Lilith.
⌕
Editorial illustration: Photo Scrubber removes faces and metadata inside the browser
Lilith illustration · editorial remix

Photo Scrubber processes a photograph locally in the browser, marks faces automatically and lets the user blur them before sharing. Export creates a new file without the original metadata, so a sensitive image does not have to travel to somebody else's server.

BlazeFace finds faces without sending the photograph to a server

Simon Willison built the tool after photographing protesters and deciding that he did not want to share identifiable faces of strangers. He had GPT-6 Astra create the experimental application. Detection uses Google's MediaPipe C++ library compiled to WebAssembly through @mediapipe/tasks-vision, together with the BlazeFace model.

The tool accepts JPEG, PNG and WebP files up to 75 MB. Decoding and editing happen on the user's device. The browser applies EXIF orientation while loading, but the exported image is created afresh without the original metadata bundle.

Local processing turns privacy from a promise into architecture

For photographs from protests, hospitals or schools, uploading the original image to an external service is already a risk. A browser tool reduces that class of exposure because the photograph does not leave the device for face detection or export. That is a practical difference from a cloud editor with vague retention terms.

The project also demonstrates a useful pattern for AI coding. A model helped assemble a small application around existing components, while the security property comes mainly from architecture. Privacy depends on the browser boundary and an inspectable export, not on a model's promise.

A short-range detector still leaves blind spots

BlazeFace is a short-range detector. It can miss small, rotated, obscured or edge-of-frame faces, and automatic blur does not necessarily hide name badges, tattoos, number plates or distinctive clothing. Metadata can be removed while the pixels still identify a person.

Photo Scrubber is explicitly experimental. Local execution reduces network exposure but does not guarantee complete anonymization. For sensitive material, a user must inspect the entire image and manually cover anything the detector missed.

Safe export depends on both the file and the edge of the frame

The next test has two parts. Independent inspection should confirm that exported JPEG, PNG and WebP files contain none of the original EXIF or other metadata. Detection should also be measured in crowds, poor light and at the edge of a photograph.

The tool becomes more valuable if it provides a clear manual review step and shows that the user has examined the entire frame. For identity protection, the final missed face matters more than average detector accuracy.

Lilith's verdict

The real test comes when a photographer reaches for Share and one unblurred face remains in the corner. Local processing closes the network route, but attentive eyes still have to close the final visual one.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