What this is

Scrub is a locally-run command-line tool, MIT-licensed open source. Its core function in one sentence: wipe clean the "invisible tags" hiding inside your files. It handles three categories—

EXIF: capture timestamp, GPS coordinates, and camera model embedded in photos; C2PA: the "content provenance" marker led by Adobe and others, capable of identifying whether an image is AI-generated; hidden Unicode: zero-width spaces, variation selectors, and other characters invisible to the naked eye but used for tracking or bypassing moderation.

Everything runs locally—no file uploads—and the codebase weighs in at just a few hundred lines.

Industry view

Supporters see this as overlooked privacy infrastructure—most users have no idea what a single screenshot can leak, and Scrub compresses "self-protection" into a single command.

The counter-argument is equally clear: this category is a cat-and-mouse game with tracking tech. Clean today, new embedding tricks tomorrow.

More notably, C2PA's design intent is to make AI-generated content traceable. Scrub wiping it wholesale reads as "deliberate origin concealment" in the eyes of mainstream platforms.

And it's CLI-only, which still sets a high bar for non-technical users.

Impact on regular people

For enterprise IT: sensitive metadata leaks in internal document flows (think employee locations, unpublished draft watermarks). Scrub-class tools work as a baseline defense layer, but fall far short of covering every scenario.

For working professionals: the habit of "scrubbing first" before sending work screenshots or contract photos is seeping from the geek crowd into ordinary white-collar workflows—we expect this to become the new digital common sense.

For the consumer market: WeChat and Xiaohongshu have long auto-compressed and stripped EXIF, but provenance labeling for AI-generated images remains a gray area. Scrub won't rewrite platform rules, but it will surface the issue to early adopters sooner.