B

Bawitools
Blog
  • privacy
  • photography
  • metadata

EXIF metadata: what your photos say about you without asking

Every photo you take with a phone carries an invisible block of data: where you were, when, which camera, and sometimes more. What it holds and when it's worth stripping.

By BawiTools5 min read

You take a photo on your phone and email it. What arrives isn’t just the picture: it’s the picture plus a block of information that wrote itself, that you’ve never seen, and that you probably don’t know exists.

It’s called EXIF, and it’s been there since 1995.

What it actually is

EXIF stands for Exchangeable Image File Format. It’s a standard defining how a camera stores information about a photo inside the file itself, in a reserved area at the start that image viewers skip when displaying it.

It was created for a sensible reason. A photographer returning from a shoot with four hundred frames needs to know the settings used on each: which came out blurred from a slow shutter, which is grainy from a high ISO. That used to go in a notebook. EXIF automated it.

The problem is that phones expanded what gets stored.

What a phone photo contains

Field Example
Date and time 2026-08-14 22:47:13
GPS coordinates 40.4168° N, 3.7038° W
Altitude 667 m
Make and model The manufacturer and exact model
Serial number On some cameras, unique to your unit
Orientation How you were holding the device
Aperture, ISO, shutter The exposure settings
Software OS or editing app version
Thumbnail A small copy of the image

The first three rows are the ones that matter. The location is accurate to within metres. It doesn’t say “Madrid”: it gives the exact point, altitude included, which inside a building means the floor.

Why this matters more than it looks

A single photo with GPS is rarely a problem. The risk comes from the set.

If someone gathers several of your photos published over months, the coordinates draw a pattern: where you sleep, where you work, what time you leave, where your children go to school. No single photo says that. All of them together do.

A few specific cases deserve care:

  • Selling something secondhand. You post a photo of the furniture, and with it your home’s exact location to a stranger.
  • Renting out a property. Same thing, with more people looking.
  • Photos of children. School, the usual park, home. This is the combination most worth avoiding.
  • Sensitive work material. Camera model and serial number can identify who took a specific photo.
  • Whistleblowing or journalism. Here EXIF can identify a source directly.

And something almost nobody knows: the embedded thumbnail isn’t always updated when you edit. There are documented cases of images cropped to hide something whose internal thumbnail still showed the full original.

What social networks do

Here there’s good news, with caveats.

The big platforms — Facebook, Instagram, X, WhatsApp — strip EXIF on upload. Not to protect your privacy, but because they re-compress every image to save bandwidth and the block gets lost along the way. Either way the effect is good.

But the exceptions matter:

  • Sending a photo “as a document” or “uncompressed” keeps the original file, with everything inside. That’s exactly what people do when they want good quality.
  • Email touches nothing. An attachment arrives exactly as it left.
  • Storage services (Drive, Dropbox, iCloud) keep the whole file. Share the link, share the EXIF.
  • Uploading to your own site keeps whatever you upload, unless your CMS strips it.

So: the route that protects you most is the one that compresses most, and the route that preserves quality best is the one that leaks most.

How to see yours

On Windows, right-click the photo → Properties → Details. On macOS, open it in Preview and press ⌘I. On Android and iOS, the gallery usually shows a map if the photo has coordinates.

Try a recent phone photo. You’ll almost certainly see the location.

How to remove it

At capture time. Turn off location access for the camera app in system settings. This is cleanest: what never gets written doesn’t need deleting. The downside is losing place-based organisation in your gallery, which is genuinely convenient.

When sharing. iOS lets you strip location from the share sheet itself (Options → turn off Location). Android varies by manufacturer, but many galleries include “Remove location data”.

On the file. On Windows, Properties → Details → Remove Properties and Personal Information. It makes a clean copy without touching the original.

By converting. Most conversions drop EXIF, because the block isn’t carried between formats unless the tool deliberately does so. Converting to PNG, for instance, usually leaves the image metadata-free.

When you do NOT want to remove it

Worth saying, because “always strip metadata” is bad advice:

  • Professional photography. Exposure data is your working record, and losing it means losing what you’d learn from it.
  • Authorship. The copyright field is your only mark inside the file.
  • Documentation. In insurance claims, surveys or disputes, date and location are precisely the evidence.
  • Your personal archive. Sorting twenty thousand photos by date and place only works if that data exists.

The practical rule is simple: keep EXIF on your originals and strip it from copies that leave your control.

The essentials

EXIF isn’t a threat. It’s an old, useful standard that, once it reached phones, started recording something its creators never anticipated: your exact position, in every photo, without telling you.

Knowing it’s there solves most of the problem. After that it’s just deciding, photo by photo, whether that information should travel with the image or stay home.

Comments

Log in to leave a comment