ChatGPT/Claude/Gemini and AI text watermark remover
Rewrite text from ChatGPT, Claude, Gemini or another AI in the same language and see every changed word.
Try it free: 3 runs on the first 1000 characters of your text (cut at a sentence end). $10 a month gives 100,000 characters.
Best effort: the ChatGPT, Claude and Gemini watermark detectors are not public, so complete removal cannot be verified.
How well does it work?
In the standard-order reference SynthID test, the single-pass LLM workflow crossed below the detection threshold in 10 of 10 English reports. Replacing the wording throughout is the strongest available removal method: the benchmark used the published full-rewrite approach with protected spans. The ChatGPT, Claude and Gemini detectors are not public. The method and results are in the retest article; the code and every measured rewrite are open source.
What it removes, and what it does not
The target is the statistical watermark type: SynthID Text and its variants, which Google describes for Gemini and Anthropic for Claude, and textGrain, the scheme OpenAI announced for ChatGPT in October 2026. This mark resides in the specific words selected by the model during thousands of low-stakes decisions, so it can survive copying and minor edits. Rewriting the wording can weaken or remove that pattern. The tool rewrites the wording. The model is instructed to keep the meaning, the structure and the formatting. Full paid rewrites include one meaning check by a second model; free runs do not. Read the result against your source.
Hidden characters are different. Zero-width spaces and unusual whitespace can be removed by any Unicode cleaner, and doing so does not affect a statistical mark. Detectors like GPTZero or Turnitin work differently: they guess if text resembles model output and hold no vendor key. The tool is not designed to bypass them, and I have not measured whether it passes them.
How it works
- Recognized quotes, links, email addresses, currency amounts and percentages are masked before the model sees the text, so they return exactly as they were. Anything the masks do not recognize is rewritten with the rest.
- The service rewrites the wording broadly. It then measures how many five-word sequences of the result no longer appear in your source. The research counted model tokens and this page counts words, so the 80% target is a rewriting heuristic, not a detector threshold.
- The rewrite is one pass by one model that is told to keep every term, name and number as written; a second attempt is made only when the length, the layout or the amount of new wording fails a check. For full paid rewrites, a second model compares the result with your source and reports possible meaning changes. It does not edit the rewrite. If the check is unavailable, the result says so. Read the result before using it.
What I measured
The research tested five configured workflows on synthetic English reports under local SynthID keys. The original panel credited the single-pass LLM workflow with all 100 selected claims. Follow-up tests found 8/10 and 10/10 results below their fixed thresholds and changed the conclusion about translation. These measurements describe the published research workflow, not the live service, which can change independently.
Generator correction and follow-up tests
My original generator applied the watermark before temperature, top-k and top-p. The standard Transformers integration applies it after those steps, before sampling a token. A new control used that standard order. The historical results remain available under their original configuration.
| Method | Original A | Repeat B | New corpus C | Standard-order control |
|---|---|---|---|---|
| LLM paraphrase | 10/10 | 8/10 | 10/10 | 10/10 |
| DIPPER | 10/10 | 10/10 | 10/10 | 9/10 |
| Light synonyms | 2/10 | 0/10 | 1/10 | 1/10 |
| Translation via German | 0/10 | 0/10 | 0/10 | 0/10 |
| Translation via Chinese | 0/10 | 0/10 | 1/10 | 5/10 |
B uses the original sources and key with fresh API responses. C and the control use a new key with the same briefs and seed schedule, but different generated source texts. All marked sources passed the common threshold; all clean controls stayed below it. These batches are not forty independent documents.
The accepted original threshold stays 0.5095383054287164. C and its control use 0.509656862745098, fixed before transformations. The simulated null targets 1% false positives; ten clean controls do not establish a population false-positive rate. The tested rewrite is single-pass Qwen3.7 Plus with protected spans. The live tool runs the same single-pass Qwen3.7 Plus method with a stricter prompt and temperature 0.7 instead of 0; this configuration was not part of these tests. Vendor production keys were not tested.
Summary JSONPair metrics CSVEvery source and resultAuthor adjudications
Evidence reviewed 2026-09-08.
The original panel, generator correction, input-protection difference and full follow-up tables are in the retest article. Background on how marks work and who detects them is in the guide.
Languages
Any language and script. The result returns in your text's language; the pipeline is instructed never to translate, and I checked it end-to-end on Russian and English. The 10 of 10 figure above was measured on English samples, because the reference watermark corpus is English. For other languages, I have the working pipeline but no detector test yet.
Access and limits
- Free without an account: 3 runs, each rewriting the first 1000 characters of your text, cut at a sentence end. Each run takes up to 10,000 characters. The monthly plan gives your account 100,000 characters for $10 a month, shared by the Watermark Remover and the AI Humanizer across the website, API and MCP. Cancel any time; unused characters do not carry over. Detector checks are free and do not spend it, with a separate limit of 100 per person each UTC day.
- A text of about a thousand characters takes around ten seconds; the longest texts can take a minute or two. The run continues if you switch tabs.
- There is no public detector for the ChatGPT, Claude or Gemini production watermarks, so the tool cannot show a before-and-after reading. It shows the rewritten share instead.
