Privacy · September 21, 2026 · PiccTools Team
What Is EXIF Data and Why Should You Remove It?
Every photo you take with a digital camera or smartphone contains a hidden dossier. It is called EXIF — Exchangeable Image File Format metadata — and while it was designed to help photographers, it has become one of the most overlooked privacy leaks on the internet. Here is what is actually inside your JPEGs, who can see it, and how to remove it before you share.
What EXIF records
Open almost any photo straight from a camera and the EXIF block typically contains the camera make and model (and for phones, the exact device), the date and time to the second, exposure settings — ISO, shutter speed, aperture, focal length — whether the flash fired, the software that last touched the file, and an embedded thumbnail of the image. Most consequentially, if location services were enabled when the photo was taken, it stores GPS coordinates accurate to a few meters, sometimes with altitude.
That combination is richer than most people expect. A single photo can answer: what device you own, when you were somewhere, and exactly where “somewhere” was.
Why it became a privacy problem
The risks are not hypothetical. Journalists have located people from photos posted online. Burglars have identified when homes are empty from holiday snaps with timestamps. Domestic-abuse advocates routinely warn survivors that a photo shared from home can reveal a safe address. Even in mundane contexts — selling a phone on a marketplace, posting in a forum — EXIF quietly broadcasts your device and habits to strangers.
There is a subtler issue too: consistency. A photo claimed to be from last year but timestamped last Tuesday, or supposedly shot on a “vintage” camera but tagged with a modern phone model, tells its own story. Metadata is evidence, and it persists unless deliberately removed. Even casual inspection of a few of your own files tends to make this concrete very quickly.
Who strips it for you (and who does not)
The good news: most major social networks — Facebook, Instagram, Twitter/X, WhatsApp — strip EXIF data when you upload. The bad news: that protection ends at their walls. Email attachments, forum uploads, marketplace listings, cloud-shared links, Discord, Telegram (when sent as a file), and most self-hosted galleries pass the original file through untouched, metadata and all. If you do not control the pipeline, assume the metadata survives.
There is also an irony to avoid: many “EXIF remover” websites ask you to upload your photo to their server — handing the very file you are trying to protect to a third party, along with whatever their logging policy fails to mention.
How to check what your photos carry
Before removing anything, it is worth looking. Our EXIF Viewer parses JPEG metadata entirely in your browser — the file never leaves your device — and shows the camera make and model, date, ISO, exposure time, aperture, focal length, orientation and editing software. If a GPS block is present, it flags that prominently. It is a five-second audit that is often an eye-opener the first time you run it on your own photos.
How to remove EXIF data properly
There are three reliable approaches:
- Re-encode through a canvas or editor. Re-saving the pixels into a fresh file discards all metadata blocks by construction — EXIF, thumbnails, maker notes and XMP all vanish. This is exactly what the “Download with metadata stripped” button in our tool does, locally, in one click.
- Turn off location tagging at the source. Both iOS and Android let you disable geotagging in the camera settings. This prevents GPS data from being recorded in the first place — the cleanest solution for the future, though it does nothing for your existing library.
- Use operating-system tools. Windows Explorer can remove properties via right-click → Properties → Details; macOS Preview can export without metadata. Workable, but tedious for batches.
Screenshots and messaging: the EXIF you create yourself
Screenshots usually carry little classic EXIF, but messaging apps add their own wrinkles. Photos sent “as documents” rather than as compressed images often retain full metadata. Cloud albums shared by link typically serve the original file, metadata included. And when you forward a photo through several apps, each may strip or preserve data differently, so you can never assume what the final recipient sees. The habit that covers every case is simple: before a photo leaves your hands for a public or semi-public place, run it through a strip step yourself. It takes seconds, works offline, and makes the question of what each platform preserves irrelevant.
When to keep EXIF
Metadata is not the enemy — uncontrolled sharing is. Photographers legitimately rely on EXIF to review their settings, organize libraries by date, and prove authorship. The sensible habit is a two-tier one: keep your originals intact in your own storage, and strip a copy at the moment you share it publicly. That takes one extra click and removes a class of risk you never have to think about again.