Privacy Guide

Don't Send a Contract With Hidden Metadata

📅 September 2026 ⏱ 6 min read ✍ Percy Ng

Every Word document you send carries a hidden history — who wrote it, who edited it, and what was said in comments and tracked changes along the way. For most files, that's harmless. For a contract sent to opposing counsel, a client, or a regulator, it can reveal your redlines, your internal notes, or even a rate you quoted a different client.

This guide covers what's actually hiding in a contract file, how to check it, and how to remove it before you hit send.

Free metadata check

Check what your contract actually reveals

Drop a .docx file below. It never leaves this browser tab — nothing is uploaded, checked, or sent anywhere.

📄
Drop a .docx file here, or click to browse
Processed entirely on your device
Remove it all — Doc Metadata Cleaner Pro X

Open your browser's Network tab while you use this if you want to confirm nothing was sent anywhere — there's nothing to see, because nothing goes out.

What a Contract File Actually Reveals

A .docx file is more than the words on the page. Behind the scenes it stores:

  • Author and "last modified by" — the names of everyone who touched the file, even if they're not on the letterhead
  • Company name — often the firm or client the template originally came from
  • Tracked changes and comments — every redline and internal note, even ones you thought you'd deleted or resolved
  • Creation and revision history — timestamps that can reveal how long a document sat untouched, or how quickly it was turned around
  • Revision number — how many times the file has been saved, which can hint at how heavily it was negotiated

None of this shows up when you read the document normally. It's only visible if someone knows to look — and increasingly, they do.

Why This Matters More for Contracts Than Other Documents

A leaked comment in a birthday invitation is embarrassing. A leaked comment in a contract is a liability:

  • Waived privilege — if a comment or tracked change reveals attorney-client discussion that made it into a file sent externally, that can weaken a claim of privilege
  • Revealed negotiating position — a redline showing your first, more aggressive draft — still present under tracked changes, just not currently displayed — tells the other side exactly how far you were willing to move
  • Cross-client exposure — a contract built from a template can carry a previous client's name in the metadata, in the file's revision history, or in a comment nobody deleted
  • Regulatory exposure — for firms bound by GDPR or client confidentiality obligations, metadata is still personal or client data — it doesn't stop counting because it's invisible
Real-world pattern: A contract built from a previous engagement's template can carry that client's name in the metadata long after the visible text has been updated — because editing what's on the page doesn't touch what's stored underneath it.

How to Remove It Manually in Word

  1. Save a copy first — Document Inspector's changes can't always be undone. Work on a duplicate, never the original.
  2. Go to File → Info → Check for Issues → Inspect Document.
  3. Make sure Comments, Revisions, and Versions and Document Properties and Personal Information are both checked.
  4. Click Inspect, then Remove All next to anything you don't want to send.
  5. Save the cleaned copy — that's the one that goes out.

This works, but it's a five-step process you have to remember to run on every single contract, every single time. Miss it once and the file goes out with everything intact.

The Faster Way: Remove It Automatically, Every Time

Doc Metadata Cleaner Pro X strips author names, company details, tracked changes, comments, and revision history from Word, Excel, PowerPoint, and PDF files in one click — and can export a compliance certificate alongside the cleaned file, useful for firms that need to show a document was checked before it went out. It runs entirely on your PC; nothing about the file or its contents is ever sent anywhere.

⊞ Download Free — Microsoft Store

Frequently Asked Questions

Does Track Changes "Accept All" remove this data?

No. Accepting all changes updates what's displayed, but the underlying revision history, comments, and document properties can still be present in the file itself. Document Inspector (or a dedicated tool) checks the file, not just the visible text.

Can the other side really see this if I don't send them the "reviewing pane" view?

Yes. Anyone with Word, or even a free online metadata viewer, can open a document's properties and revision history independent of how it displays on screen.

Does this apply to PDFs too?

Yes, though differently — PDFs converted from Word can retain author and application metadata, and some PDF editors preserve comment history. It's worth checking PDFs before sending them externally as well.

Is this a GDPR issue?

It can be. Metadata that includes a name, email address, or other personal data is personal data under GDPR regardless of whether it's visible on the page — the same data-minimisation principle that applies to the document's content applies to what's attached to it.


About Beginza — Beginza builds privacy tools for Windows that run entirely on your device. No cloud, no accounts, no subscriptions. Browse all apps at beginza.co.uk.

PN

Percy Ng

Co-founder of Beginza. Builds privacy tools for Windows that run 100% locally — no cloud, no accounts. All Beginza apps are available on the Microsoft Store.