent when Toolars reopened the output.

Why is ICC not selected by default?

ICC is a color profile rather than typical personal metadata; removing it can alter how colors display.

Written by
Toolars Product & Engineering
Reviewed by
Toolars Privacy & Accessibility Review
Last tested
Content updated