Free publisher resource
Embed a photo privacy checker
Give readers a practical way to inspect supported GPS coordinates, camera/device details, and capture time before sharing a JPEG. The selected file is read inside the visitor's browser. The widget does not include a file-upload endpoint.
Copy and paste
<div data-cu-photo-privacy-checker></div>
<script src="https://privacy.convertunlimited.com/embed/v1/photo-privacy-checker.js" defer></script>
Use the versioned /embed/v1/ URL in production. The unversioned URL remains a compatibility loader that currently resolves to v1.
Options
| Attribute | Example | Effect |
data-lang | th | Uses the Thai interface. English is the default. |
data-accent | #5b4bdb | Changes buttons and status accents. |
data-title | Check your photo | Overrides the widget heading. |
data-layout | compact | Uses a shorter card for sidebars and narrow article callouts. |
Compact example
Coverage and limitations
- The embedded checker reads selected JPEG APP1/EXIF fields: GPS, camera make/model, and capture time.
- It does not inspect IPTC, XMP, embedded thumbnails, AI provenance, or metadata containers in PNG, WebP, HEIC, PDF, or office documents.
- “No supported fields detected” is not a forensic guarantee that the file contains no metadata or identifying visual information.
- The widget inspects only. The linked metadata remover creates and verifies a cleaned JPG, PNG, or WebP copy.
Publisher terms
You may embed the hosted script on editorial, educational, nonprofit, and commercial pages. Do not conceal the source link, represent the limited inspection as forensic certification, or use the widget to imply that ConvertUnlimited endorses the host website. The attribution is part of the useful interface rather than a hidden search-engine link.
Content Security Policy
If your site uses a restrictive CSP, allow https://privacy.convertunlimited.com in script-src. The widget does not need a ConvertUnlimited entry in connect-src, img-src, or frame-src; selected files are read through browser file APIs and are not requested by the hosted script.
Content-Security-Policy: script-src 'self' https://privacy.convertunlimited.com
Publishing-platform compatibility
| Platform | Installation location | Important constraint |
| WordPress | Custom HTML block | The account or security plugin must permit external scripts; WordPress.com plans may strip them. |
| Ghost | HTML card | Add the script once per page or through Code Injection, not both. |
| Webflow | Embed element | Custom code requires a plan that permits embeds; publish the site after changing code. |
| Plain HTML | Inside the article body | Use defer and the versioned v1 URL shown above. |
Version policy
Version 1 keeps the current element attributes and result meanings stable. Fixes that preserve those contracts may ship at the same URL. A future incompatible interface or parser contract will use a new versioned path; publishers can remain on v1 until they choose to migrate.
- v1 · 2026-08-11: JPEG GPS, camera/device and capture-time inspection; English and Thai; full and compact layouts; Shadow DOM style isolation.
What this page provides
A copy-paste, dependency-free JavaScript widget that lets website visitors inspect supported JPEG privacy fields locally in their browser.
Recommended use
Embed it beside photo-sharing safety, digital-literacy, journalism, marketplace-selling, or family-privacy guidance where readers benefit from checking their own file.
ConvertUnlimited · Tools · About · Contact · Privacy · Terms · Trust Center