Technical explainers

Video Metadata and Privacy: What Face Anonymization Does Not Remove

A blurred face does not hide location tags, filenames, timestamps, or subtitles. Check the exported file and the information visible inside the picture.

On this page

A video can hide every face and still arrive with a filename that names the person. It can also reveal a location through a caption, a camera timestamp, or metadata stored inside the file.

These are different problems. Removing a metadata field will not remove an address printed on a parcel in the picture. Blurring the parcel will not rename the download.

Treat the exported file and the video it contains as two separate things to inspect.

Check the package around the video

Before sending a file, look at its name, the folder or sharing link, and the message accompanying it. A carefully redacted interview called “FullName-home-interview.mp4” defeats a fairly obvious part of the work.

Use a neutral filename that still lets you distinguish versions, such as “interview-public-v03.mp4.” Make sure a shared folder does not expose the original alongside it. If you send a project rather than a finished video, check whether the project includes source media, proxies, or links to unredacted assets.

A recipient may also see the owner's account name or the title of a shared collection. Review the actual recipient view, not just your local folder.

Inspect metadata without uploading the footage

Your operating system's file-properties panel is a useful first look, but it may not display every field.

For people comfortable with a terminal, a local installation of FFprobe can inspect format and stream information. Run this against a non-sensitive test file first:

ffprobe -v error -show_format -show_streams -of json "public-copy.mp4"

The official FFprobe documentation explains its format, stream, and output options. Look through the reported tags and streams for unexpected titles, comments, dates, location information, subtitles, or additional tracks. The command reports information; it does not modify or sanitize the file. Do not publish its output if that output contains identifying details.

Absence of a familiar tag is not proof that a file contains no identifying information.

Inspect what is baked into the picture and sound

A surveillance timestamp visible in the corner is part of the image. So are usernames on a recorded call, text on a screen, and a street sign behind the speaker. These require an image edit, a crop, or a different shot—not a metadata cleanup.

Listen to the audio separately. Spoken names and background announcements are not metadata either. Check captions and subtitle tracks against the audio; muting a name is ineffective if the subtitle still spells it out.

Recheck the final export

Do metadata inspection after the last edit, because each export creates a new file. If you use another application to remove metadata or tracks, play that resulting file again and confirm that orientation, sound, timing, and face masks still look right.

Unseen's face effects target faces. Do not treat them as a documented metadata-sanitization feature. The file you send needs its own final check, even when the face edit is finished.

Try it on a short clip

Start with a difficult moment from your video, then inspect the exported result.

Open Unseen