Remove location data from photos before you share them
A photo can reveal more than the pixels. Depending on the file and sharing route, it may carry GPS coordinates, capture time, device details, editing fields, captions, or provenance data.
What photo metadata can reveal
EXIF is best known for camera settings, but privacy-sensitive fields can include latitude and longitude, capture date and time, device make and model, software, orientation, and other technical details. XMP or IPTC can contain authoring, copyright, workflow, caption, and editing information. Some files also carry C2PA Content Credentials or application-specific chunks.
Not every photo contains all of this. A screenshot may contain very little. A camera original may contain much more. The useful habit is to inspect the actual file instead of assuming a social network will clean it for you.
The safest workflow is simple
- Keep the original. Store the full-resolution source somewhere private. Do not destroy metadata you may later need for your own archive.
- Inspect a sharing copy. Check GPS, EXIF, XMP/IPTC, software fields, and provenance information before upload.
- Remove only what you do not want to disclose. For most public social posts, GPS is an obvious candidate. Professional publishing workflows may intentionally preserve copyright or provenance fields.
- Verify the exported file. Re-open the sanitized copy and confirm that the fields are actually gone.
Why “the app strips EXIF” is not a privacy plan
Messaging apps and social networks frequently transform media, but behavior can differ by format, client, quality option, and whether you send an image as a photo, document, original file, or cloud link. A platform can also change its pipeline without notice.
More importantly, the file received by another person does not tell you everything the platform received at upload time. If location privacy matters, clean the file before it leaves your device.
iPhone users already have useful controls
Apple documents that shared photos can include metadata such as date, time, location, device information, and captions. In the Photos share sheet, iPhone users can turn off Location for a share. Apple also provides controls for adjusting or removing stored photo locations.
Primary reference
Metadata cleanup has limits
Removing EXIF or C2PA metadata does not erase information that is visibly present in the image. A street sign, house number, school badge, reflection, QR code, shipping label, or computer screen can expose far more than EXIF.
Metadata cleanup also does not mean an invisible pixel-domain watermark has been removed. Those are separate technical layers. A privacy tool should be precise about which layer it is changing.
| Risk | Check | Typical action |
|---|---|---|
| Exact location | GPS latitude/longitude, location-related XMP | Remove before public posting |
| Device details | Camera make/model and software fields | Remove when unnecessary |
| Authorship/workflow | XMP/IPTC and Content Credentials | Decide intentionally; these can be useful |
| Visible personal information | Pixels themselves | Crop, redact, or blur separately |
For creators, make sanitization a publishing step
If you regularly post from home, travel, photograph products in a private studio, or send client work through multiple platforms, manual checking gets old quickly. Treat the sanitized copy the way you treat a resized thumbnail or final export: a separate deliverable produced specifically for sharing.
That gives you a repeatable rule: originals stay private; public copies carry only the information you intended to publish.
Inspect and clean a sharing copy locally
CreatorPrivacyKit reads supported metadata in your browser so you can review GPS, EXIF, XMP and provenance information before publishing.
Open Metadata Cleaner →