MetaWipe
← All posts

Check Photo Metadata Before Sharing: The Complete Checklist

A practical pre-sharing checklist for photo metadata — which platforms strip EXIF for you, which don't, and what to verify before you hit post.

Most people have a vague sense that photos "contain data" and an equally vague trust that "the platform handles it." Both are half true, and the gap between them is where leaks happen. Instagram will strip your GPS coordinates; the same photo attached to an email keeps them. WhatsApp cleans a photo sent normally; sent "as document," it arrives with everything intact.

This is the checklist to run before any photo leaves your device — plus an honest map of which platforms actually strip metadata for you.

Which platforms strip metadata — and which don't

The public-facing social networks re-encode uploaded images, which removes EXIF, GPS, IPTC, and XMP from what other users can download:

Strip metadata from public posts:

  • X (Twitter) — images are re-processed; EXIF is removed from served copies.
  • Instagram — strips metadata on upload (though the app may read GPS first for its own location features).
  • Facebook — same pattern: re-encoded, metadata removed from what's served.
  • WhatsApp / Telegram, normal photo send — images are compressed and metadata is stripped.

Do NOT strip metadata:

  • Email attachments — the file is transmitted exactly as attached, GPS and all.
  • WhatsApp / Telegram "send as document/file" — the whole point of that mode is byte-for-byte delivery. Original metadata included.
  • Discord file uploads — files are served as uploaded; recipients get the original metadata.
  • Cloud drives and link sharing (Google Drive, Dropbox, OneDrive, iCloud links) — you're sharing the original file. What's in it goes with it.
  • Slack, forums, marketplaces, your own website — behavior varies and often preserves everything. Assume nothing is stripped.

Two important caveats even for the "safe" platforms. First, the platform receives the metadata before stripping it — removal protects you from other users, not from the platform itself. Second, policies change and vary by upload path (mobile app vs. web vs. API). Stripping metadata yourself is the only version of this you control.

The pre-sharing checklist

Run through this before posting anything you care about. It takes under a minute once it's habit.

1. Check what's actually in the file

Don't guess — look. Open the photo in a metadata viewer and scan for:

  • GPS coordinates (the deal-breaker: home, school, workplace)
  • Capture date and time (contradicts your story? reveals you're on vacation?)
  • Device make, model, serial numbers
  • Your name in Artist, Creator, or Copyright fields
  • Embedded thumbnail that may show a pre-crop version

MetaWipe shows all of this in your browser without uploading the file, which matters: inspecting a sensitive photo shouldn't require sending it to a server.

2. Check the pixels too

Metadata isn't the only leak. Before sharing, glance at the image itself for:

  • Street signs, house numbers, storefronts that reveal location
  • Reflections in windows, mirrors, sunglasses, and screens
  • Documents, envelopes, packages with printed addresses
  • Screens showing open tabs, notifications, or contact names
  • Distinctive landmarks visible from your window

No metadata tool fixes these — this is a human review step.

3. Consider edited images extra carefully

If you cropped, blurred, or redacted the image, verify the cleaned version doesn't carry the original along:

  • The EXIF thumbnail may still show the uncropped scene.
  • XMP edit history can record what software did to the file.
  • Samsung motion photos embed a video clip after the JPEG data that survives many edits.

The reliable fix is stripping all metadata after the final edit, as the last step before sharing.

4. Match the action to the channel

  • Posting to X, Instagram, Facebook: platform stripping covers other users, but strip first anyway if you don't want the platform itself reading your GPS trail.
  • Email, Discord, cloud links, "send as file": always strip. These channels deliver originals.
  • Selling on marketplaces: strip. You're sending photos taken inside your home to strangers.
  • Anonymous or pseudonymous accounts: strip everything, every time, including creator fields and serial numbers that can link accounts together.

5. Strip, then verify

Remove the metadata, then re-open the cleaned file in a viewer and confirm the sensitive fields are gone. Trust, but verify — some tools remove EXIF while leaving XMP duplicates of the same GPS data behind.

Special cases worth knowing

Screenshots contain no camera EXIF, but they do record device model and timestamp, and screenshotting costs image quality. Fine for casual use; not a substitute for proper stripping when quality matters.

Kids' photos deserve the strictest treatment. Geotagged photos of children establish where they live, study, and play. Strip everything, always, and think twice about the channel.

Batch sharing (an album for family, a folder for a client) is where manual per-file methods break down. This is the case for a batch-capable tool: MetaWipe processes multiple photos at once, entirely client-side, so cleaning a 200-photo album doesn't mean uploading 200 originals anywhere.

Photos you received from others carry their metadata. If you forward or repost them, you may be leaking someone else's location. Extend the same courtesy you'd want.

The one-line policy

If you can't remember the details, remember this: assume nothing strips metadata for you, and clean every photo before it leaves your device. Stripping metadata never hurts a photo — the pixels are untouched — so the safe default costs you nothing.

FAQ

Does WhatsApp remove metadata from photos?

Photos sent the normal way are compressed and stripped of metadata. Photos sent as documents/files are delivered unchanged, with GPS, timestamps, and all other metadata intact. The same distinction applies to Telegram.

Do Instagram and Facebook remove EXIF data?

Yes — images served to other users are re-encoded without the original metadata. But the platforms receive your original file first, so metadata can still inform their own systems. Strip before uploading if that matters to you.

How do I check if a photo still has GPS data?

On Windows, right-click → Properties → Details and look for GPS entries. On Mac, open in Preview → Tools → Show Inspector. Or drop the file into a client-side viewer like MetaWipe, which lists every field — including XMP duplicates that OS dialogs miss — without uploading the photo.