no-watermark
Finds and strips invisible characters, hidden payloads and fingerprints from text copied out of AI chats.
The problem
Text copied out of ChatGPT, Claude, Gemini or any other assistant can carry characters you never see. Some are harmless typographic habits. Some aren’t: the Unicode Tags block is a complete shadow copy of ASCII that renders as nothing in any browser, editor or chat, yet a language model reads it perfectly. It’s the carrier behind ASCII smuggling and invisible prompt injection.
What it does
no-watermark finds those characters, shows you what was hidden and gives you back clean text. It catches zero-width characters, variation selectors, bidirectional controls, Cyrillic letters posing as Latin ones and unusual spaces.
There’s a desktop app — paste on the left, read clean text on the right, and optionally have everything you copy cleaned automatically — and a command-line tool that also works as a CI check.
Honesty first
The README has a table of what can and cannot be removed. Google’s SynthID-Text, for example, is a watermark hidden in word choice: it leaves no special character, and no character-level tool can remove it. A tool that claims otherwise is wrong.
It’s also careful not to damage real text. Emoji sequences stay whole, Arabic and Persian keep the characters their spelling needs, genuine Cyrillic is left alone. Each of those guarantees has a test.
Technical choices
Written in Rust and split into crates: the detection engine, with no I/O; the English and Italian strings; the command-line tool; the egui desktop app. It has more than 40 tests. CI publishes an MSI installer for Windows and .deb, .rpm and AppImage packages for Linux on every release.
Status
Finished, with downloadable releases on GitHub. MIT licence.