Problem / motivation
Users need one authoritative privacy-cleaning action that preserves image payloads and color profiles.
Scope
Use the exact released default Privacy Clean policy, create _clean output names, acquire a save handle during the user gesture when supported, clean without Canvas, and save only after successful verification.
Non-goals
No granular field controls, re-encoding, resizing, format conversion, quality changes, selective EXIF rewriting, or ZIP.
Acceptance criteria
- Cleaning uses the vendor-exported authoritative policy constant.
- EXIF/XMP/IPTC/comments/ordinary PNG text/timestamps are removed where supported and ICC is preserved.
- Source bytes remain unchanged and output format/MIME are derived from detected format.
- Save cancellation/failure keeps inspected state usable.
- No output bytes are written when cleaning or verification fails.
Problem / motivation
Users need one authoritative privacy-cleaning action that preserves image payloads and color profiles.
Scope
Use the exact released default Privacy Clean policy, create _clean output names, acquire a save handle during the user gesture when supported, clean without Canvas, and save only after successful verification.
Non-goals
No granular field controls, re-encoding, resizing, format conversion, quality changes, selective EXIF rewriting, or ZIP.
Acceptance criteria