What Is EXIF Data? Strip It Before Sharing
Your photos embed GPS coordinates, device info, and timestamps. Learn what EXIF data contains, the real privacy risks, and how to remove it in seconds.
By Formatly
Every photo your phone takes carries a hidden payload: exactly where you were, when, and on what device — embedded in the file itself. It’s called EXIF data, and most people share it without knowing it exists.
What EXIF data actually contains
EXIF (Exchangeable Image File Format) is a metadata standard written into JPG, HEIC, TIFF, and WebP files at capture time. A typical smartphone photo’s EXIF includes:
- GPS coordinates — latitude/longitude, often accurate to a few meters, plus altitude
- Timestamp — date and time the photo was taken (down to the second)
- Device info — phone model, sometimes serial number
- Camera settings — aperture, shutter speed, ISO, focal length, flash state
- Software — the app or OS version that created the file
- Embedded thumbnail — a small preview image (which itself can contain metadata)
- Orientation flag — how the phone was held
You can see it yourself: on Windows, right-click a photo → Properties → Details. On macOS, open in Preview → Tools → Show Inspector. It’s all there in plain text.
What EXIF looks like: a real example
Here’s a condensed version of what a typical iPhone photo carries (values illustrative):
File: IMG_4821.HEIC
Date Taken: 2026-09-14 18:42:07
GPS: 40.7128° N, 74.0060° W (±4 m)
Altitude: 12 m above sea level
Device: iPhone 16 Pro
Lens: 24mm f/1.78, 1/120s, ISO 100
Software: iOS 18.4
Read that as an attacker would: on September 14th at 6:42 PM, the owner of an iPhone 16 Pro was at a specific street corner in New York. One photo gives a location; a camera roll gives a life pattern — home, workplace, school, vacation dates. That is what’s riding along inside every photo you share unmodified.
Note the altitude and precision fields too — modern phones log GPS accuracy, so the coordinates aren’t approximate. And the thumbnail embedded in the EXIF can survive even naive “metadata removal” that only clears top-level tags, which is why a proper stripper rewrites the file rather than just blanking fields.
The privacy risks are concrete, not theoretical
Location exposure. The big one. That photo of your new apartment, your kids at the park, your car for sale — each can carry the exact coordinates where it was taken. Post it publicly and anyone who downloads the file can read them. This is how “I found the Airbnb from the listing photos” stories happen.
Timeline reconstruction. Timestamps across a set of photos reveal patterns: when you’re home, when you travel, your daily routine.
Device fingerprinting. Serial numbers and device models in EXIF have been used to link anonymous accounts to real identities in investigations and doxxing cases.
Workplace leaks. Photos of prototypes, documents, or whiteboards can carry the photographer’s identity and the office location.
Some platforms strip EXIF automatically — Instagram, Facebook, and Twitter/X remove most metadata on upload. But many don’t: email attachments keep it, messaging apps vary, file-sharing links keep it, and your own website or portfolio keeps it unless you strip it first. Never assume the platform handled it.
When to keep EXIF and when to strip it
Keep it when:
- Archiving personal photos (location data makes “photos from that trip to Kyoto” searchable)
- Submitting to stock photo agencies or contests (they often require intact metadata as proof of origin)
- Doing photography work where camera settings are useful reference
Strip it when:
- Posting publicly (social media, forums, marketplace listings)
- Sharing with strangers (selling items online, dating apps)
- Sending to anyone who doesn’t need to know where you live
- Uploading to a website or portfolio
The safe default: strip on share, keep on archive. Maintain your originals with metadata intact, and export clean copies for sharing.
How to strip EXIF data
In the browser (fastest, private): Our EXIF remover deletes all metadata client-side:
- Go to /remove-exif/.
- Drop your photos onto the page.
- The tool strips every EXIF tag and shows you what was removed.
- Download the clean copies.
Nothing is uploaded, so this is safe even for sensitive photos. You can verify with the Network tab in DevTools — no image data leaves your machine.
On your phone: iOS lets you remove location from individual photos (Photos → share → Options → toggle off Location), but that only strips GPS, not the rest. Android’s options vary by manufacturer. A dedicated tool is more thorough.
On desktop: ExifTool (free, command-line) is the gold standard — exiftool -all= photo.jpg wipes everything. Windows and macOS also offer partial removal via file properties, but they miss some tags.
A note on screenshots and edited images
Screenshots generally contain minimal EXIF (no GPS, since no camera was involved) but can include device and software info. Edited images are a mixed bag: some editors preserve the original EXIF, others strip it, and a few add their own tags. After editing, check — don’t assume.
Also note: stripping EXIF doesn’t remove everything identifying. The image content itself (faces, license plates, reflections, backgrounds) can still give you away. Metadata removal is one layer; look at what’s in the frame too.
Make it a habit
The two-minute version of this entire article: before any photo leaves your device for public or semi-public viewing, run it through an EXIF stripper. Pair it with compression while you’re at it — stripped, optimized images are smaller, faster, and safer.
Related: How to convert HEIC to JPG without uploading your photos (convert first, then strip) · How to compress images without losing quality