What Your Photos Reveal About You — EXIF Data & Privacy
Every photo you take carries invisible baggage — GPS coordinates, device fingerprints, timestamps, and editing history. Here's what's actually in there.
You take a photo of your dog in the backyard and text it to a friend. Harmless. But that JPEG file doesn't just contain pixels — it contains your exact GPS coordinates, the time down to the second, your phone model, and sometimes a serial number that's unique to your device. If you post that image on a forum, a blog, or anywhere that doesn't strip metadata, anyone who downloads it can extract all of that in seconds.
Scanly's EXIF Viewer lets you drop any photo and see every metadata field it carries — GPS, camera data, software tags, thumbnails, all of it. Runs in your browser, nothing leaves your machine. Try it free →
Check Your Photo MetadataThe Data You Didn't Know You Were Sharing
EXIF (Exchangeable Image File Format) was designed for photographers. It records camera settings — ISO, aperture, shutter speed, focal length — so you can review what worked for a shot and replicate it later. That's useful. The problem is that the same standard also records contextual data that has nothing to do with photography technique.
GPS coordinates. Most smartphones tag every photo with latitude, longitude, and sometimes altitude. The precision is typically within 3-5 meters. Take a photo in your apartment, and the metadata places someone at your building. Take enough photos over time, and the coordinates trace out your daily routine — home, office, gym, school pickup.
Date and time. Not just the date — the exact timestamp, including timezone offset on many devices. Combined with GPS, this tells someone where you were and when. A photo tagged at 2:15 AM at a specific address tells a story you might not want told.
Device identification. Camera make, model, and often a serial number. Two photos from the same camera carry the same serial number, which means someone can link images taken years apart to the same device — and by extension, to the same person. Forensic investigators use exactly this technique.
Software and editing history. If you crop, filter, or adjust an image, some editors write their name and version into the EXIF. Photoshop, Lightroom, Snapseed, and others leave traces. The EXIF thumbnail sometimes preserves the original uncropped image — meaning you can crop out a face or a location sign, and the thumbnail still shows it.
Where This Actually Gets Dangerous
The risk isn't theoretical. A journalist photographs a source in a sensitive location and publishes the image with GPS still attached — the source's location is exposed. A person selling items online posts product photos taken at home — the listing now contains their home coordinates. A parent shares a child's school event photo on a public forum — the school's location is embedded in the file.
In 2012, Vice magazine published a photo of John McAfee while reporting on his hideout location. The EXIF data in the published image contained GPS coordinates that revealed his exact position in Guatemala. Metadata doesn't care about your intentions — it records facts.
Even without GPS, the combination of device serial number, timestamps, and software tags creates a fingerprint. If someone has access to two different photos — say, one from your anonymous blog and one from your public social media — matching serial numbers ties the accounts together. The EXIF Viewer shows exactly which identifying fields your files carry, so you know what you're working with before sharing anything.
What Your Phone Embeds by Default
Both iOS and Android embed GPS coordinates by default unless you've explicitly turned it off. Here's what a typical smartphone photo contains:
Always present: camera make and model, image dimensions, color space, date/time, orientation, flash status, focal length equivalent, software version.
Usually present (GPS enabled): latitude, longitude, altitude, GPS timestamp, GPS datum (WGS-84).
Sometimes present: lens make and model (on phones with multiple cameras, this identifies which lens was used), scene type, white balance, exposure mode, digital zoom ratio, unique image ID.
To see exactly what your own phone embeds, take a fresh photo and drop it into the EXIF Viewer. The fields vary by device and OS version — the only way to know for sure is to check a real file from your specific phone.
The GPS Trail You Don't See
GPS coordinates in a single photo reveal one location. GPS coordinates across a photo library reveal a life. Anyone with access to a batch of your geotagged images — from a shared drive, a cloud album, or a stolen phone backup — can map your movement patterns.
Scanly's GPS Map Viewer plots photo coordinates on an interactive map. It's built for you to audit your own files — drop a batch of photos and see exactly which locations you've tagged. If the map shows your home, your workplace, and your regular routes, that's information you probably don't want distributed with every image you share.
The fix is simple: strip GPS before sharing. But you have to do it before the file leaves your device. Once someone downloads the original, the data is out. You can't retract metadata after publishing.
Thumbnails — The Data That Survives Cropping
EXIF includes a thumbnail field — a small preview image (typically 160×120 pixels) embedded in the file header. Most cameras and phones generate this thumbnail at the moment of capture. The catch: editing software doesn't always update it.
If you take a photo, then crop out a person or a street sign, the full uncropped scene might still be visible in the thumbnail. Some editors (including older versions of Photoshop) are notorious for leaving stale thumbnails. This is a known issue in forensic analysis — investigators routinely check the EXIF thumbnail against the visible image for discrepancies.
The EXIF Viewer displays the embedded thumbnail alongside the main image. If they don't match, you know the file carries outdated preview data that should be stripped.
How to Strip Metadata Before Sharing
Knowing what's exposed is step one. Step two is removing it. You have a few options depending on your workflow.
Per-file removal. Scanly's EXIF Remover strips all metadata from any image file — GPS, device info, timestamps, thumbnails, everything. The file stays in your browser; nothing is uploaded. You get a clean image with pixel data only. This is the most reliable approach for individual photos you're about to share publicly.
Disable GPS at the source. On iOS: Settings → Privacy & Security → Location Services → Camera → Never. On Android: open the Camera app → Settings → toggle off Location tags. This prevents coordinates from being written in the first place. Camera make/model and other device fields will still be recorded — only GPS is affected.
Rely on platform stripping (partially). Instagram, Facebook, Twitter/X, and most social platforms strip EXIF on upload. But they store the original data server-side. And not every sharing method goes through a platform — email attachments, Slack uploads, shared Drive links, direct downloads, and forum posts often preserve the full original file. Assume metadata survives unless you remove it yourself.
For a deeper look at which platforms strip what, see the social media EXIF stripping guide.
Beyond EXIF — What Pixels Themselves Reveal
Even after stripping all metadata, the image content itself carries information. A reflection in a window shows a street name. A shadow angle indicates time of day. A Wi-Fi network name on a screen in the background identifies a building. Metadata is the low-hanging fruit, but visual content has its own information leakage.
Forensic techniques can also identify a camera by its sensor noise pattern — a unique fingerprint baked into every image at the hardware level. This is harder to detect and impossible to strip because it's part of the pixel data, not the metadata. If you're operating at a threat level where sensor fingerprinting matters, metadata stripping alone isn't sufficient — but for the vast majority of people, removing EXIF covers the practical risks.
Your Photos Talk — Decide Who Listens
The metadata in your photos exists for practical reasons. GPS makes it easy to find beach photos from last summer. Timestamps help sort a decade of memories. Camera settings let you learn from your best shots. None of that data is harmful when it stays on your own device.
The problem starts at the moment of sharing. Every image you send, upload, or publish potentially carries your coordinates, your device identity, and your daily patterns along with it. A quick pass through the EXIF Viewer shows you what's there. The EXIF Remover gets rid of it. Takes less time than typing a caption.
Tools used in this guide