Manual camera-roll audit
1. Start with screenshots
Open Photos and begin with the Screenshots media type. A bounded collection is easier to finish than an unstructured review of the entire library. Work from newest to oldest, or audit one month at a time.
2. Check the categories with real consequences
- Passwords and sign-in screens: temporary credentials, copied passwords, PINs, and login details.
- Recovery material: 2FA backup codes, account recovery codes, seed phrases, and setup QR codes.
- Developer secrets: API keys, access tokens, authorization headers, terminal output, and cloud dashboards.
- Financial information: payment cards, bank details, statements, receipts, and account identifiers.
- Identity and health documents: IDs, passports, and licenses, plus insurance details, prescriptions, and medical records.
- Private conversations and notes: addresses, contact details, personal messages, and confidential work material.
3. Secure the information before deleting its copy
Do not delete the only copy of something you still need. Move credentials into an appropriate password manager or approved secure storage, and confirm that recovery material works before removing the photo. The right storage choice depends on the account and your threat model.
4. Treat deletion and revocation as different jobs
Deleting a screenshot reduces one copy of the exposure. It does not invalidate a password, token, API key, or recovery code that may already have been seen or synchronized elsewhere. If exposure is plausible, rotate or revoke the credential through its issuing service.
5. Delete deliberately
After confirming a safe replacement, delete the original screenshot. Apple keeps deleted photos in Recently Deleted for 30 days unless you remove them sooner. Remember that iCloud Photos synchronizes deletion across devices signed into the same Apple Account.
6. Review which apps can access Photos
Open Settings, then Privacy & Security, then Photos to review app access. Remove access an app no longer needs, or choose limited access when full-library access is unnecessary.
7. Make the audit repeatable
A small recurring review is more realistic than a perfect one-time cleanup. Pair it with a habit: avoid photographing secrets when possible, remove temporary screenshots after the task is complete, and recheck the Screenshots collection every few months.
Where SecretScan helps
SecretScan automates a private first pass using on-device OCR and deterministic pattern detection. It can narrow a large screenshot collection to likely findings, show why an item was flagged, save a redacted copy, or request deletion of the original. It can miss things and can produce false positives, so human review still matters.
Related focused guides
- Triage a screenshot that may already have been shared
- Search screenshots by visible text using built-in iPhone tools
- Redact private information in an iPhone screenshot
- Remove location metadata from iPhone photos before sharing
- Find API keys and tokens in developer screenshots
- Find recovery codes and seed phrases in photos
Primary references: Apple on searching photos and videos, deleting or hiding photos and videos, and controlling app access; GitHub on remediating a leaked secret.
Last reviewed September 2, 2026.