What your photos hide: EXIF and GPS metadata
Every photo you take with your phone stores far more than the image. Inside the file itself travels an invisible block of data called EXIF: your exact device model, the date and time down to the second, the shooting settings and — if location services are on — the GPS coordinates of where you took it. Anyone who receives that file can read it with free tools, no technical skill required.
What a photo actually carries
| Data | What it reveals | Sensitive? |
|---|---|---|
| GPS coordinates | The exact spot it was taken, accurate to metres | High |
| Date and time | When you were there, to the second | Medium |
| Device model | Which phone or camera you use | Low |
| Serial number | On some cameras, identifies the specific body | Medium |
| Shooting settings | ISO, aperture, shutter — no personal value | None |
Why this actually matters
The risk isn't theoretical, and you don't have to be a public figure for it to affect you. The common cases are far more everyday:
- Marketplace listings. You post a photo of furniture shot in your living room; the coordinates say where you live, and the listing says you own something worth taking.
- Photos of children. An image taken at school or at home carries the location of both places embedded in it.
- Working from home. A screenshot sent to a client or posted on a technical forum can reveal your home address.
- A pattern, not a photo. Several geotagged images together map out a routine: where you live, where you work, what time you leave.
This isn't professional paranoia: in investigative journalism, stripping metadata from images before publishing is standard practice, specifically to protect the location of whoever sent them.
The common mistake: "social media already strips it"
That's half true, and the half that isn't is what causes problems. Large platforms (Instagram, Facebook, X) do remove metadata when processing an image for publication. But that doesn't cover the cases where the photo travels as a file:
- Emailing it as an attachment
- Uploading it to a marketplace, a forum or a web form
- Sharing it through a messaging app as a "document" or "file" rather than as a photo
- Passing it over USB, shared cloud storage or AirDrop
In all of those, the EXIF arrives intact at the other end.
How to check whether a photo carries a location
- On Windows: right-click the file → Properties → Details tab. Any location appears under the GPS section (latitude, longitude and altitude).
- On Mac: open the image in Preview → Tools menu → Show Inspector → info tab, GPS section.
- On a phone: in the gallery, open the photo's details (usually by swiping up or tapping the info icon). If a location was saved, you'll see a map straight away.
How to remove it
1. By converting the image (fastest)
When you re-convert a photo, the original metadata isn't copied into the new file — it's discarded in the process. Every tool on this site works this way: you convert the image and the result comes out clean, with no coordinates and no capture date, without the photo ever leaving your device.
2. From Windows itself
Right-click the file → Properties → Details → Remove Properties and Personal Information. Pick "create a copy with all possible properties removed" to keep the original untouched.
3. By stopping it being saved in the first place
If you'd rather your camera never recorded location again:
- iPhone: Settings → Privacy & Security → Location Services → Camera → Never.
- Android: open the Camera app → Settings → turn off Location tags (the exact label varies by manufacturer).
Mind the trade-off: without geotagging you lose place-based search in your own gallery. It's convenient to keep it on for your private photos and strip metadata only from the ones you're about to share.
If you run a site that accepts user images
Here it stops being personal and becomes legal. Under GDPR, GPS coordinates tied to an identifiable person are personal data. If your site lets people upload photos (a profile, a listing, a support form), you're receiving and storing that information even if you never use it and didn't know it was there. The sensible approach is to strip metadata when processing the image server-side, and to say so in your privacy policy.
Convert it here: the output has no GPS coordinates and no capture date, and the photo never leaves your device.
Convert a photo now
FAQ
What is EXIF metadata in a photo?
It's a block of information the camera stores inside the image file itself: camera or phone model, exact date and time, shooting settings and, if location services are on, the GPS coordinates of where the photo was taken.
Do photos uploaded to social media keep their GPS location?
Major platforms usually strip metadata when processing an upload, but that doesn't protect you elsewhere: emailing a photo, uploading it to a marketplace listing, attaching it on a forum or sharing it as a file usually keeps the metadata intact.
How do I check whether a photo has GPS coordinates?
On Windows, right-click the file, choose Properties and open the Details tab: any location shows under GPS. On Mac, open the photo in Preview and use Tools → Show Inspector. On a phone, the gallery app usually shows a map in the image details.
How do I remove metadata from a photo?
The simplest way is to re-convert the image with a tool that drops metadata in the process. On Windows you can also right-click → Properties → Details → Remove Properties and Personal Information, which creates a clean copy.
Are a photo's GPS coordinates personal data under GDPR?
Yes. A location tied to an identifiable person counts as personal data, so if your site or business accepts user-uploaded images, that metadata falls within GDPR scope and it's wise to discard it on receipt.
Does removing metadata affect image quality?
No. Metadata is text information stored alongside the image; removing it doesn't touch a single pixel. What can change quality is re-compression during conversion, not the metadata removal itself.