Photo metadata: which EXIF fields actually give you away
A file named IMG_4821.jpg can carry a few hundred bytes of structured facts about where it was made,
when, and on what device. That is EXIF, and it lives inside the file rather than in its name, so nothing
visible changes when it is there — or after it is gone.
Most of EXIF is camera trivia. A few fields carry real information, one of them is a coordinate, and the trivia is what makes generic “photos leak your location” advice half wrong.
The fields that carry information
| Tag | Typical value | What it reveals |
|---|---|---|
GPSLatitude + GPSLatitudeRef | 37/1 47/1 19/100, N | Capture location |
GPSLongitude + GPSLongitudeRef | 122/1 25/1 41/100, W | Same point, east-west |
DateTimeOriginal | 2026:10:06 14:32:11 | When, to the second |
Make / Model | Canon / EOS R6 Mark II | Which device took it |
LensModel | RF24-105mm F4 L IS USM | Gear detail; proves ownership |
Artist | Your name | Often the only human name here |
Copyright | © 2026 Your Name | The field worth keeping |
Software | Adobe Lightroom 14.2 (Macintosh) | Toolchain, sometimes OS |
Orientation | 6 | “rotate 90° clockwise” |
MakerNote adds a vendor-private block, undocumented and different per brand, so a cleaner that edits
standard tags one at a time can leave it behind. No field here contains an address or an account
identifier; the exposure is narrower than the headlines — a coordinate and a clock reading, in one file.
How the coordinate gets built
GPSLatitude is not a decimal number. It is three unsigned rationals — degrees, minutes, seconds — and
the sign comes from a companion tag:
latitude = 37/1 47/1 19/100 -> 37 + 47/60 + 19/3600 = 37.788611
latitudeRef = "N" -> +37.788611
longitude = 122/1 25/1 41/100 -> 122.428056
longitudeRef = "W" -> -122.428056
Those hemisphere tags are load-bearing: a reader that ignores them returns a mirrored position on the other side of the world, and software with that bug has shipped. The precision is generous too. Six decimals is about a tenth of a metre; two still sit inside a kilometre box, which identifies a building.
The thumbnail is a second copy
EXIF normally carries a small preview, often near 160×120, in its own directory inside the same block. It is a fully decodable picture of the same scene, and it survives half-finished cleaning: a tool that blanks the tag values but leaves the thumbnail directory still ships a visible copy of the photo.
Screenshots, chat photos, camera originals
Whether a file has EXIF at all depends on what produced it, which is where blanket advice falls apart.
- Camera roll: full EXIF, GPS included when geotagging is on. Many phones geotag by default, and some Android skins offer a location toggle in the share sheet that applies to that share only.
- Screenshots: usually none, because there was no camera. macOS and iOS write PNG, and PNG carries a metadata block only if something deliberately writes one.
- Compressed by a messenger: the app decodes and re-encodes, so the original tags go with the resolution.
- Sent as a file or document: bytes copied unchanged, so every tag survives.
- Cloud library, downloaded as “original”: metadata preserved, since byte fidelity is the point.
The same person can have both a clean file and one that shows where they live. The pipeline decides.
Removing tags is not re-saving
Metadata sits in a segment between the JPEG header and the compressed image data, next to Comment, ICC
profiles and the thumbnail. Delete that segment and copy the image data verbatim, and the pixels are
bit-for-bit identical to the original: nothing was decoded, so nothing was degraded, and the size change
is only the removed block.
Re-encoding through an editor is a different operation. Pixels get decoded and re-quantised, so some
quality setting applies whether or not you picked one; export can resample to a new size, and the colour
profile may be dropped or baked in. Tags tend to be partly rewritten rather than cleared — the editor’s own
Software value, a fresh timestamp, an orientation either resolved into the pixels or left behind to be
applied a second time.
That is why “Save As” is not a reliable way to clean a photo: saving to a new file is an encode, and an encode costs quality while deciding metadata policy on your behalf.
Do not rely on the platform
Large social networks and messaging services re-compress uploads, and re-compression drops EXIF as a side effect, not as a privacy feature. Services with a download-as-original button keep it. Some channels strip location but retain camera details; some resize yet preserve a comment block. Behaviour also changes over time, and platforms rarely publish a metadata policy worth trusting. The only dependable test is to download the file from the post and read its tags.
What survives stripping
- The filename.
IMG_20261006_1432.jpgencodes a timestamp in a wayIMG_4821.jpgdoes not. Name the file something neutral yourself. - The picture’s own content. A view through your window, a mailbox with legible letters, a workplace badge, a licence plate. No tag removal touches these.
- Copies already shared. Cleaning your local file does nothing to versions cached on a CDN or saved by a recipient.
Before you send a photo to a stranger
- Read the tags. If
GPSLatitudeorGPSLongitudeis present at all, remove it. - Look for
Artist,Copyright, and aSoftwarevalue containing your username or machine name. - Check the embedded thumbnail, and confirm the cleaner dropped the whole block, not just the values.
- Decide about
DateTimeOriginal: on a listing or a delivery receipt a date is useful and harmless, but a second-accurate timestamp plus a coordinate is what to avoid. - Rename the file, then look at the frame for anything readable in the scene.
Step one is what everyone skips: tags stay invisible until something decodes them, and decoding them in the page you already have open keeps a private photo off someone else’s server.