PassRealPricingApp

Gemini AI watermark: what a remover can and cannot reach

Images generated by Gemini carry two separate marks. A C2PA manifest sits in the file container and states, with a signature, that the image was machine-made - stripping it removes it completely. SynthID is embedded in the pixel values themselves and was built to survive re-encoding, cropping and resizing. Any tool claiming to remove both is describing only the first.

Before and after naturalization of a generated image, full frame plus the busiest region enlarged at two magnifications
Source: ai-sd15-04.png, 512×512. After: JPEG, Samsung SM-S928B EXIF, Samsung (mesurée) quantization table. SSIM 0.8524, PSNR 28.4 dB. Full image on both sides, then the same detail at 100 % zoom and 200 % zoom.

Two marks, one word

« Watermark » covers two different things in a Gemini image, and confusing them leads to confident advice that is wrong.

The first is a C2PA manifest: a signed statement in the file container, alongside EXIF, saying what produced the image. It is verifiable and tamper-evident. It is also metadata, which means it can be removed outright - and removal is clean rather than partial. A verifier then reports no provenance data, exactly as it does for the overwhelming majority of images on the web.

The second is SynthID: a pattern woven into the pixel values, imperceptible to a viewer and read by a model paired with the encoder. It was designed specifically to survive what destroys metadata - screenshots, re-encoding, cropping, colour grading, resizing.

Why the distinction decides everything

If what worries you is a manifest that says « generated by » in plain text - because a marketplace reads metadata, or a distributor runs a script - then stripping resolves it entirely. That is a mechanical operation with a deterministic outcome.

If what worries you is a Google surface checking its own watermark with its own key, no third-party tool can promise a result. The detector is not public, and the watermark's strength is not published. There is no measurement that would support a claim either way, so this page makes none.

Checking what your file actually carries

Before deciding anything, look at the file. The answer differs by tool, by export path and by month.

That last point causes most of the confusion online: someone concludes provenance data is trivially removed, or impossible to remove, from one path through one client.

What processing changes

Metadata first: the C2PA manifest, XMP blocks and any text chunks are removed. So are the absences that follow generated images around - no camera make, no exposure triple, no lens description, no capture timestamp.

Then the optical layer. Grain at intensity 0.018 gives the image a noise floor it never had. Lateral chromatic aberration reaches 1.25 px of channel separation at the corners and none at the centre, which is how refraction actually varies across a lens. A constant shift across the frame is easier to implement and is not how any lens behaves.

The frequency stage applies a low-pass filter at 0.88 of Nyquist, attenuating the periodic residue left by the decoder's upsampling steps.

Finally the file is written as a JPEG with EXIF describing a specific body, and the quantization table of that make rather than a generic one. A file claiming a camera while carrying a software library's table contradicts itself in a way a forensic tool reads immediately.

What it costs, measured

The sheet above reports SSIM and PSNR for this exact image, computed against its source. Figures differ from one image to another, which is why they are computed per image rather than published as a single number.

The boundary worth stating: this changes what a file declares and what its pixel statistics look like. It does not change whether the subject reads as machine-made to someone looking at it.

Turning provenance off at the source

For work you have not generated yet, the cheapest fix is upstream. Some surfaces let you export without a manifest, and any path that re-encodes through a tool unaware of C2PA drops it as a side effect. That handles new files and nothing else: anything already produced still carries whatever it carried, so a pass over the archive is still needed once.

Keep a separate record of your prompts and settings if you strip metadata systematically. Losing the seed for an image you want to iterate on is a worse problem than the manifest was, and it is the mistake people regret most.

What a reviewer sees afterwards

A file that has been through this reads as an ordinary photograph to metadata inspection: a camera make and model, an exposure triple in a plausible range, a lens that was sold for that mount, a capture timestamp, and a quantization table belonging to the make it claims. Nothing declares an origin, because nothing has to - most images in circulation declare nothing.

What it does not do is make an implausible picture plausible. Six fingers, reflections that disagree, lettering that falls apart under inspection: those survive every pixel operation, and a human reviewer notices them long before any tool does.

What is checkedValue
Accepted formatsPNG, JPEG, WebP
Maximum size20 MB
Maximum dimension8192 px on the longest side
Sensor grain intensity0.018
Lateral chromatic aberration1.25 px at the corners, none at the centre
Frequency cutoff0.88 of Nyquist

Questions

Does Gemini put a visible watermark on images?

Not on the pixels in most flows. What it writes is a C2PA manifest in the metadata, plus SynthID, which is imperceptible by design. A visible corner mark appears in some surfaces and products, but the durable marks are the two invisible ones.

Which of the two can actually be removed?

The C2PA manifest, completely and deterministically - it is metadata, and deleting it leaves a file with no provenance data, like most images online. SynthID lives in the pixels and is detected by a paired model Google does not distribute.

Does screenshotting remove the Gemini watermark?

It removes the C2PA manifest, because a screenshot is a new file made by a different program. It does not remove SynthID, which travels in the pixels the screenshot copies. This is the single most common misunderstanding about the two layers.

Is Nano Banana the same thing?

Nano Banana is the image model inside the Gemini stack, so the marks are the same: C2PA in the file, SynthID in the pixels. Anything true of one is true of the other.

What does PassReal actually do to a Gemini image?

It strips the C2PA manifest and the rest of the generation metadata, applies a sensor model, smooths frequency-domain residue, and writes camera EXIF with a matching quantization table. It makes no claim about SynthID.

Limits

Naturalization operates on the pixels and on the file, not on the content of the image. A subject that is implausible - six fingers, inconsistent reflections, text that does not read - stays implausible after processing, and a human reviewer will notice it. PassReal changes what a statistical classifier measures, not what a person sees.

Results vary by generator, by subject and by detector, and detectors are retrained. No pass rate is published on this page because none has been measured in a way that would still hold next month.

Process three images free

Three images, no card, no expiry.