Choose the right tool
| I want to… | Tool |
|---|---|
| See the camera and photo metadata | EXIF Viewer → |
| Inspect every metadata field available | Image Metadata Viewer → |
| Investigate whether an image shows processing signals | Image Forensics → |
| Investigate AI and provenance signals | AI Image Provenance → |
| Check for Content Credentials markers | C2PA Checker → |
| Compare file fingerprints and identity | Image Hash Checker → |
If you're still unsure: upload on the homepage analyzer and read the report top to bottom — it is the union of all six tools.
How PictureMatters analyzes images
Every tool shares the same seven-stage pipeline. Understanding it helps you read any report correctly.
- File validation — the upload is identified by its actual bytes: file signatures, MIME detection and pixel decoding. Filenames and extensions are never trusted; a renamed archive fails validation, as does anything that is not genuinely a JPG, PNG or WebP.
- Metadata extraction — the analyzer walks the file's real container and decodes the records inside: EXIF (camera, lens, exposure, timestamps), GPS coordinates, XMP workflow fields and IPTC declarations, including AI digital-source labels.
- Binary and structure inspection — the container is mapped segment by segment: JPEG markers, PNG chunks, WebP boxes, comments, color profiles, and any data riding after the image's proper end marker.
- Image fingerprinting — an exact SHA-256 of every byte, plus a 64-bit perceptual fingerprint derived from the image's brightness gradients for near-duplicate comparison.
- Provenance detection — recovered strings are matched against a curated signature list: editors, exporters, camera firmware, messaging apps and AI generators; plus C2PA / Content Credentials markers and IPTC source declarations.
- Signal interpretation — the findings are composed into a Journey reading: a consistency assessment of what the file's signals suggest about its history, explicitly labeled as interpretation rather than verdict.
- Report generation — everything lands in a single structured page: facts, signals and interpretation in separate registers, with a standing limitations note. The report expires automatically with its data.
The methodology page documents each layer in depth, including what it can and cannot establish. To see the output before uploading anything, read the sample report.
Privacy: temporary by design
Uploads arrive in small chunks under server-issued session tokens, are validated, analyzed, and deleted — the original image is removed immediately after the report is built, and the report itself expires within 15 minutes. There is no account system, no database, and no gallery of your files. Abuse controls (rate limits, session caps, storage ceilings) protect the service without storing anything that identifies you. The full architecture is on the security page, and the privacy policy covers data handling in plain language.
Limitations — read this before relying on a report
PictureMatters produces analytical evidence, not authentication. Metadata can be edited or stripped; markers can be forged; entropy is statistical. A report cannot prove an image is authentic, fake, edited, or AI-generated — it tells you what technical signals the file carries and what they may mean. For decisions that matter, combine reports with source verification and context, and read the limitations section of every report. The methodology is explicit about the boundary of each layer.