- Prose only: paste complete paragraphs. A rewrite that does not keep your paragraphs, lines and list markers, or that leaves 70–140% of your text's length, is discarded and not charged; code and tables are not what the rewrite is built for.
Your text
The text you paste and the result are stored on my server so I can see what the tool is used for and improve it. They are linked to your anonymous browser id or, if you registered, to your account, kept for at most 12 months, and never sent to analytics, logs or any marketing platform. Ask me and I delete them within 7 days. Do not paste secrets or confidential personal data. Details are on the privacy page.
Questions
- What exactly was tested?
- The original experiment used ten English sources, a local SynthID key and five workflows. Its four-model panel credited the LLM workflow with 100% of the claims selected in advance, and the detector missed it in 10 of 10 texts. Fresh responses on the same sources reached 8/10. New-corpus runs reached 10/10 with both processor orders. Under the standard order, DIPPER reached 9/10, Chinese translation 5/10, German translation 0/10 and light edits 1/10. These are small configured-workflow tests, separate from the current web pipeline.
- Does Claude watermark its text, and which models?
- Yes. Anthropic's support article states that Claude models launched on or after August 2, 2026 mark their text from launch, lists Fable 5.1 and Mythos 5.1 as supported, and says marking for earlier models is still being added. Anthropic's announcement calls it a version of the SynthID Text approach: the mark sits in which words the model picks, not in any visible or hidden character. There is no public detector. The detection API is a private preview for eligible organizations such as regulators, media, fact-checkers, and researchers.
- Does ChatGPT watermark its text?
- For some users, soon. On October 5, 2026 OpenAI announced textGrain, a statistical watermark in the model's word choices. It says the mark will be added over the coming weeks for eligible ChatGPT and Codex users on all plans in the EU only. API customers worldwide can opt in for select models, and it stays off by default there. The detector is open only to approved researchers and organizations. This tool has not been tested against textGrain: my results are for SynthID Text with a research key. A text with no detected mark is not proof that a person wrote it.
- Can a unicode or zero-width cleaner remove it?
- No. Those cleaners strip invisible characters. A SynthID-style mark is a statistical tilt in the words the model chose, not a character, so a text can be free of every hidden character and still carry the mark. Only changing the words changes the mark, and the test shows how much change it takes.
- Does translating to another language and back remove it?
- Translation can weaken or remove the signal. In my original configuration, neither route produced a result below the threshold: ten German outputs stayed detectable, nine Chinese outputs stayed detectable and one Chinese attempt failed. Chinese translation later crossed below the threshold in 1/10 new-corpus cases under my old processor order and 5/10 with standard placement. The original LLM paraphrase removed 94.5% of the signal. Those results do not establish what a translation will do to a vendor's private watermark.
- Does this make text pass GPTZero or Turnitin?
- No, the system is not built for that purpose. These detection services guess whether text reads like model output. They do not search for embedded watermarks, nor do they hold any vendor's key. The tool targets statistical watermarks. Whether such a detector flags the rewrite is a separate question. I have not measured it.
- How do I know the watermark is gone?
- This tool cannot check a text against the ChatGPT, Claude or Gemini detectors: none of them is public. It shows changes to your text and a wording-change heuristic. The tool's lowercased word-and-punctuation five-grams differ from the research detector's model-token five-grams; a wording target such as 80% is not a validated watermark threshold. The single-pass research workflow reached 8/10 or 10/10 below-threshold results across the tested batches. Those are not measurements of this deployment or guarantees for your text.
- Will the facts survive?
- Full paid rewrites include one meaning check by a second model, which reports possible changes without editing the rewrite. Free runs skip that check. If the check is unavailable, the rewrite stays available with an incomplete-check notice. Every result shows a diff for your own comparison. Selected spans such as money amounts, numeric percentages and quotes are protected by placeholders. This helps preserve their text but does not guarantee that every relation or qualification survives. The original research panel credited all 100 selected claims to its LLM workflow; the standard-order follow-up review retained 97, with two changed qualifications and one uncertain case after author review. DIPPER had no matching placeholder wrapper, so that comparison describes the tested workflows. Inspect your result before using it.
- Is it free, and is my text stored?
- Without an account you get 3 free runs per browser; each rewrites the first 1,000 characters of your text. $10 a month gives 100,000 characters, counted only for successfully processed text and shared across the website, API and MCP. Cancel any time; unused characters do not carry over to the next month. Detector checks are free and limited to 100 per person each UTC day. Your text and the result are stored for at most 12 months, linked to the browser or account, to help improve the tool. They are never sent to analytics, logs or marketing platforms. Ask me to delete them within 7 days. Do not paste secrets.
- Which languages work?
- The tool accepts text in any language and instructs the model to retain the source language and script. The pipeline has been exercised on English and Russian. The reference-key detector results were measured on synthetic English reports; they do not establish the same removal rate for other languages or writing tasks.
Answers checked 2026-09-08 against the evidence files and the vendors' own pages listed in the site repository.
Last updated .
Writing with an AI client? Connect the MCP server or API.