Your image-generator prompt travels inside the PNG

Guide · 18 August 2026

In one sentence. An image saved by a Stable Diffusion front-end such as Automatic1111 or ComfyUI carries the full text of the prompt that produced it — seed, model and often the negative prompt included — and that text travels with the file everywhere the file goes.

What the generator writes into the file

When one of these tools saves an image, it also saves its own working notes, in plain text, inside the file. The exact shape depends on the tool:

  • Automatic1111 writes a field named parameters: the complete positive prompt, the negative prompt, then the steps, sampler, CFG scale, seed and model hash on one line.
  • ComfyUI writes two fields, prompt and workflow, describing how the image was produced — prompts included.
  • InvokeAI writes sd-metadata; Fooocus uses keys of its own. Other keys seen in the wild include dream, aiprompt and generation_data.

The point of this data is reproducibility: anyone who has the file can regenerate the image, or a variation of it. That is also exactly what makes it a disclosure.

Where it lives

In a PNG, this text sits in dedicated text chunks — tEXt, iTXt or zTXt — stored alongside the compressed image data, not inside it. The pixels do not contain the prompt; the file does. When the same tools export a JPEG, the generation parameters travel in the metadata segments instead, including the JPEG comment segment.

Nothing announces this. Your image viewer shows the picture and stops there. But a tEXt chunk stores its value as plain readable text — the literal string sits in the file's bytes — so any metadata reader, and in many cases a plain text editor, will show the prompt to whoever looks.

Why the prompt is sensitive

A prompt is something you wrote for a machine, not for an audience. In practice it can contain the names of people, a client or project name, a described likeness, a visual idea you have not published yet, or phrasing you would not want attached to your name. It states, in your own words, exactly what you asked for — which is often more revealing than coordinates in a photo. The negative prompt can be just as telling: it lists everything you were trying to avoid.

And because the text rides inside the file, publishing the image publishes the prompt. Sending it to a colleague, attaching it to an email, uploading it anywhere that keeps the original file — the notes go along each time.

The trap in metadata cleaners

Most cleaning tools work from a list of things they recognise: they show you categories, you tick boxes, they remove what was ticked. Generation fields are a recent arrival, and a cleaner that files parameters or workflow under some generic technical bucket will never offer a box for them — so the file comes out labelled clean with the prompt intact.

QuietMeta had this exact defect in an early version: the engine could erase PNG text chunks but did not classify them as sensitive, so the option never appeared. The fix was to create a dedicated category and to lock it in place with an automated test, so the mistake cannot quietly return.

A category of its own

QuietMeta classifies these fields under AI generation parameters, a category marked sensitive — shown and offered for removal exactly like location, camera or author. It recognises the field names the common tools use: parameters, prompt, the negative prompt in its several spellings, workflow, sd-metadata, plus the individual knobs — seed, sampler, steps, CFG scale, model hash.

The match is deliberately narrow. An ordinary Comment field saying "holiday photo" is not a generation parameter and is not classified as one; a test checks that too, because alarming people for nothing is its own kind of defect.

Removal without re-encoding

Removing the category removes the chunks, not the picture. QuietMeta operates at the chunk level: the text chunks are dropped, the image data is copied through untouched, and the pixels of the produced file are bit-for-bit identical to the original. No decoding, no recompression, no quality loss. The output is still a well-formed PNG, from signature to final chunk.

Checked against the bytes, not the report

After cleaning, QuietMeta reads the produced file again and shows what is present now. The engine's own test suite goes one step further: it builds a PNG carrying a witness prompt, cleans it, and then searches the output bytes for that prompt — the assertion is on the file itself, never on what the report claims. A report can be wrong; the bytes cannot.

The reverse is tested too: when no removal is requested at all, nothing is removed, and the tool does not pretend otherwise.

What removal does not change

One thing must be said plainly: removing these chunks changes nothing about whether the image can be recognised as AI-generated. The pixels are identical before and after, so anything that can be inferred from the picture itself can still be inferred. This is a question of prompt confidentiality — keeping your working notes out of a published file — not a question of origin.

Content Credentials (C2PA) are a separate structure with different trade-offs, and QuietMeta keeps them by default; they have their own guide.

Doing it

Drop an image on the inspection page to see what it carries — if generation parameters are present, they appear as their own category, with an excerpt of what would be removed. Files sent to the web version are held in memory for one request and released. For whole folders, or for images you would rather not send anywhere at all, the desktop application does the same work offline.

Inspect an image Get the desktop app

Related