What Your Photos Reveal: The Hidden Data Inside Every Picture

A photo file holds more than the picture. Alongside the pixels, most cameras and phones write a block of metadata describing how, when and often exactly where the shot was taken. It is invisible when you look at the image and it travels with the file wherever you send it. Most of the time it is harmless, and sometimes useful. Occasionally it tells a stranger where you live.

What a photo can carry

The main format is EXIF, a standard created by Japanese camera makers in the 1990s and now written by virtually every phone. A typical phone photo includes:

  • GPS coordinates, accurate to a few meters when the camera has location access, plus altitude and sometimes the direction the camera was facing.
  • The date and time the photo was taken, often with your time zone offset, which on its own narrows down where you are.
  • The device: make and model, lens, and on many dedicated cameras the body and lens serial numbers, which can link photos posted under different names to the same camera.
  • Software that edited the file, and sometimes the owner's name or a copyright line typed into the camera's settings years ago.
  • An embedded thumbnail, a small preview of the image. Some editing tools update the main picture but leave the old thumbnail, so a cropped or blurred photo can still carry a tiny copy of the original.

Two other containers, XMP and IPTC, carry editing history, captions, keywords and creator details, mostly added by editing and photo management software.

This has gone wrong in public

In 2012, a magazine published a photo of the fugitive software entrepreneur John McAfee without stripping its metadata, while he was in hiding. The GPS coordinates showed he was in Guatemala, and he was arrested there days later. In a widely reported 2003 incident, a television presenter posted a cropped photo whose embedded thumbnail still showed the uncropped original. Those are the famous cases. The everyday version is quieter: a photo of a couch listed for sale, taken in a living room, with the home's coordinates attached.

Who strips it and who does not

Most large social networks remove location and camera details from the copy of a photo that other people can see or download. That protection depends entirely on the route the file takes, and plenty of routes keep everything:

  • Photos attached to an email
  • Files shared through cloud storage links, such as Google Drive, Dropbox or OneDrive
  • Images sent as a "file" or "document" in a messaging app to avoid compression
  • AirDrop and direct transfers between devices
  • Uploads to many forums, classified sites and personal websites

Note also that a platform which strips metadata from the public copy may still read it, and keep it, when you upload. Removing it before the file leaves your device is the only way to be sure who sees it.

Stop it at the source

If you rarely need to know where your photos were taken, the simplest fix is to stop the camera recording it. On an iPhone, go to Settings, then Privacy & Security, then Location Services, then Camera, and choose Never. On Android, open the camera app's settings and turn off the option to save or tag location; the wording varies by maker. Photos you have already taken keep their location, so this protects future pictures only.

When you want location in your own library but not in what you share, use the share controls. On an iPhone, tap Options at the top of the share sheet and turn off Location before sending. Google Photos has a setting to remove location from items shared by link.

Removing metadata from a file

For a photo that is already taken, remove the metadata before you send it. There are two ways to do it, and they are not equal. Re-saving the image, as screenshot tricks and many online tools do, decodes and re-compresses the picture, which costs quality each time. The better way is to cut the metadata blocks out of the file and leave the image data untouched, so the result is pixel for pixel identical.

The Photo Metadata Remover does the second. It shows what a photo reveals, including whether it holds a location or a hidden thumbnail, removes EXIF, XMP and IPTC without re-compressing, and checks its own output to confirm nothing is left. The photo is processed on your device and never uploaded, which matters for a tool whose entire purpose is privacy.

What metadata removal cannot fix

Stripping metadata removes what is written about the picture, not what is in it. A street sign through the window, a distinctive view, a house number, a reflection in a mirror or sunglasses, a school logo on a uniform: people have been located from all of these with no metadata at all. Before posting a photo taken at home, look at the background as a stranger would.

Photo Metadata Remover: See where a photo was taken, then strip it out.

Open the tool
The Internet Omni-Tool