Before you share: a file privacy checklist
Removing metadata solves one part of file privacy. A photograph can lose its GPS tags and still show your address. A document can lose its author property and still name the author on page one. Use this workflow to check both the hidden fields and the content a recipient can see.
From original file to checked copy
Keep the original and choose the actual attachment
Work from a copy, especially for signed PDFs or Word documents with tracked changes. Check the extension: BeforeShare supports JPEG, PNG, WebP, PDF and DOCX. Renaming a HEIC photo or an old DOC file does not convert it. Export a supported copy in its original application first, then inspect that export.
Inspect before you clean
Open the metadata viewer and look for location coordinates, author names, camera identifiers, dates and editing software. Decide which details matter for this recipient. A creation date may reveal your working timeline; an author field may contain a previous collaborator rather than you. A missing field means the reader did not find it, not that the file has never contained private information.
Clean and read the result
Create the cleaned copy and review the remaining fields. Image width, height and other technical properties can remain because the file still needs to display. If removable fields remain, or verification could not finish, treat the result as incomplete. Do not assume that a successful download means every privacy check passed.
Open the downloaded copy
Check every page or the full image in a viewer. Look for names, addresses, reflections, comments, headers and screenshots of account details. Metadata cleaning does not redact visible content. For sensitive documents, remove that content in the source application and export again; covering text visually may leave the underlying text readable.
Check the file you will actually send
Reinspect the downloaded copy, and use a second local inspector for higher-risk files. Attach that copy, not the original sitting beside it. If another application edits or exports the file afterward, inspect the new export too: it may add fresh metadata. Do not depend on a messaging service to remove it for you.
Worked example: a photo with location tags
Illustrative fields, not a result from your file. Suppose inspection shows GPSLatitude, GPSLongitude, Artist and ImageWidth. Here is how to interpret the next step:
- GPSLatitude / GPSLongitude: location tags should no longer appear in the cleaned-copy inspection. If they remain, stop and review the result.
- Artist: an author name is removable metadata. Check the downloaded copy rather than relying on the original-file preview.
- ImageWidth: a remaining width is expected. Dimensions describe the image structure; their presence does not mean the GPS cleanup failed.
- A street sign in the pixels: still visible after cleaning. Crop or redact it separately, then inspect the exported file again.
What changes for each file type
JPEG, PNG and WebP
BeforeShare removes supported metadata containers without re-encoding the image data. JPEG retains supported display information such as orientation and the color profile. This is deliberately different from deleting every non-pixel byte. Visible watermarks and watermarks encoded into the image signal are outside this cleanup.
Image cleanup details →The cleaner targets supported Info and XMP properties. Read page text and examine annotations and attachments separately; these may still contain personal information. Saving a modified PDF can invalidate a digital signature. Keep the signed original when authenticity is important.
PDF scope and limitations →Word (DOCX)
Cleanup removes supported document properties, comments and review traces. Tracked changes resolve to the current visible document, so keep an original if you need the review history. Names in the body, headers and embedded content need a separate review.
Word scope and limitations →What a cleanup report proves
A report records what the BeforeShare reader detected before and after cleaning. Zero remaining supported removable fields is a useful check within that reader’s coverage, not a certificate of anonymity. The SHA-256 identifies the output bytes; it does not prove that a file is harmless, authentic or free of all hidden information. Reinspection with the same reader can share the same blind spots.
Try a reproducible example before using your own file
Our published experiment includes three synthetic image files, measured results and the executable test. It compares metadata, file hashes, dimensions and decoded pixels. It covers those fixtures, not every camera, document or browser. Download a fixture and compare your result with the published record.
Open the cleanup experiment →How this guide was prepared
Published by BeforeShare. This workflow follows the cleaner’s supported behavior and its report logic. The linked experiment is our own test; the Research Lab’s platform briefs are source-based summaries and identify evidence from other publishers. Examples here are illustrative and are not measurements of your files.
About BeforeShare and its scope →