Forensic Cleaner by Two Tensors

AI Detection Remover

A hosted tool that lowers the statistical signals AI image detectors read, and returns an export that still looks like the file you started with.

What the remover actually is.

Forensic Cleaner is a hosted image pipeline. You hand it a file you own, it reprocesses the pixels on our GPUs, and it returns an export that scores differently to an AI image detector while still reading as the same picture to a person.

One job, run the same way every time

There is nothing to install and no local model to maintain. Sign in, open the Forensic Cleaner, drop in a PNG, JPG, or WEBP, and the app checks the file, scores how hard it expects the clean to be, and runs the pass at the strength you chose. Finished jobs stay in your account history, so a setting that worked can be repeated later or cleared out.

Not a repaint, and not a metadata tool

The model is not building a new picture out of yours. It does not restyle the frame, move the subject, or invent detail that was never in the source. It is also not a dedicated metadata cleaner, even though metadata does fall out of the pipeline along the way. If what you want is the click by click version of one run, that lives on the how to remove AI detection guide instead of here.

At a glance

  • Input PNG, JPG, or WEBP
  • Output One cleaned image, about 2 megapixels at most
  • Working size 768px on Free, 1024px on paid plans
  • Strength Strong on every plan, Quality on paid plans
  • Optional stage SynthID watermark removal
  • Automation API access on Pro and Scale

It moves the statistics, not the subject.

Detectors do not judge what your image is of. They score how it appears to have been produced, using distributions that survive a crop and a re-save. Those distributions are the surface the cleaner works on.

Pixel statistics

Relationships between neighboring pixels are the cheapest signal for a classifier to learn and the one it leans on hardest. The pass perturbs them on purpose.

Frequency

Generators and camera pipelines spread energy differently across the frequency range. Reprocessing shifts that profile without visibly softening the frame.

Encode history

Validation converts your upload to lossless WEBP before anything else runs, so the compression history of the file you sent does not carry into the export.

Watermark

SynthID is a mark somebody embedded deliberately, not a by-product of generation, so it gets its own stage rather than being folded into the clean.

~90% clean rate across three popular AI image detectors, measured in internal testing

What that number is, and what it is not

It is a measurement from our own testing against three widely used detectors. It is not a promise about your image or about the detector you happen to care about. Detectors get retrained without notice and thresholds move, so a file that reads clean this month can read differently later. Difficulty also varies enormously by image, which is why the app shows an AI slop score before you spend anything: it is an estimate of how hard that specific picture will be to clean.

The product reduces detector-facing signals. It does not claim invisibility, and it cannot speak for what any platform does with your upload afterwards.

What comes back.

One file, plus a few consequences that are worth knowing before you build anything on top of it.

The export

  • A close copy, not a reinterpretation The model is optimized for visual similarity, so the result should still read as your photograph rather than a new version of it. Hard images at Strong can show smearing or a color cast, and Quality mode on paid plans is the gentler pass for exactly that case.
  • Metadata does not survive the trip The lossless WEBP conversion in validation does not carry EXIF across, so camera model, lens, timestamps, and location fields are absent from the export. That is a by-product of how the pipeline is built rather than a metadata feature, so do not treat it as one.
  • A working size, not your native resolution Output is capped at roughly 2 megapixels, with Free accounts at 768px and paid plans at 1024px. The ceiling is not only a limit: on stubborn images the 1024px option can improve the result, and it tends to help SynthID removal too.
  • A record you can act on Cleaned files stay in your account until you clear them. Rerun one at a different strength, keep the version that held up, and remove the rest when the job is finished.

What we store and for how long is set out in the Privacy Policy. Allowed and prohibited uses are in the Safety Guidelines.

Where the SynthID stage sits.

Detector bypass and watermark removal are different problems, and the product keeps them apart. Bypass works on statistics that nobody put in the file on purpose. SynthID is the opposite: an imperceptible mark embedded into images that certain Google models generate, so it behaves like a payload to disturb rather than a fingerprint to smooth out.

In the app it is a toggle with its own strength control, and it can run on its own or on top of a normal clean. It is billed on its own terms at 3 credits, either standalone or added to a bypass job. On the API it is the remove_synthid_watermark flag, and turning detector_bypass off gives you the watermark stage by itself.

It is also the less predictable of the two. Medium strength is a sensible place to start, the 1024px option tends to help, and if a few attempts fail the honest reading is that this particular file may not clean. The SynthID remover page covers that stage in detail.

Who it is for.

Creators processing their own work

The intended user made the image and now has to put it somewhere that runs a detector: a photographer whose retouching used AI assisted tools, an illustrator who generated a base pass, a small team shipping product renders. The tool assumes the file is yours, and that assumption does real work. A detection remover is only defensible when the person running it owns the work, which is why the safety rules are short and unambiguous.

Anyone who needs the same result twice

Hand rolled noise, a quick blur, and a re-save are unrepeatable by definition. Two people doing it get two different files, and the same person doing it twice gets a third. A fixed pipeline with named strengths is duller and much more useful: you can say which setting produced a given export and get that export again next month. Pro and Scale add API access for when the run has to happen without anyone opening a browser, and the background on why detectors are brittle is worth reading before you automate anything.

The limits, stated plainly.

Forensic Cleaner lowers detector-facing signals. It does not make an image undetectable, and it cannot promise how a given detector, platform, or human reviewer will treat your file. Outcomes move with third-party model updates that we do not control.

Some detectors are unreliable in both directions and will call ordinary photographs generated, because their scores react to resolution and compression rather than to how a picture was made. Checking a result against more than one, for example TruthScan, Hive, or AI or Not, gives you a more honest read than trusting a single number.

Use it on work you own or are licensed to process. Impersonation, deception about a real person, non-consensual imagery, and unlawful use are outside what this product is for, and outside what the terms allow.

FAQ

Questions about the tool itself.

Is this something I install, or does it run on your side?

It runs on our GPUs. There is no plugin, no local model, and no desktop app to keep updated. You sign in, upload a PNG, JPG, or WEBP, and the job is validated, cleaned, and written back to your account history in the browser or through the API on Pro and Scale.

Does it repaint the image or generate a new one?

No. The model works on the statistical surface of the file rather than its content, so the subject, composition, and detail stay where you put them. It is closer to a reprocessing pass than to a generator, which is why the output should still read as your original picture.

Will EXIF and other metadata be gone from the export?

Yes, as a side effect. Validation converts the upload to lossless WEBP before cleaning, and that conversion does not carry EXIF fields across, so camera, lens, timestamp, and location data do not survive the round trip. It is a consequence of the pipeline, not a dedicated metadata product.

What is the difference between Strong and Quality?

Strong is the more aggressive setting and is available on every plan. Quality is the gentler pass, available on paid plans, and it is the one to reach for when Strong worked but left visible smearing or a color cast on a difficult image.

Does the remover handle SynthID as well?

SynthID removal is a separate optional stage with its own strength control, and it can run alone or alongside a normal clean. It is billed separately at 3 credits, and it is not reliable on every image, so treat it as a second tool rather than part of the same pass.

How large can the cleaned file be?

Output tops out at roughly 2 megapixels. Free accounts process at 768px and paid plans at 1024px, so a large source is handled at that working size rather than at its native resolution. Higher resolutions are limited by processing and GPU cost.

Can I run it on images I did not make?

Only if you hold the rights to process them. The product is built for people cleaning their own work, and impersonation, deception about a real person, non-consensual imagery, and unlawful use are out of scope. The Safety Guidelines are the binding version of that answer.