C CreatorPrivacyKit

Provenance is evidence, not a vibe check

“Was this made by ChatGPT?” is a forensics question. The useful answer starts with what the file still carries, what an official verifier returns, and what a screenshot already destroyed — not with counting fingers.

Reviewed 17 September 2026

Four different things people collapse

Trusted positive vs missing

A trusted positive from official OpenAI C2PA/SynthID, after you click verify, is evidence about that API’s view of that file. Local inspection showing a C2PA/JUMBF structure is a clue you can screenshot for yourself.

A miss means this scan did not find the field. The image may still be synthetic, the credential may have been stripped, the watermark may be unsupported, or the file may be a screenshot.

Screenshots and recompression

A screenshot is a new raster. C2PA almost always dies. EXIF is usually gone or replaced by the phone. Pixel watermarks may degrade. Treat screenshot provenance as weak unless an official verifier still reports a supported watermark.

Walkthrough: what survives a screenshot.

Workflow in this kit