
Photo EXIF and GPS Privacy: What to Check Before Sharing
A photo can contain more than the visible image: location coordinates, capture time, camera and lens details, software information, or an author name. Which fields are present depends on the device, app, settings, and editing history.
CIPA lists Exif 3.1 in its 2026 standards. This guide uses the metadata specification and platform guidance to explain what to check before sharing. It does not assume that every photo contains every tag, or that every sharing service handles metadata the same way.
Japanese original published: 2026-04-22
Exif is structured metadata, not the visible image
Exif, short for Exchangeable image file format, specifies metadata associated with image files. It originated with JEIDA in 1995; CIPA and JEITA now work jointly on the specification. JEIDA should not be described as an earlier name for CIPA.
Its structure builds on TIFF image file directories, or IFDs: tables holding tags and values. In a JPEG, Exif data is carried in an APP1 segment. The directories have different roles:
- 0th IFD: main-image properties such as manufacturer, model, software, resolution, and orientation.
- Exif IFD: capture information such as exposure, aperture, sensitivity, focal length, white balance, and flash.
- GPS IFD: location-related values and reference tags.
- Interoperability IFD: interoperability information.
- 1st IFD: an embedded thumbnail, when present.
Finding one familiar field does not mean a reader has enumerated every kind of metadata in the file.
GPS tag precision is not positioning accuracy
Granting location permission does not guarantee the same tags in every photo. The camera app, positioning result, and later processing all matter. Read values together with their reference tags:
Scroll horizontally if the table does not fit.
| Tag | Interpretation to check |
|---|---|
| GPSLatitude / GPSLongitude | Rational degree, minute, and second values together with N/S and E/W references |
| GPSAltitude | The altitude value and GPSAltitudeRef |
| GPSTimeStamp / GPSDateStamp | UTC time and date, distinct from capture-time tags |
| GPSImgDirection | GPSImgDirectionRef distinguishes true north from magnetic north |
| GPSSpeed | GPSSpeedRef distinguishes km/h, mph, and knots |
Many displayed decimal places do not prove an equally accurate measurement. The distance corresponding to a degree of longitude also varies with latitude. Device and reception conditions affect uncertainty; a coordinate does not always identify an exact address. Nevertheless, coordinates combined with the visible scene can help someone infer a building or an area you visit.
Location can be inferred through more than Exif
Other clues include location information managed by a photo service, place names in a caption, house signs, shop fronts, and recognizable scenery. Repeated places and times across several photos can suggest a pattern of activity. Repeated coordinates alone do not establish that a location is someone’s home.
Google Photos explicitly notes that landmarks can reveal a location even when location information is not shared. Do not treat every report of a person being located from a photo as proof of an Exif leak. Removing metadata and reviewing the visible image address different sources of information.
Separate camera permissions from sharing controls
On iPhone
Apple’s guidance describes Settings → Privacy & Security → Location Services → Camera → Never to stop the Camera app from using location. Labels can vary with OS version and interface language. Changing this permission does not remove location information from photos already taken.
In Photos, adjusting a photo’s location and turning off Location in the share sheet’s Options are separate operations. The sharing option applies to that share; it is not a bulk removal of every metadata field from all originals on the device.
On Android
Check both the camera app’s location-saving setting and its operating-system location permission. Names and locations vary by manufacturer and camera app, so there is no single “standard Android camera” sequence that covers every device. Take a new test photo after a change and inspect the saved file.
The sharing route changes what needs checking
Scroll horizontally if the table does not fit.
| Route | What to check |
|---|---|
| Ordinary social-media image post | Processing may depend on the service, settings, and posting method |
| Email attachment | Inspect the actual attachment; it may be the original file |
| Cloud or file sharing | Inspect the downloadable file, not only the preview |
| Blog, CMS, or forum | Check the file actually delivered after processing |
| Messaging app | Distinguish photo sending from original-file or document sending |
Do not assume a service always strips location metadata. Check the local copy before sharing and, where appropriate, the received or delivered file afterward.
Google Photos’ in-service location-sharing settings do not necessarily govern a file downloaded and then sent by email or another service. A location hidden in an app’s interface is not evidence that the downloadable file contains no location metadata.
HEIC and HEIF need compatible readers
On supported Apple devices, the High Efficiency capture setting can use HEIF for photos, commonly stored as HEIC when using HEVC image coding. HEIF is a container format specified in ISO/IEC 23008-12; it should not be confused with the codec itself.
These files can carry Exif or XMP metadata. A reader without appropriate support may fail to display information that is present. An empty metadata panel is therefore not enough to prove absence.
Conversion to JPEG or PNG can preserve or remove metadata depending on the conversion path. Reinspect the output rather than assume that a new image format means the private information is gone.
A practical workflow for a sharing copy
- Before capture: disable location saving if it is not needed. Handle existing photos separately.
- Inspect a copy: use a reader that supports the format. Consider Exif, XMP/IPTC, thumbnails, and associated sidecar files rather than only one GPS field.
- Remove what is unnecessary: process the sharing copy, reopen it, and inspect it again. Removing orientation or color-management information can also affect appearance.
- Review the pixels: look for names, screens, reflections, and other identifying details. Crop or cover sensitive areas with a sufficiently opaque fill where necessary; blur alone is not a guarantee of concealment.
- Check delivery: use the intended sharing mode and, where possible, inspect the received or publicly delivered file.
For any metadata tool, read its supported formats and removal scope. Neither resizing nor HEIC conversion alone proves that every metadata field has been removed. Keep the original separate from the copy intended for publication.
Key points
- Exif 3.1 appears in CIPA’s 2026 standards, but individual photos contain different subsets of metadata.
- Distinguish GPS representation from measurement accuracy, and read reference tags and units.
- Camera permissions, editing existing photos, and share-time exclusion are different controls.
- Check other metadata containers and the visible image as well as Exif.
- Use a sharing copy and inspect the actual result after processing and delivery.
References and sources
Editorial note
This article was prepared with AI assistance and reviewed by an editor before publication. It may still contain factual errors, interpretation mistakes, or outdated information. Check the cited primary sources or official documentation before making an important decision.

