Short answer

A PNG can contain readable text that never appears in the picture. Inspect every text chunk, including compressed and international fields, preserve the source, and clean only a public copy before checking the uploaded result.

Try these tools

Metadata Remover

Open tool

Separate the visible picture from stored text

A PNG is a sequence of typed chunks, not just a grid of pixels. The tEXt chunk stores a keyword and Latin-1 text, zTXt stores compressed text, and iTXt supports international text with optional compression. These values do not have to appear in an ordinary image preview, yet a recipient can extract them from the file. A clean-looking screenshot therefore cannot be treated as proof that the PNG contains no descriptive or identifying information.

Start by identifying the source and destination. Screenshots, design exports, scientific images, and editor project outputs may carry different software fields or comments. Decide whether the public file should retain a title, rights notice, or source statement. Mark personal names, email addresses, client names, internal project codes, local paths, and work notes for review. Preserve the original PNG and edit a distribution copy so a useful field can be restored without recreating the asset.

  • Inspect pixels and chunks separately
  • Classify allowed and private text
  • Work on a copy of the original

Text that is invisible in the rendered image can still be read from the file.

Enumerate every keyword and custom value

The PNG specification gives familiar keyword examples such as Title, Author, Description, Copyright, Creation Time, Software, Disclaimer, Warning, Source, and Comment. Files are not limited to those examples. An application or workflow can write custom keywords, and the same keyword can occur more than once. Export the chunk type, keyword, language tag, translated keyword, and value for every text entry instead of searching only for a short list of standard names.

Simple string search may miss compressed zTXt or compressed iTXt data, so use a parser that understands PNG structure. International fields can contain text in scripts that a narrow visual scan overlooks. Examine long comments for embedded JSON, generation instructions, file paths, usernames, or application settings. Treat an unfamiliar value carefully: investigate whether it is needed for the public use, but do not keep it merely because its purpose is unclear. Record the original report before cleaning.

  • List all chunk types, keywords, and values
  • Decode compressed and international text
  • Check duplicates and custom keywords

Expand the audit beyond text chunks

A text-chunk review is important but not a complete PNG privacy audit. Depending on the file and tools, other metadata areas can expose Exif or XMP values, timestamps, profiles, or application-specific information. Review every group reported by the metadata reader and save the report so the inspected scope is clear. Tool labels may describe logical tag families rather than literal chunk names, so map findings back to the actual file structure when a result is uncertain.

Visible content is another independent channel. A metadata remover cannot erase account names, notifications, document titles, addresses, map positions, faces, QR codes, or browser tabs captured in the pixels. Zoom to a readable size and inspect all corners as well as the main subject. If redaction is needed, use an opaque replacement and flatten the final image; a blur may leave recognizable shapes. Reopen the flattened copy and confirm that hidden layers or editing data were not exported.

  • Review all reported metadata groups
  • Inspect visible identifiers at full size
  • Flatten and verify any redaction

Removing metadata does not remove information that is part of the pixels.

Clean a copy and verify the PNG remains valid

Apply the metadata remover to a duplicate, using an explicit policy for fields to retain. Then parse the cleaned file again rather than trusting a success message. Confirm that targeted tEXt, zTXt, and iTXt values are absent, allowed values are accurate, and no duplicate or empty placeholder chunks remain. Also confirm that required color and transparency information was not removed accidentally. A privacy change should not silently alter the intended rendering.

Open the cleaned file in at least two PNG-capable applications. Compare pixel dimensions, transparency, edges, gradients, and color with the source. Structural damage can be subtle if one viewer recovers from an invalid chunk while another does not. Keep a checksum or immutable copy of the archival original and name the sanitized file clearly. For repeat work, record the remover version and options so the same policy can be reproduced and reviewed later.

  • Parse the cleaned copy again
  • Confirm transparency and color behavior
  • Record tool version and removal policy

Inspect the published version, not only the upload

Send a representative PNG through the real website, repository, chat service, or document system. The destination may optimize the image, preserve the original, generate thumbnails, or expose both versions. Download each recipient-accessible file and repeat the chunk and pixel review. Check whether the public URL serves the cleaned upload or a cached older asset. A local pass is incomplete when the platform creates another distributable copy.

Make the final decision against a written checklist: no disallowed text values, no unexpected metadata groups, no visible identifiers, correct transparency, correct color, and a valid decoded image. If any check fails, return to the preserved source and generate a new public copy rather than editing an already processed derivative. Approve batch handling only after different PNG sources pass the full path. This practical endpoint prevents a correct local cleanup from being undermined downstream. Retain the audit report with the approved public asset so later reviewers can reproduce the decision.

  • Download all public variants
  • Check caching and generated thumbnails
  • Approve batches only after end-to-end tests

The relevant privacy result is the file a recipient can actually access.

Key takeaways

  • PNG tEXt, zTXt, and iTXt chunks can store keywords and values independently of the visible pixels.
  • Author, comment, software, time, path, and custom fields can reveal personal or internal work information.
  • A structure-aware tool is needed to read compressed text, international text, duplicate keywords, and custom chunks.
  • Clean a copy, validate pixels and structure, and inspect the version created by the destination service.

Frequently asked questions

Can PNG files contain comments that are not visible?

Yes. tEXt, zTXt, and iTXt chunks can store comments and other keyword values independently of the displayed pixels.

Why might a normal text search miss a PNG comment?

The text may be compressed in zTXt or iTXt, encoded as international text, or stored in a structure the search does not decode.

Are standard PNG keywords the only ones I need to inspect?

No. Applications can write custom keywords and repeated values, so enumerate every text chunk rather than checking only familiar names.

Does removing text chunks remove all private information?

No. Other metadata groups and visible pixel content can still disclose information, and both require separate review.

How do I confirm a cleaned PNG is safe to publish?

Parse it again, inspect the pixels at full size, test transparency and color, then download and examine the version served by the destination.

Sources and references

  1. W3C — Portable Network Graphics (PNG) Specification, Third Edition
  2. ExifTool — PNG Tags