← All posts

What's Actually Hiding in Your Photos? EXIF and GPS Metadata, Explained

Published August 28, 2026

The photo tells more than the picture does

In 2012, security researcher John McAfee was on the run in Belize. He gave a magazine interview in secret, and the accompanying photo of him — face hidden, location supposedly unknown — was published online. Within hours, people had located him: the photo's embedded GPS coordinates pointed straight to the hotel he was hiding in. No image analysis, no detective work. The location was sitting in the file the whole time.

That's an extreme case, but the mechanism behind it sits in every photo your phone takes.

What EXIF actually is

EXIF (Exchangeable Image File Format) is a block of metadata your camera or phone writes directly into a photo file the moment you take it — separate from the pixels themselves, invisible unless you specifically go looking. It's not a conspiracy or a tracking feature; it exists for legitimate reasons (photo apps use it to sort your library by date, apply lens corrections, orient the image correctly). It's just rarely explained to the person holding the phone.

A typical photo from a modern smartphone can include:

  • Exact GPS coordinates — often accurate to a few meters — plus altitude and sometimes the compass direction the camera was facing
  • Device make and model — "iPhone 17 Pro," down to the exact model
  • Lens and camera settings — aperture, ISO, shutter speed, focal length
  • Software used to edit it, if you ran it through an editing app
  • Precise date and time, often to the second
  • Occasionally an owner or artist name, if it was ever set on the device

None of this is visible when you look at the photo. You'd need to deliberately inspect the file to see it.

The misconception: "doesn't the app I use strip this automatically?"

Often, yes — but not always, and the exceptions are exactly the ones that matter most.

Major platforms like Instagram, Facebook, and X do strip most EXIF data from photos during upload, partly to save bandwidth and partly for user privacy. That's a real, meaningful protection — but it only applies once a photo goes through that specific upload pipeline.

The metadata usually survives fully intact when you:

  • Send the original file directly — AirDrop, email attachments, Messages/iMessage at "actual size," or a shared cloud drive link
  • Post to a marketplace or classifieds site that doesn't process images the way social networks do
  • Upload to a personal website or blog without an image pipeline that scrubs metadata
  • Transfer via USB or an external drive

This is the gap most people don't think about. You get used to "social media handles this," and forget that the original file — the one sitting in your camera roll, the one you might email to a landlord, upload to a resale listing, or send to family — usually still has everything.

Why it matters in practice

The GPS coordinates in a photo of your front door, taken to sell a couch online, point straight at your home address. A photo taken from a hotel balcony on vacation, shared in a group chat before you're back home, tells anyone who checks exactly when your house is empty. A product photo for a small business, taken in a home office, can leak a home address nobody meant to publish.

None of these require a sophisticated attacker — just someone willing to open the file's properties, or run it through any of the many free EXIF viewers online.

How to check what's actually in your own photos

The only way to know for sure is to look. We built a free tool that does exactly this, entirely in your browser — it never uploads your photo anywhere, so you can check something sensitive without a second thought: see what your photo reveals, and strip it in one click.

How Privately handles this differently

Most privacy tools take a blunt approach: strip everything, always. We went a different way, because that trade-off has a real cost — if metadata is deleted the moment a photo is imported, you permanently lose things like the actual date a memory was captured, which matters when you're looking back at a vault years later.

So Privately keeps the original metadata inside the encrypted vault by default — it's already sealed behind AES-256-GCM encryption, so there's no added exposure risk in storing it. The privacy decision instead happens at the one moment it actually matters: when a photo leaves the vault. Exporting or sharing gives you three independent switches — Capture Date and Camera & Lens default on (most people want to keep those), while Location (GPS) defaults off, stripped automatically unless you deliberately turn it back on for a specific photo.

It's a small distinction, but it's the difference between "delete everything and hope you didn't need it later" and "keep your memories intact, control what leaves."

If that sounds like the right default for your photos, Privately is free to download — this part of it isn't gated behind a subscription. And if you're also rethinking where your most private photos live in the first place — not just what leaves them — it's worth reading why the iPhone's built-in Hidden Album isn't the same thing as an encrypted one.