Privacy

Why your photos talk about you: how EXIF metadata puts your privacy at risk

Written and maintained by the KitYards team Published: 14 min read

Somebody sells a bicycle. They photograph it in the garage, post the listing, and within a day a stranger knows their street, their house, and that there is a bike worth two thousand euros in an unlocked garage. Nothing in the picture gave that away — no house number, no street sign, no reflection. The address was in the file, in a block of data that is invisible on screen and is copied faithfully every time the photo is sent. It is called EXIF, it has been in almost every digital photograph since 1995, and most people have never seen it.

What EXIF metadata actually is

EXIF — Exchangeable Image File Format — is a standard for storing structured information inside an image file. It was published in 1995 by the Japanese camera industry so that a photograph could carry its own technical context: which camera took it, with what settings, and when. Practically every digital camera and every phone has written it ever since. In a JPEG it sits in a small block near the beginning of the file, before the compressed pixels; in a PNG it lives in a dedicated chunk; in a WebP it is a chunk of the container. In all three cases it travels with the file. Copy the photo, email it, put it on a USB stick — the block goes too.

None of this is a bug or a secret. It is a documented, well-intentioned feature, and it is genuinely useful: it is why your photo library can sort by date, group by place and tell you which lens you used. The problem is not that the data exists. The problem is that it was designed for photographs that stay with the photographer, and we now send photographs to strangers a dozen times a day.

What a phone actually records

The exact set varies by device, but a photo taken on a modern phone with default settings typically carries:

  • GPS coordinates — latitude and longitude to six decimal places, which is a precision of roughly ten centimetres, plus altitude and often the direction the camera was pointing.
  • Date and time of the exposure, to the second, together with the time-zone offset.
  • Make and model of the device — “Apple / iPhone 15 Pro”, “Samsung / SM-S928B”.
  • Camera settings: shutter speed, aperture, ISO, focal length, whether the flash fired.
  • Lens and body serial numbers, on many dedicated cameras and some phones.
  • Software — the operating system version, and the name of any app that edited the file afterwards.
  • Author, copyright and comment fields, filled in by editing software and frequently carrying a real name.
  • A unique image ID, which is exactly what it sounds like.

The GPS field is the one that matters

Everything above is information about a device. The coordinates are information about a person. Six decimal places is not “the neighbourhood” or “the city” — it is a specific corner of a specific room. A handful of photos from the same account are usually enough to draw somebody's life: a cluster of coordinates in the evenings and at weekends is home, a different cluster on weekday mornings is work, and a third that repeats every Tuesday at six is a gym, a clinic or a place of worship. No single photo says any of that. The pattern does.

How the data escapes

Most people's mental model is that posting a photo online strips it clean. That is half true in a way that is more dangerous than being simply false, because the half that is true teaches you to stop worrying.

Social networks: what they strip and what they keep

The big platforms do remove EXIF from the copy they serve to the public. Upload a geotagged photo to Facebook, Instagram or X and the version another user can download will usually have nothing left in the header. This is a real protection and it is worth knowing about. It is also a protection against other users, not against the platform: the file you uploaded arrived complete, coordinates included, and what happens to that original afterwards is governed by a privacy policy rather than by physics. The stripping happens on their server, after they have the data.

Messaging apps: it depends entirely on how you send it

This is where most accidental leaks happen. WhatsApp, Telegram and Signal re-compress photos sent through the normal photo picker, and re-compression discards EXIF as a side effect. Send the same file as a document or file — the paperclip, the “send as file” option, the “original quality” toggle — and it goes across untouched, metadata and all. The two paths sit next to each other in the same menu, they produce a visually identical result in the chat, and only one of them is safe. People choose “original quality” precisely when the photo matters, which is usually when the location matters too.

Everywhere else, nothing is stripped at all

Email attachments arrive exactly as they left. So do files uploaded to forums, classified-ad sites, property portals, cloud storage shared by link, printing services, insurance claim forms and job applications. A CV with a photograph, a rental listing, a warranty claim, an image posted to a support forum to show an error on screen — all of them carry whatever the original file carried. The default in most of the internet is: everything is preserved.

The four risks, in the order you are likely to meet them

1. Publishing your home address by accident

This is by far the most common, and it costs nothing to exploit: any image viewer shows the coordinates. Second-hand listings, pets for sale, “look at my new kitchen”, a photo of a lost cat with a phone number — all photographed at home, all posted publicly. The listing tells a stranger what you own and roughly what it is worth. The metadata tells them where it is.

2. Building a timeline of your movements

Each photo carries a coordinate and a timestamp. A set of photos is therefore a partial record of where somebody was and when, accurate to the second. That is a gift to anyone attempting to establish a pattern: an ex-partner, a stalker, an opposing party in a legal dispute, a burglar working out when a house is empty. It requires no technical skill, only patience and a public account.

3. Linking accounts you thought were separate

The device fields are a fingerprint. Camera make, model, lens and — where present — body serial number are constant across everything a given camera produces. If the same serial number appears on an anonymous account and on a portfolio with your name on it, the two are the same person, and no amount of care about writing style or usernames changes that. This is not theoretical: it is a standard, routine step in open-source investigation, and it is how more than one anonymous source has been identified.

4. Leaking things you did not know were in the file

Editing software writes its own fields. A photo that has been through a desktop editor often carries the licensed user's full name, the organisation that owns the licence, and sometimes an internal file path — which is to say a project name, a client name and a folder structure. Press images and product shots leak this constantly. Nobody ever decided to publish it; the software wrote it and nobody looked.

