Every photo you take on a smartphone contains far more than just the image. Embedded invisibly in the file is a block of metadata that can include the exact GPS coordinates where the photo was taken, the make and model of your device, the date and time down to the second, and in some cases the serial number of your camera. This metadata is called EXIF data, and most people have no idea it's there.
EXIF stands for Exchangeable Image File Format. It's a standard for storing metadata inside image files — primarily JPG and TIFF — that was established in the 1990s and is now baked into virtually every digital camera and smartphone on the market. When you take a photo, the camera automatically records a snapshot of technical information alongside the image itself.
That information can include:
The GPS data is the most sensitive piece for most people. If location services are enabled on your phone when you take a photo, the exact coordinates are embedded in the file. Share that photo publicly and you've shared your location — your home address, your workplace, your child's school, wherever you happened to be.
The issue isn't that EXIF data is secret — anyone who opens your image file in the right software can read it. The issue is that most people don't know it's there and have never thought about what they're sharing when they post photos online.
For most people the stakes aren't that dramatic, but the privacy implications are real. Posting a photo taken at your home to a public forum with GPS data intact is essentially posting your home address alongside it — it just takes slightly more effort to extract than a caption that says "outside my house."
Beyond location, device information has its own implications. Knowing exactly which phone model and software version someone uses is useful context for targeted phishing. Timestamps can contradict claimed alibis. Camera serial numbers can link multiple "anonymous" images to the same device.
Most major platforms do strip EXIF data when you upload — Facebook, Instagram, Twitter/X, and TikTok all remove metadata as part of their image processing pipeline. This is one of the few cases where platforms are actually doing something privacy-protective, even if it's not the primary reason they do it (smaller files are faster to serve).
The platforms where you need to be more careful are file-sharing services that preserve files as-is: Dropbox, Google Drive, email attachments, direct file transfers. If you email someone a photo or share it via a link to the original file, the EXIF data goes with it untouched.
On a Mac: open the photo in Preview, go to Tools → Show Inspector → the GPS and EXIF tabs show everything.
On Windows: right-click the file → Properties → Details tab. All EXIF fields are listed there.
On iPhone: open the photo in the Photos app, swipe up, and you'll see location and camera information below the image.
Online: several free tools let you upload a photo and view its full EXIF data. Just be aware that you're uploading the file to do so.
Not necessarily. EXIF data has legitimate uses — photographers use it to track camera settings across a shoot, location data lets Photos apps organize images by place, and timestamps help keep libraries in order. The question is whether you want that information to travel with the file when you share it.
A reasonable rule: keep EXIF data in your personal photo library where it's useful for organization, but strip it before sharing images publicly or sending files to people you don't know well. The GPS data in particular is worth removing from anything that might be shared beyond your immediate circle.
Run any photo through ConvertoFile's Image Converter and the output file contains pixel data only — no EXIF, no GPS, no device info. Nothing is uploaded anywhere.
Open Image Converter