What photo metadata leaks about you (and who strips it)
The pixels are only part of what a photo says. Alongside the image, camera apps write a block of metadata — EXIF — and for privacy purposes three things in it matter enormously: where the photo was taken, when, and with what device. This guide covers what’s actually in there, which platforms remove it for you (and the limits of relying on that), and how to share photos without it.
What’s in a photo file besides the photo
A JPEG from a phone typically carries: GPS latitude and longitude, often precise enough to identify a building; altitude; capture date and time down to the second; the device make and model; software version; exposure settings; and sometimes a small embedded preview thumbnail. Screenshots are the notable exception — they don’t pass through the camera pipeline, so they don’t get GPS coordinates (their leaks are in the pixels: notification banners, tabs, usernames — see the screenshot page).
None of this is malicious; geotagging exists so your gallery can build maps and search. The problem is purely that the data travels with the file when the file leaves your gallery.
The classic failure
The pattern repeats every year somewhere: a photo posted “anonymously” — a marketplace listing, a room-for-rent photo, a pet photo, a protest shot — whose EXIF still contains the coordinates of the poster’s home. The person checked the pixels carefully and never thought about the container. It’s worth internalizing the asymmetry: checking pixels requires attention; checking metadata requires knowing metadata exists. Most people don’t.
Which platforms strip EXIF for you
Recent platform tests (2025–2026) are consistent on the big names: Facebook, Instagram, X and most major social networks remove EXIF — including GPS — from the copies other users can see or download. Facebook has done so since roughly 2012. Two caveats keep this from being reassuring:
- The platform itself reads the data before discarding it. Stripping protects you from other users, not from the service — location extracted from your uploads can feed ad targeting and location features.
- The stripping is policy, not physics. It differs by platform, changes without notice, and does not cover the many other ways photos travel: email attachments, most messaging apps sending “as file”, many forums, classifieds sites, cloud-drive share links and your own website preserve metadata exactly as sent. WhatsApp and similar apps strip metadata when compressing images, but sending “as document/original quality” typically keeps it.
The practical conclusion isn’t to memorize the matrix — it’s to stop depending on it. A photo that’s clean before it leaves your device is clean on every platform, in every DM, forever.
How to check what’s in your photo
- Windows: right-click → Properties → Details. GPS appears under “GPS” if present.
- macOS: open in Preview → Tools → Show Inspector → the GPS tab (if there’s location data).
- iPhone: the Photos info panel (ⓘ) shows a map if the photo is geotagged. iOS also offers “Remove Location” in the share sheet’s options — easy to miss, but built in.
- Android: Google Photos shows location in the details swipe-up; a long-press in the share flow on recent versions offers location removal.
If a photo of your home shows a map pin in these panels, that pin travels with any “original quality” copy you send.
How BlurLocally handles it
Every download from this site is re-encoded from raw pixels, which means the output file simply never has the original’s metadata — no GPS, no timestamps, no device identifiers, regardless of settings. This isn’t a feature toggle; it’s a property of drawing the image onto a canvas and encoding a new file. The tool also tells you what it found: when a loaded photo contains GPS data, the line under the editor says so, which over time teaches the useful habit — noticing which of your photos are geotagged at all.
Two honest limits. First, re-encoding strips everything, including harmless fields like copyright notices — if you’re a photographer who wants attribution metadata kept, this is the wrong tool for that export. Second, stripping metadata from your shared copy does nothing about copies that already left: the version you emailed last month still has its coordinates. Clean exports are prevention, not recall.
Beyond EXIF: the pixels that act like metadata
A few things live in the image itself but function like location data: street signs and house numbers (covered here), license plates (here), distinctive storefronts, and reflections. Reverse image search adds another layer — a photo posted twice can connect accounts even with every tag stripped. And captions betray more than either: “first day at Lincoln Elementary!” defeats any amount of pixel work. Redaction is a habit of looking at the whole object you’re about to share — file, pixels, words — and asking what each one says.
The two-minute routine
Before posting anything sensitive: share the photo through a clean-export step (this site, or any tool you’ve verified); glance at the corners and backgrounds for plates, labels and faces you didn’t mean to include; then read your caption as a stranger would. That’s the whole discipline. It costs two minutes, and unlike platform policies, it doesn’t change under you.