Detect Llama watermarks
The Llama watermark detector scans pasted text for the invisible Unicode that comes with copied Llama and Meta AI output: zero-width spaces, non-breaking spaces, and the directional marks messaging apps add around text.
The Llama watermark remover strips the invisible characters that copied Llama and Meta AI text carries, and flags the phrasing habits that make a draft read as generated. It also answers the question most pages dodge: whether Meta watermarks Llama text at all.
Cleaned drafts
end up here
Platform names and marks indicate where drafts cleaned with GPTCleanup are commonly published. All marks are the trademarks of their respective owners. No partnership, sponsorship, or endorsement is implied.
The Llama watermark detector scans pasted text for the invisible Unicode that comes with copied Llama and Meta AI output: zero-width spaces, non-breaking spaces, and the directional marks messaging apps add around text.
A Llama watermark remover for hidden characters. Word joiners, byte-order marks, soft hyphens, left-to-right marks, variation selectors, and tag characters come out; the words you can see stay as written.
Every hidden character is reported by Unicode code point with a count, so you can trace it to a chat app, a web interface, or an editor, rather than taking a tool's word that it was a watermark.
Llama instruct models introduce their own answers: "Here is a revised version of your text:" and a cheerful sign-off. The phrasing pass flags those, the long dashes, and the stock transitions that no character cleanup touches.
Llama is the open-weight case, and that changes what a watermark could even mean.
Meta has published no watermarking scheme for text generated by Llama. Its research groups have studied text watermarks, and Meta does mark AI images, but nothing it has shipped puts a mark in Llama’s written output. The contrast is Gemini and Claude, which both embed a statistical watermark in the word choices as the text is generated.
The open weights make the question different in kind. Anyone can download Llama and run it, so a watermark would have to be added by whoever serves the model: Meta in its own apps, a cloud provider, a startup, or you on your own machine. None of the major providers serving Llama has said it adds one. Run the model locally in a terminal and the text usually comes out with no hidden characters at all.
What people find in copied Llama text comes from the route it took. Replies copied out of messaging apps can carry left-to-right marks and non-breaking spaces. Web chat interfaces add zero-width characters when they render Markdown. Editors add more on the way in. All of it is worth removing, and none of it is a watermark.
One thing this page is not: an image tool. If the search that brought you here was about a picture made with Meta AI, the Meta AI image watermark page covers the visible “Imagined with AI” label and the signals Meta embeds.
U+200EHere is a revised version of your paragraph: The launch moved to MarchU+00A0— giving the team time to test properly. I hope this helps!
Here is a revised version of your paragraph: The launch moved to March — giving the team time to test properly. I hope this helps!
Characters gone, and the reply still introduces itself, leans on a long dash, and signs off like a help desk.Because the same weights sit behind so many products, there is no single Llama voice. What the instruct models do share is a frame around the answer: a first line announcing what follows, and a last line hoping it helps. Paste that frame into a document and it gives the draft away before anyone reads the middle.
Inside the frame, Llama has the habits every instruct model has: even sentence lengths, stock transitions, and a tidy closing line that restates the point. Those are what a detector scores. The phrasing pass flags each one and quotes it back; detection is free, and humanizing the flagged text is the paid part.
421 characters in total: 37 named individually below, plus 384 more across the variation selector and tag-character ranges. The set is the same for every model, because these characters come from apps, interfaces and editors rather than from Llama.
No width at all. They survive copy and paste, they are invisible in every editor, and they are what people usually mean by a hidden watermark character.
Removed completelyU+200BZero-width spaceU+200CZero-width non-joinerU+200DZero-width joinerU+2060Word joinerU+FEFFByte-order markU+00ADSoft hyphenU+180EMongolian vowel separatorSpaces that are not the ordinary space character. Identical on screen, but they break find-and-replace, wrap oddly, and split words in search indexes.
Replaced with a normal spaceU+00A0Non-breaking spaceU+202FNarrow no-break spaceU+205FMedium mathematical spaceU+3000Ideographic spaceU+2000En quadU+2001Em quadU+2002En spaceU+2003Em spaceU+2004Three-per-em spaceU+2005Four-per-em spaceU+2006Six-per-em spaceU+2007Figure spaceU+2008Punctuation spaceU+2009Thin spaceU+200AHair spaceU+2028Line separatorU+2029Paragraph separatorCharacters that look exactly like ordinary punctuation and are not. GPT models write the non-breaking hyphen in compound words, and it breaks search and find-and-replace like any other hidden character.
