AI Watermark Remover for Text
See what is hidden in AI-generated text - and remove what can be removed.
Scan any text for invisible characters, hidden payloads and AI typography, then clean it in one click. Your text stays on your own computer - never uploaded, never stored, never seen by anyone. We show exactly what we found and are honest about what no tool can remove.
Paste text to scan it
The whole analysis runs on your own device, instantly, as you type.
Hidden message decoded
These characters spell out readable text. This is how prompt injections and document trackers are smuggled through copy and paste.
Invisible characters
Your text with every finding marked
Hover any badge to see the Unicode name and codepoint.
Typography signals
Statistical watermark risk
We cannot detect a statistical watermark - nobody outside the vendor can, because it needs their secret key. What we can tell you is how much signal a text of this length could carry.
The only thing that meaningfully weakens a statistical watermark is rewriting the text substantially, in your own words. Use the rewrite prompt below and, importantly, do not use the same model that wrote the text - that would simply stamp it again.
What we can and cannot detect
Invisible characters
Zero-width characters, bidirectional controls, Unicode tags and variation selectors. Fully detectable and fully removable - we show you the exact count.
Detected and removableStatistical watermark
Anthropic, Google and others bias which words the model picks, using a secret key. The signal lives in the word choice itself, not in any character.
Cannot be measured without the vendor keyFile provenance (C2PA)
Images, video and audio carry signed provenance metadata. That is a different layer and needs a different tool.
Use our metadata removersYour text stays on your own computer
This tool never uploads anything. Here is what that actually means for you.
Nothing is sent to us
What you put in here does not travel over the internet. It stays on the device you are using right now.
Nothing is stored
There is no copy on a server and no database with your content in it, because it never reaches us in the first place.
Nobody can read it
Not our team, not other visitors, not any other company. There is nothing to read, because nothing arrives.
It is never used to train AI
Your content is not fed into any AI model and not passed on to an AI provider.
It disappears when you close the tab
Nothing is left behind. Reload the page and the tool simply starts empty again.
Do not take our word for it
Open this page, then switch off your wifi or unplug the network cable. The tool keeps working perfectly. That is only possible because all the work happens on your own computer, not on ours.
That makes this safe for text you would never send by email: client work, contracts, medical or legal documents, exam material, unpublished writing and internal company information.
Every finding named
Not a vague score. Each character is listed with its Unicode name, codepoint and a confidence level, so you can verify the result yourself.
Hidden messages decoded
Runs of tag characters and variation selectors are decoded back into readable text, revealing smuggled prompts or trackers.
Honest about the limits
We remove what is removable and say plainly that statistical watermarks are not. No tool can certify that a vendor check will fail.
Your text stays private
Nothing is uploaded, nothing is stored and nobody can read what you paste. Close the tab and it is gone for good.
How AI text watermarking actually works
There is no single AI watermark. Three completely different mechanisms get lumped together under that name, and they behave nothing alike. Knowing which one you are dealing with decides whether removal is trivial, impossible, or simply the wrong question.
Layer A: invisible characters
The first layer is edit-based: invisible characters inserted into the text after it is written. Zero-width spaces, bidirectional controls, variation selectors and Unicode tag characters all occupy no visual space, yet survive copy and paste perfectly. They are used to fingerprint documents, to trace leaks and, increasingly, to smuggle instructions into text that will later be pasted into an AI assistant. This layer is fully detectable and fully removable, and this tool reports the exact count so you can verify it.
Layer B: statistical watermarking
The second layer is what Anthropic announced for Claude models released from 2 August 2026, and what Google already ships as SynthID-Text. It works at generation time. Whenever the model picks the next word, a secret key marks part of the vocabulary as "green" and those words get a very small probability bonus. Any single sentence looks completely normal, but across hundreds of words the proportion of green choices drifts measurably away from chance. Someone holding the key can then run a statistical test and say the deviation is very unlikely to be coincidence.
Why layer B cannot be stripped
Because the signal is spread across the word choices themselves, there is no character to delete and no metadata to strip. Copy and paste changes nothing. Light editing barely moves it. Only rewriting a substantial share of the text - sentence by sentence, in different words - meaningfully weakens the signal, and even then no one can honestly certify that the vendor's check would fail. Two practical consequences follow. Rewriting costs you the original wording, so it is worth it for a hygiene requirement and not worth it as a shortcut. And if you rewrite with the same model that produced the text, you simply stamp it again - use a different model, or your own hands.
Layer C: file provenance
The third layer only applies to files. Images, video and audio can carry a signed C2PA manifest, plus XMP and EXIF fields naming the generator. That data is comparatively easy to remove, but it is metadata rather than a text watermark, so it needs a different tool. Our AI metadata removers handle images, video and audio, and our C2PA checker shows you what is in a file before you decide.
What about AI detectors?
Tools that claim to tell you whether a human or a machine wrote a text are guessing from surface style, and they are wrong often enough to have caused real damage to real people. We deliberately do not offer one. What we do offer is the part that is verifiable: the exact invisible characters in your text, decoded hidden payloads, and a typography checklist that we label as an indication rather than as evidence. That distinction is the whole point.