Private screenshot triage

Shared a screenshot with a password or private data?

Answer six questions to put the next actions in a safer order. This page never asks you to paste a secret, identify an account, or upload a photo.

Sharing sends only this page link. Questionnaire answers are never included.

No sensitive input

The check runs entirely in this browser tab.

You select only Yes, No, or Unsure. The page has no analytics, account, text field, photo picker, upload, or network request after it loads. Your answers are not saved. Do not paste an actual password, token, recovery code, or private message into any website to use this tool.

Six decisions

Describe the situation without sharing the sensitive content.

1. Does the image show anything that could grant account or system access?

Examples: a password, passcode, 2FA code, recovery code, seed phrase, API key, access token, private key, or login QR code.

2. Could anyone or any service beyond you have received the image?

Include messages, tickets, social posts, shared albums, work systems, synchronized devices, and cloud backups you do not fully control.

3. If a credential is shown, could it still work?

Choose Unsure when you have not confirmed its status with the service that issued it.

4. Is this the only copy of information you still need?

For example, the only recovery-code list, receipt, document, or account detail you can currently access.

5. Does the image show other personal, financial, identity, health, work, or location information?

Inspect the entire frame, including notifications, browser tabs, filenames, QR codes, addresses, faces, backgrounds, and photo metadata.

6. Does the original still exist in Photos, Recently Deleted, or another copy you control?

A redacted sharing copy does not automatically remove the original or invalidate a credential.

Need to find the screenshots before you can triage them?

SecretScan uses on-device OCR and deterministic pattern checks to narrow an iPhone screenshot library to likely passwords, recovery codes, API keys, payment details, IDs, and other sensitive text. Human review is still required.

Why revocation comes before deletion

Removing an image reduces one copy of the exposure. It does not stop a password, token, API key, recovery code, or private key from working. For an active or uncertain credential, use the issuing service to replace and revoke it, then clean up the screenshot and any destinations where it appeared.

Related guides

Primary references: GitHub's leaked-secret remediation guide, Apple's photo deletion guide, and Apple's app-access controls.

Last reviewed September 2, 2026.