Replaced with a normal hyphenU+2011Non-breaking hyphenFormatting controls that set text direction. Harmless to read, obvious to anything inspecting the underlying characters, and never intentional in ordinary prose.
Removed completelyU+200ELeft-to-right markU+200FRight-to-left markU+061CArabic letter markU+2066Left-to-right isolateU+2067Right-to-left isolateU+2068First strong isolateU+2069Pop directional isolateU+202ALeft-to-right embeddingU+202BRight-to-left embeddingU+202CPop directional formattingU+202DLeft-to-right overrideU+202ERight-to-left overrideFamilies used to smuggle invisible payloads into text. A tag-character sequence can encode an entire hidden message that renders as nothing, so these are removed wholesale rather than listed one by one.
Removed completelyU+FE00 to U+FE0FVariation selectors 16U+E0100 to U+E01EFVariation selectors supplement 240U+E0000 to U+E007FTag characters 128Copy the answer from Meta AI, from a chat app, or from any interface running Llama 3 or Llama 4, and paste it in unedited. Reformatting first can strip the characters the detector is looking for.
Two passes run together. One reports every hidden character by Unicode code point and count. The other reads the writing and flags preambles, sign-offs, stock transitions, and punctuation habits.
Each finding shows what it is and why it was flagged. Nothing is rewritten without your say.
The Llama watermark remover applies only what you accepted. Meaning, names, and structure stay where they were.
No. Meta has published no watermarking scheme for text generated by Llama, and the weights are open, so a watermark could only exist if whoever runs the model added one. No major provider serving Llama has said it does. That puts Llama alongside ChatGPT and Grok, and apart from Gemini and Claude, which both watermark text in the word choices.
Meta labels AI images, with a visible "Imagined with AI" mark and invisible signals its platforms read, but it has not published a watermark for the written replies Meta AI gives in WhatsApp, Instagram, Messenger or Facebook. Text copied out of messaging apps can pick up invisible characters, such as left-to-right marks and non-breaking spaces, and those are what this tool finds.
The invisible Unicode added on the way to you: zero-width spaces, non-breaking spaces, word joiners, byte-order marks, and directional marks. They come from the interface serving the model, the app you copied from, and the editor you pasted into. They are real and worth removing, and none of them is a watermark.
No, this page is for text. Search results for a Llama watermark remover are full of image tools, partly because of LaMa, an unrelated image inpainting model with a similar name. For images made with Meta AI, the Meta AI watermark remover page covers the visible label and the invisible signals.
It scans your draft twice. The character pass checks every character against 421 supported characters and reports each match by Unicode code point with a count. The phrasing pass reads the writing and flags announcing preambles, sign-offs, stock transitions, and punctuation habits, quoting each with the pattern it matched.
Because the same weights sit behind very different products. System prompts, sampling settings, and formatting all change with whoever serves the model, so there is no single Llama voice and no single set of Llama hidden characters. A misconfigured server can even leak template tokens such as <|eot_id|> into the reply. Those are visible text, so check for them yourself before you publish.
Detectors never looked at hidden characters, and there is no provider watermark here to find. They score how predictable the word choices and sentence rhythm are, and Llama instruct models have the habits every instruct model has: an announcing first line, even sentence lengths, stock transitions, and a tidy closing line. Those are visible words.
On its own, no. Detectors score phrasing, not invisible characters, so a draft stripped of every zero-width space can still read as machine-written. That is why the phrasing pass exists. No tool can promise a result against a specific detector.
Stripping invisible characters from your own text is ordinary formatting and it is legal. The Llama licence and acceptable use policy, platform terms, disclosure requirements, and academic or workplace policies on AI assistance all still apply to how you use the text.
Yes. Detection is free and needs nothing but your text. Phrase-level rewriting is the paid part of GPTCleanup, and it is a separate job from stripping characters.
Llama’s nearest relative on this question is DeepSeek, the other open-weight family, which carries no text watermark either but does carry AI labels under Chinese law; the DeepSeek watermark cleaner sets out what those are. At the other end, Anthropic began watermarking Claude text in August 2026, and the Claude watermark remover covers what GPTCleanup does with Claude drafts.
Most people pasting here want the same result whatever the model: text with nothing hidden in it. The ChatGPT watermark remover is the fullest guide to that, and the homepage text cleaner runs the same checks on anything you paste.