For most people, embedded photo metadata is a minor privacy detail. For a source sending a photo to a journalist, or a journalist handling material from a source, it can be the difference between anonymity and exposure — so it's worth treating deliberately rather than assuming it's fine.
What's actually at risk
- GPS coordinates — can pinpoint exactly where a photo was taken, potentially identifying a source's location
- Timestamp — down to the second, which can be cross-referenced against other logs, access records, or public events to narrow down who took a photo and when
- Device and camera details — a serial number or consistent device fingerprint across multiple images can link separate submissions back to the same physical device, and by extension the same person
- Thumbnail remnants — some files retain an embedded preview generated at an earlier editing stage, occasionally showing an older or uncropped version of the image
Don't assume your messaging app handles it
Some apps strip metadata automatically when you send an image as a "photo" through their normal media flow — but the same app may leave metadata fully intact if the same file is sent as a generic "file" or "document" attachment instead. This distinction is easy to miss and changes between app versions, so it's not something to rely on without checking the specific app and method you're actually using.
A before-you-send checklist
- View the file's metadata first, so you know exactly what you'd be sending
- Strip it locally, on a device you control, rather than trusting an online tool you haven't verified keeps files private
- Re-check the stripped copy afterward — confirm the fields are actually gone, not just visually similar
- Apply this to every photo in a batch, not just the one that seems most sensitive
Metadata isn't the whole picture
Stripping metadata addresses the hidden data inside a file. It says nothing about what's visible in the photo itself — reflections, background details, distinguishing features — which is a separate risk that needs its own review.
A tool built around this
AiEraser processes JPEG, PNG, and WebP files entirely in your browser — the file is never uploaded anywhere — so you can check and strip metadata without having to trust a third-party server with sensitive material.