For journalists, newsrooms & human-rights researchers

Protect your source before the photo ever leaves your device.

See what a leaked image is quietly revealing — GPS, timestamps, a camera serial — then strip it and irreversibly blur a face. Every step runs in your browser. The source's photo never reaches a server you don't control.

The duty a careless photo can violate.

One ethics principle every newsroom recites — and one famous photo that gave a man's hiding place away.

SPJ Code of Ethics — Minimize Harm

Balance the public's need for information against potential harm or discomfort… Recognize that legal access to information differs from an ethical justification to publish or broadcast. Consider the long-term implications of the extended reach and permanence of publication.

Protecting a confidential source is a core obligation, and reporter's-privilege norms exist precisely so sources can speak safely. But a leaked photo can betray that source on its own: in 2012 a Vice photo of John McAfee carried GPS coordinates in its EXIF that pinned his location in Guatemala. keptimage shows you what an image is leaking and lets you strip it — before the file leaves your hands.

Three ways a single photo can burn a source.

A recognizable face

A clear face — yours, a bystander's, a whistleblower's — is enough to identify someone. A blur or pixelation that can be reversed isn't protection; only destroying those pixels is.

GPS & timestamps in EXIF

Phone and camera files embed exact coordinates and the moment of capture. Publish or forward the original and you may pin where a source was, and when — the McAfee mistake, repeated.

A camera serial that links images

EXIF often carries the camera's body and lens serial. That fingerprint can quietly tie an "anonymous" photo back to a device — and to every other image it ever took.

Built for how source material actually arrives.

See what the photo reveals

Remove Metadata first shows you what's hidden — the GPS pin, the timestamp, the camera serial — then strips it, so you know exactly what you were about to leak.

Irreversibly redact a face

Redact overwrites the pixels under a face or detail — there's no liftable layer — and the output ships with a SHA-256 certificate attesting the file's origin.

Auto face-blur for crowds

Protest and crowd photos can expose dozens of bystanders. Automatic face detection blurs every face it finds in one pass — review the result, since detection isn't perfect.

Background removal & cleanup

Remove Background isolates a subject for a story graphic — locally, so the original frame and everything around it never touches a server.

How it works.

Four steps, zero uploads. Watch your network tab if you don't believe us.

  1. Drop the photo in

    Open the app and drop a source's image — JPG, PNG or WebP. It loads straight into your browser's memory; nothing is sent anywhere.

  2. See what's hidden

    keptimage reads the EXIF and shows you the GPS pin, the timestamp and the camera serial the file was carrying — the reveal most tools never show you.

  3. Scrub & redact

    Strip the metadata, then irreversibly blur or black out faces and identifying details. Pixels are overwritten and the file is re-encoded — no liftable layer remains.

  4. Download — nothing uploaded

    Save the clean image with its SHA-256 certificate. Because the work happened on your device, there is no cloud copy of the original to subpoena, breach, or leak.

A note on publishing: social platforms strip provenance and re-encode on upload, so a certificate attests origin before you publish — it travels separately, not baked into the posted image.

How we compare.

Same redaction. Very different exposure for your source.

Capability keptimage Cloud redaction service remove.bg / online editor
Source image is processed in your browser — never uploaded
Shows you the GPS / EXIF a photo is leaking
Destroys the underlying pixels under a face (no liftable layer)
Strips EXIF / GPS metadata in the same pass
Ships a verifiable SHA-256 certificate of origin
No vendor-side copy of the original to retain, breach, or subpoena
You can verify zero uploads yourself — watch the network tab

✓ yes · – partial, depends on workflow · ✗ no. Marks reflect typical default workflows as of May 2026. Dedicated cloud redaction services do destroy pixels, but the source file is uploaded and a copy is retained server-side; remove.bg and general online editors see the original and rarely strip metadata or issue a certificate. keptimage does all of it locally — the source's photo never leaves your browser.

What we do — and what we don't claim.

keptimage exists to keep source material on your device. When you reveal a photo's hidden data, strip it, or blur a face, the file is processed entirely inside your browser. The code loads once on the page visit; after that, no image content returns to our servers. There is no upload endpoint to attack, subpoena, or breach — which is the whole point when the file could identify a source.

We're deliberate about the limits. Automatic face detection is a convenience, not a guarantee — it can miss a face or blur the wrong thing, so review every result before you publish. Our SHA-256 certificate attests a file's origin and integrity — that this exact image came out of keptimage unaltered — it does not prove the photo is "true," and we make no claim to detect or defeat deepfakes.

And because publishing platforms re-encode and strip provenance on upload, attestation is a separate artifact from the posted image: keep the certificate alongside your records, not baked into the file you publish.

You shouldn't have to take our word for any of it. Open the Verify page, open your browser's network tab, and watch zero outbound uploads happen.

Pricing for newsrooms.

Freelance reporter or solo researcher? Start free — no card, or upgrade to Pro ($9/mo) inside the app.

See exactly what a source's photo is leaking — before anyone else can.

Open the app