Privacy
C2PA metadata, and what it discloses
Some cameras and apps now sign photos with provenance data that can include device and edit history, which is a new field to strip.
A newer kind of metadata is starting to show up in photo files: a cryptographically signed record of where the image came from, called a content credential. It is built to answer a different question than EXIF ever tried to - not "what were the camera settings" but "can this file's history be trusted" - and that makes it worth understanding on its own terms rather than folding it into a general metadata list.
What C2PA actually is
The Coalition for Content Provenance and Authenticity, or C2PA, is an industry specification backed by companies including Adobe, Microsoft, Sony, Canon and Nikon, for attaching a signed manifest to a media file. The manifest can record the capturing device, the software that touched the file afterward, and a chain of edits - each addition cryptographically signed so a viewer can tell whether the record has been tampered with. The intended use case is largely the opposite of privacy: proving a news photo or an AI-generated image is what it claims to be, in an environment where fabricated images are cheap to produce and hard to tell apart from real ones.
What it can disclose
Where it is present and populated, a content credential can include the capturing device model, a timestamp, the editing applications used and in what order, and sometimes an assertion about whether generative AI was involved in producing the image. That is a meaningful amount of provenance detail sitting in a single signed block, and unlike EXIF, it is specifically designed to be hard to quietly strip - tampering with a signed manifest is supposed to be detectable, which is the entire point of the format existing. In practice, most current implementations still allow the credential to be removed outright rather than forcing it to persist; detectable tampering and undeletable metadata are different design goals, and C2PA so far pursues the first. A manifest can also chain: each new tool that touches the file can append its own signed entry rather than replacing the previous one, so a photo edited by two different applications can carry two separate assertions, each independently verifiable, rather than one overwritten record. That chaining is the part of the design doing the actual work - a single unsigned "edited with X" tag is trivial to fake, while a chain of signed entries is comparatively expensive to forge convincingly.
What to actually expect in 2026
Adoption is real and growing among newer camera bodies, some phone camera apps, and generative AI tools that add credentials to flag synthetic content, but it is far from universal. Most photos taken on an ordinary phone camera still carry no C2PA manifest at all. Treat its presence as camera- and app-specific rather than assumed, and check rather than guess: reading a photo's metadata before you upload it is the same inspection step that surfaces a content credential when one exists, alongside EXIF and any PNG text chunks. General stripping tools that clear other metadata typically clear this too where the format allows it, which is one more reason a general strip before uploading anywhere remains the reliable habit rather than checking for each new field individually.
Where this intersects with scoring
None of this changes how a rating model reads an image - a manifest sits alongside the pixels, not inside the vector a scoring model produces, so what the model actually sees is unaffected by whether a credential is attached. It is a disclosure question, not an accuracy one, and it belongs in the same category as any other field a file can carry into an upload box. Rate Cock processes whatever image arrives regardless of its provenance metadata, which is the normal behaviour for a scoring pipeline rather than a gap. Tool comparisons that look at data handling as a real differentiator - Penis Rater covers this ground - are the more useful place to check a specific service's stance, since the specification itself only describes what a credential can contain, not what any given tool does with one. A measurement taken by hand carries no file at all, provenance or otherwise - Measure My Cock's method sidesteps the entire category. A file sent to a human judge carries the same manifest along with it, camera or app permitting, and what belongs in that kind of submission is worth a glance for the same reason. The direction worth remembering is that provenance metadata is a new field added for a purpose unrelated to you, and it is worth checking for the same reason any new field is worth checking for.