Why the cleaning tool should run on your device

Here is the awkward part. Search for a way to remove EXIF and most results are websites that ask you to upload the photo. Think about what that transaction is. You have a file whose hidden location data you consider too sensitive to share. To remove it, you send the complete file — location data included — to a server run by someone you have never heard of, funded by means you cannot see, in a country you were not told about. The problem you wanted to solve is that a stranger might learn where you live. The proposed solution is to tell a stranger where you live and then trust them to forget.

That is not a criticism of anyone's honesty; it is a structural point. A server-side conversion creates copies you cannot audit: the upload, the worker's temporary file, the output, whatever the CDN cached, and a line in an access log that contains at minimum your IP address, the filename and the time. Retention promises are policies, not mechanisms — they are enforced by the operator's own code and goodwill, they can change without notice, and they say nothing about the backup taken twenty minutes later. We wrote about this at length in the piece on how KitYards handles data, and the argument is the same here, only sharper: with metadata, the payload *is* the secret.

What a local tool does instead

A browser has been able to do all of this on its own for years. The FileReader API hands the page the bytes of a file the user chose, without any network involvement; from there, parsing an EXIF block is ordinary arithmetic and rebuilding the file is a matter of copying byte ranges into a new buffer. There is no server in the loop because there is nothing a server could contribute. The EXIF Viewer & Remover on this site works exactly that way: it reads the file in memory, shows you every field it finds, and hands you back a rebuilt copy through a temporary local URL that dies when you close the tab.

Rewriting is not the same as re-encoding

There are two ways to strip metadata, and the difference shows up in the file you get back. The lazy way is to draw the photo onto a canvas and export it again: a canvas has no concept of metadata, so the output is certainly clean — but it has also been decompressed and re-compressed, which costs a generation of JPEG quality and can make the file bigger than the original. The right way is to walk the container and copy everything except the metadata blocks, leaving the compressed image data untouched. The result is byte-for-byte identical in the pixels and simply shorter at the front. That is what the tool here does for JPG, PNG and WebP; the canvas route only exists as a fallback.

See what your own photos are carrying

Drop a picture in and read the report before you strip it. Most people are surprised by at least one field. Nothing is uploaded — the file is read and rebuilt in your browser.

Inspect & clean

How to verify the claim rather than believe it

“It all happens locally” is easy to write on a page and impossible to take on trust. Fortunately it is one of the few claims on the web you can check yourself, in under a minute:

  1. 1 Open your browser's developer tools and select the Network tab.
  2. 2 Load the tool page, then clear the request list so only what happens next is shown.
  3. 3 Drop in a photo and clean it. Watch the list: if the file were being uploaded, a request carrying several megabytes would appear. Nothing does.
  4. 4 For the strongest version of the test, load the page once, then turn off your Wi-Fi and use the tool offline. It keeps working, because everything it needs is already on your machine.

Cleaning your photos in practice

A workable routine, in rough order of effort:

  1. 1 Look before you strip. Run one photo from your camera roll through a viewer and read what comes back. Knowing which fields your specific device writes is worth more than any general advice.
  2. 2 Clean anything that leaves a private channel. Marketplace listings, forum posts, anything public, anything going to somebody you do not know. It takes seconds.
  3. 3 Watch the “send as file” option. In messaging apps, that toggle is the difference between a re-compressed copy and your original with its coordinates attached.
  4. 4 Keep your own originals intact. Clean the copy you are sending, not the file in your library — the metadata is useful to you and harmful only in transit.

One useful side effect: converting an image between formats also drops the metadata, because a conversion re-encodes the pixels into a new container and nothing carries the old header across. If you were going to convert a photo to WebP for a website anyway, the Universal Image Converter does both jobs at once. It is a re-encode rather than a lossless rewrite, so use it when you were converting anyway, and use the dedicated cleaner when you want the original quality preserved exactly.

What removing EXIF does not fix

It is worth being exact about the edge of the protection, because a false sense of safety is worse than none:

  • Anything visible in the frame. House numbers, street signs, number plates, a name badge, a document on the desk, a distinctive view through a window, a reflection in a mirror or in someone's glasses. Metadata cleaning does not touch the image.
  • The sensor's own fingerprint. Manufacturing imperfections give each sensor a consistent noise pattern that survives cropping and compression and can link photos to a specific physical camera. That lives in the pixels.
  • Copies already sent. Cleaning affects the file you are about to share, not the one you shared last year.
  • What the receiving platform already has. If you uploaded the original, the original is what they hold, whatever the public copy looks like.
  • Screenshots of maps or apps. No EXIF, but the content of the screenshot may be far more specific than any coordinate.

Better still: stop writing it in the first place

Cleaning is a cure. Turning off the geotag is prevention, and it takes about fifteen seconds.

On iPhone

Settings → Privacy & Security → Location Services → Camera, and choose Never. Photos already taken keep their coordinates, so this only affects new ones. When sharing an individual photo you can also tap the share sheet's Options at the top and turn Location off for that share — useful when you want the geotag in your own library but not in the message.

On Android

Open the Camera app, go to its settings and turn off Location tags (the exact wording varies: “Save location”, “Geotagging”, “Location tags”). On most builds you can also revoke the location permission for the camera entirely from Settings → Apps → Camera → Permissions.

The trade-off is real: with geotagging off, your photo library can no longer group by place, and “photos from Lisbon” stops working. Many people keep it on for that reason and simply clean the files they share. Either approach is defensible. Doing neither, on the assumption that a photo is only a picture, is the one that keeps surprising people.

The short version

A photograph is two documents in one. The visible one you compose deliberately; the invisible one is written by your device without asking, and it can be more specific about you than anything in the frame. It is easy to read and easy to remove — and the tool that removes it has no business asking you to upload the very file you are trying to protect. Read what your own photos say about you, decide what you are comfortable sending, and strip the rest before it leaves your device rather than after.

The tools used in this guide

Free, no sign-up, and everything runs on your own device.

Keep reading