What Your Photos Reveal: EXIF Data, GPS, and Privacy
Every photo from a phone or camera carries an invisible data file inside it. Sometimes that data includes the exact spot on Earth where you were standing. Here's what's in there, when it matters, and how to remove it.
What EXIF metadata actually stores
EXIF (Exchangeable Image File Format) is a block of information your camera writes into every photo automatically. You never see it in the picture itself, but anyone with the file can read it in seconds — Windows shows much of it under Properties → Details, and macOS under Get Info or Preview's inspector.
A typical smartphone photo carries:
- Date and time the photo was taken, down to the second.
- GPS coordinates — latitude and longitude, often accurate to within a few yards — if location tagging was on (it is on by default when you first allow your camera app to use location).
- Device details: phone or camera make and model, sometimes the lens.
- Camera settings: exposure, ISO, focal length, whether flash fired.
- Software traces: which app or editor last saved the file.
- Occasionally an owner or artist name, if one was ever configured on the camera.
Individually these seem harmless. Combined, a stranger can learn what device you own, when you were somewhere, and — the serious one — precisely where "somewhere" is.
A realistic way this goes wrong
Say you're selling a mountain bike on an online marketplace. You wheel it into the backyard, take four photos on your phone, and post the listing with your first name and general area. Reasonable so far.
But if that marketplace serves your images with metadata intact — or a buyer asks you to email or text the "original full-quality photos," which is a completely normal request — those files can contain GPS coordinates pointing at your backyard. Paste them into any map app and it resolves to your home address. The listing already announces you own a valuable bike, and roughly when you're home to answer messages. Police departments have warned about exactly this pattern for years.
The same logic applies to photos of kids sent to a group chat, room-for-rent photos, dating profile pictures shared directly, and photos attached to reviews or forum posts. The risk isn't the photo — it's the coordinates riding along inside it.
Which platforms remove metadata — and which often don't
Major social networks generally strip EXIF data when they process your upload (they typically re-encode every image anyway). The gap is everything that isn't a social network: email, messaging apps in "file" or "document" mode, and cloud drive links usually pass the original file through untouched — that's their job.
| How the photo is shared | Metadata typically… |
|---|---|
| Facebook, Instagram, X, LinkedIn (normal posts) | Generally stripped during upload processing |
| Messaging apps sending a compressed photo (e.g., WhatsApp default) | Usually stripped or reduced along with the re-compression |
| Messaging apps sending as a "document" / "original file" | Often preserved — the file is sent as-is |
| Email attachments | Preserved — email doesn't modify attachments |
| Cloud drive links (Google Drive, Dropbox, iCloud links) | Preserved — recipients download the original |
| Marketplace and forum uploads | Varies by site — safest to assume it may survive |
Two cautions about this table. First, platform behavior changes without notice and isn't something they all document, so treat "generally stripped" as a tendency, not a guarantee. Second, even when a platform strips metadata for viewers, you still handed the original — coordinates included — to the platform itself. The only version of the photo you fully control is the one before you share it.
How to check and clean a photo yourself
The reliable approach is to strip metadata before a photo leaves your device, and it takes under a minute:
- Open the free CalcPerch EXIF Remover in any browser.
- Drop in the photo. The tool reads and displays what's embedded — this alone is worth doing once with a few of your own photos; seeing your street corner appear from a "harmless" picture is convincing.
- Download the cleaned copy. The image looks identical; only the hidden data is gone.
Everything happens locally in your browser — the photo is never uploaded to a server, which would rather defeat the purpose of a privacy tool. If you're also resizing photos for a listing or email, run them through the Image Compressor too; smaller files are easier to send, and you'll be working from clean copies either way.
Stop the data at the source: phone settings
Cleaning files is the cure; the better fix is not recording location in the first place unless you want it. Menu names shift between versions, but the general path is:
iPhone: Settings → Privacy & Security → Location Services → Camera, and choose "Never" (or "Ask Next Time"). Separately, when you share via the Photos app, tap "Options" at the top of the share sheet — there's a Location toggle that strips GPS from just that share, which is a good middle ground if you like having location in your own library.
Android: open the Camera app's own settings and look for "Location tags," "Save location," or similar, and switch it off. Because Android camera apps vary by manufacturer, you can also revoke location permission for the camera app under Settings → Apps → Camera → Permissions.
A sensible policy for most people: keep location on if you genuinely use it (it powers the map view and search in your photo library), but strip metadata from any photo that leaves your household — marketplace listings, attachments to strangers, anything posted where you don't control the platform.
What metadata removal doesn't fix
Be honest with yourself about the limits. Stripping EXIF removes hidden data, not visible clues: street signs, house numbers, distinctive landmarks, reflections in windows, even school logos on clothing can place a photo just as precisely. And once a photo has been shared with metadata intact, cleaning your copy doesn't clean theirs. Metadata hygiene is one layer of privacy — a cheap, easy layer, but not the whole answer.
Sources
On what image files record and the standard that defines it:
- CIPA DC-008 — Exif specification — the standard that defines the GPS and camera fields discussed here.
- FTC — Online privacy and security — consumer guidance on what to strip before sharing.
Frequently asked questions
Does taking a screenshot of a photo remove its EXIF data?
Mostly yes — a screenshot is a brand-new image, so the original camera and GPS data aren't carried over. But the screenshot gets its own fresh metadata (device, timestamp), and you lose image quality. A proper EXIF remover keeps full quality and guarantees the old data is gone.
Do photos from digital cameras (not phones) contain GPS?
Usually not, unless the camera has built-in GPS or was paired with a phone for geotagging. They still record timestamps, camera model, serial-identifiable details, and sometimes an owner name — worth checking before publishing photos anywhere.
If Instagram strips metadata anyway, why bother cleaning photos first?
Because "generally strips for viewers" isn't the same as "you kept the data private" — the platform still received the original, policies change, and the habit that actually protects you is the one that covers email, messengers, and marketplaces too. Cleaning before sharing works everywhere; relying on each platform works only where it happens to be true.