A landlord posted a “flat for rent” photo straight from his phone. A stranger extracted the GPS coordinates, walked to the building, and knocked — while the flat sat empty awaiting tenants. The photo had done exactly what the landlord asked, plus one thing he never imagined: broadcasting his vacant property's location to the meter. Every phone photo embeds EXIF metadata — GPS, timestamps, device model. This guide shows what leaks, how to check in seconds, and how stripping works (plus the WhatsApp exception everyone misunderstands).
Part of the image optimization guide. Inspect any photo in the EXIF viewer (local FileReader — nothing uploads); strip by recompressing in the image compressor. Portal method in 100KB guide.
What your photo leaks (GPS, timestamps, device)
| Field | Example leak | Who cares |
|---|---|---|
| GPS coordinates | 28.6139°N, 77.2090°E — your home | Anyone downloading the file |
| Timestamp | Photo taken Tue 02:14 — proves routine | Insurers, disputants, stalkers |
| Device + software | iPhone 15, edited in Snapseed | Forensics, verification |
| Orientation flag | Rotated display vs stored pixels | Developers (layout bugs) |
Rental listings, marketplace sales, dating profiles, protest photos, whistleblower documents — any upload where location or timing matters deserves a 10-second EXIF check first. The landlord's photo carried all four fields.
Check in 10 seconds (local viewer method)
Open the EXIF viewer, drop the photo, read the table: coordinates with map link, timestamp, camera, dimensions, orientation. Because it uses FileReader locally, checking a sensitive photo is safe — the bytes never traverse the network (verify in DevTools if you are cautious; zero requests fire). Screenshots and downloaded memes typically carry no EXIF (already stripped upstream); fresh camera photos almost always do. Check before posting, not after — deletion after upload only removes future copies.
The WhatsApp myth (what it strips vs keeps)
“WhatsApp removes metadata, so I'm safe everywhere” — wrong in both directions. WhatsApp does strip EXIF on send (re-encoding images), which is why forwarded photos lose location. But email attachments, direct forum uploads, cloud links (Drive/Dropbox originals), listing sites and Bluetooth transfers preserve EXIF fully. The rule: assume every upload keeps metadata unless the platform documents stripping. Instagram strips on post but keeps it in stories drafts; Telegram's “send as file” preserves everything while quick-send compresses. When in doubt, strip yourself — takes seconds, costs nothing.
Strip method: recompress and verify
Re-saving through the image compressor drops EXIF while keeping pixels: the canvas pipeline carries image data only, no metadata segments. Procedure: view original (note GPS present) → compress at 80% → view output (GPS absent) → upload the output. For bulk listing shoots, batch all finals through one pass. Caveat: orientation flags also strip — if a photo relied on the flag to display upright, verify rotation after (rare, but check). Professionals handling source protection should additionally screenshot-and-recrop sensitive frames rather than trusting any single tool. Pair with resizing for portal uploads in one workflow.
General guidance only, not legal advice. For legally sensitive material, consult counsel about metadata obligations — some contexts require preserving originals.