Metadata Cleaner

Privacy Policy

Last updated: July 11, 2026

Metadata Cleaner – Privacy (“Metadata Cleaner”) is a native iPhone and Mac app with a browser companion. This policy explains what stays local, the limited data used for the native free-export allowance, and how purchases and support work.

Media and document processing

The native app inspects and cleans user-selected photos, Live Photos, videos, PDFs, and supported Word, Excel, and PowerPoint documents on the device. It does not upload the selected file, filename, metadata values, cleaned copy, visual-privacy findings, provenance assertions, or verification receipt to a cleaning service. Originals remain unchanged unless you independently replace them outside Metadata Cleaner.

Native C2PA and Content Credentials inspection reads the selected local file. Remote manifest retrieval, OCSP retrieval, and remote network hosts are disabled for this verification path. A structural fallback can report only that provenance-shaped data exists; it is not an AI detector.

The web cleaner processes selected photos and videos in your browser. Cleaned-history summaries are stored in that browser's local IndexedDB storage. The selected media and cleaned bytes are not uploaded by the cleaner. You can remove browser-local history by clearing site data.

Native free-export allowance

The native app includes three free exports per physical device. To make that allowance resistant to reinstall, a quota request sends an opaque Apple DeviceCheck token, an optional count of exports being reserved, and a non-personal development or production environment marker to our quota endpoint. The endpoint uses Apple DeviceCheck's two-bit state to read or update a count from zero to three. It does not receive media, filenames, metadata contents, an Apple ID, an advertising identifier, an email address, or purchase history. Premium exports do not consume this allowance.

The quota endpoint is hosted by Supabase and communicates with Apple DeviceCheck. Our endpoint code does not create an account or store the raw token in an application database. Apple, Supabase, Vercel, and network providers may process limited technical request information under their own policies to deliver and secure their services.

Purchases

Product information, purchases, entitlement checks, promoted purchases, and restoration use Apple StoreKit 2 directly. Metadata Cleaner does not forward StoreKit transaction history or purchase events to a developer analytics server. Apple processes App Store billing and transactions under Apple's privacy terms.

Local history, diagnostics, and support

Cleaning history, settings, quota cache, purchase-state cache, fault counters, and a random Support ID are kept locally in the app or its app group. The app does not automatically upload diagnostics or crash summaries. If you choose Contact Support, the app creates an editable email draft that can include the app version, Support ID, and a visible diagnostics summary. Nothing in that draft is sent until you choose to send it.

Website operations and tracking

The public website is hosted on Vercel, so ordinary web requests may include technical information such as an IP address, browser type, requested URL, and request time for delivery, reliability, and security. We do not use advertising SDKs, sell personal data, create advertising profiles, or track people across apps or websites.

Your choices

Metadata Cleaner has no app account. You can remove app-local data by deleting the app and browser-local data by clearing this site's storage. The Apple DeviceCheck free-export state is intentionally reinstall-resistant and is not an account profile. You decide whether to send a support email and can edit or remove its contents first.

Contact

For privacy questions, email ismailharmanda.dev@gmail.com or use the Support page.