Metadata Privacy And Billing
See what Metadata withholds, how tenant-scoped exact-byte memory works, when evidence remains stored, and how SCU charges are counted.
What the response exposes
The public file report uses bounded fields. It withholds raw EXIF and XMP text, GPS coordinates, device serials, comments, prompts, filenames, and private hashes. JPEG v2 can expose selected parsed capture and GPS fix times; privacy.capture_timestamps_exposed reports when either is present. The Content Credentials receipt omits the raw manifest, signer name, certificate, path, prompt, and timestamp.
For a PDF, document-level claims and native-image claims stay separate. A child's source kind tells you whether the scan inspected extracted JPEG bytes or a PDF pixel stream. A PDF pixel stream cannot supply the source photo's EXIF or Content Credentials.
Tenant memory and retention
When enabled for your organization, the Dashboard can look up previous Metadata scans by the SHA-256 hash of the exact original bytes. Results stay within that organization. A matching hash means identical submitted bytes; a crop, screenshot, or re-export does not match. This is exact-byte lookup, not image similarity or a public-web search.
Stored redacted Metadata receipts and the file hash remain until an explicit deletion workflow runs. There is no automatic expiry for that retry record. Per-scan evidence deletion is a separate, permissioned Dashboard operation and may be unavailable during rollout. Billing and audit records follow separate retention rules. See file evidence lookup and deletion for the Dashboard routes and their availability.
Billing
Metadata runs synchronously in secure mode. An analyzed image or PDF parent costs 2 SCU. Each distinct analyzed native PDF image costs another 2 SCU. PDF pages add no charge, and an unsupported or unanalyzed child does not count as analyzed.
| Scan | Charge |
|---|---|
| One analyzed image | 2 SCU |
| PDF with an analyzed parent and two distinct analyzed native images | 6 SCU |
| Unsupported format or failed admission | 0 SCU |
The receipt gives analyzed_parent, analyzed_native_image_count, usage_units, and scu_charged. If the API cannot confirm a billing commit, it returns metadata_billing_outcome_unknown. Retry identical content and options with the same request ID to recover the receipt; do not assume the charge was zero.
Compare scan prices
The SCU guide shows how Metadata billing differs from routing image and PDF scans.
