Quick answer
To check if a photo contains hidden metadata, inspect the exact file you plan to share, not just the copy in your photo library. On iPhone, open the photo in Photos and swipe up or tap the Info button. On Mac, open it in Preview and use Tools > Show Inspector. On Windows, right-click the file, choose Properties, and open the Details tab. For a privacy check without uploading the file, drop it into a browser-based EXIF reader such as PhotoTools Remove EXIF.
The fields to look for first are GPSLatitude, GPSLongitude, GPSAltitude, DateTimeOriginal, Make, Model, Software, Orientation, and any creator, caption, keyword, copyright, or location fields added by editing software. If GPS coordinates are present, treat the photo as location-sensitive. If only camera settings are present, the risk is usually lower, but still depends on the context.
A good metadata check has 3 passes:
- Check the metadata fields.
- Check the visible pixels for private details.
- Clean a copy and re-check the cleaned file before sharing.
That last step is the one people skip. They clean one file, then accidentally send the original from Photos, iCloud, Google Photos, email, or a chat app.
What hidden photo metadata can include
Photo metadata is data stored in or alongside the image file. It does not appear in the picture itself, but software can read it. A normal phone photo can contain several kinds of metadata:
| Metadata type | What it can contain | Why it matters |
|---|---|---|
| EXIF | Camera make/model, capture time, orientation, exposure, aperture, ISO, focal length | Useful for photography, but can identify device and timing |
| GPS | Latitude, longitude, altitude, direction, GPS timestamp | Can reveal a home, school, workplace, hotel, clinic, or travel route |
| IPTC | Creator, copyright, caption, keywords, location, credit line | Useful for publishers and photographers; risky if it exposes names or internal labels |
| XMP | Editing software, workflow tags, rights fields, descriptions, custom metadata | Can reveal tools, project names, edits, or content-management history |
| MakerNotes | Proprietary camera or phone fields | Often hidden from simple viewers; useful for forensic or camera-specific analysis |
| Embedded thumbnail | A small preview image stored inside the file | Can be stale after editing; strip metadata if you do not need it |
EXIF is the word most people know, but it is only one slice of photo metadata. IPTC metadata is common in news, stock, and publishing workflows. XMP is widely used by Adobe and other creative tools to embed labels, descriptions, rights, and workflow data. A privacy check should look beyond the word "EXIF" and ask a simpler question: what does this file reveal?
A realistic example
A photo from a phone might show a coffee cup. The file can still say:
| Field | Example value | How to read it |
|---|---|---|
| GPSLatitude | 37.774900 |
Exact north/south coordinate |
| GPSLongitude | -122.419400 |
Exact east/west coordinate |
| GPSAltitude | 52 m |
Elevation, sometimes useful when combined with location |
| DateTimeOriginal | 2026:03:14 09:22:11 |
When the original image was generated |
| OffsetTimeOriginal | -07:00 |
Time zone offset, if the file includes it |
| Make | Apple |
Device maker |
| Model | iPhone 16 Pro |
Device model |
| Software | 18.3.1 |
OS or app that wrote the file |
| Orientation | Rotate 90 CW |
Why the photo may appear sideways in some apps |
| Creator / Copyright | Jane Example |
Sometimes intentionally useful, sometimes private |
| Keywords | client-x, unreleased, home-office |
Often added by DAM, stock, or editing workflows |
One field alone is not always dangerous. Together, fields tell a story: where the photo was taken, when it was taken, what device captured it, and what workflow touched it afterward.
The privacy triage table
Use this table when you are deciding whether to clean a file before sharing.
| Field or clue | Risk level | What to do |
|---|---|---|
| GPSLatitude and GPSLongitude | High | Strip before public posting, email, marketplace listings, forums, or client delivery |
| GPSAltitude, GPSTimeStamp, GPSImgDirection | High when paired with coordinates | Strip with GPS fields |
| DateTimeOriginal and OffsetTimeOriginal | Medium to high | Strip if timing reveals schedule, travel, school, medical, or workplace patterns |
| Make, Model, Software | Low to medium | Usually harmless, but strip for anonymous or sensitive sharing |
| Creator, Credit, Copyright | Depends | Keep for portfolio/rights use; strip if it reveals a private name or internal account |
| Caption, Description, Keywords | Medium | Check for client names, project codes, location words, or private labels |
| Orientation | Low | Mostly display-related, but explains sideways-photo problems |
| Embedded thumbnail | Medium in edited files | Strip if the photo was cropped, redacted, or edited before sharing |
| Filename | Medium | Rename if it contains names, project IDs, dates, addresses, or sequential evidence |
| Visible pixels | Often high | Metadata removal does not hide faces, documents, screens, reflections, signs, or map pins |
The key is context. A GPS tag on a public landmark photo may not matter. A GPS tag on a photo taken in your living room matters a lot.
Where to check metadata, by platform
| Platform | Fastest check | Best for | Limitation |
|---|---|---|---|
| iPhone Photos | Open photo, swipe up, or tap the Info button | Location, capture time, camera details | Friendly summary, not every tag |
| Mac Preview | Tools > Show Inspector, then EXIF/GPS tabs | Quick local check on JPEGs | May not show every IPTC/XMP/MakerNote field |
| Mac Finder | Get Info > More Info | Basic capture and camera fields | Partial summary |
| Windows | Right-click > Properties > Details | Basic EXIF and GPS on supported files | Can omit advanced fields or unsupported formats |
| PhotoTools | Drop file into /remove-exif | Local browser check for common EXIF/GPS fields and clean export | Not a forensic all-tag viewer |
| ExifTool | exiftool -a -G1 -s photo.jpg |
Complete technical audit across many metadata formats | Command-line tool |
If you only need to know "does this photo leak GPS?", the built-in tools or PhotoTools are enough. If you need to inspect every possible tag before legal, journalistic, archival, or client delivery work, use ExifTool or another dedicated desktop metadata tool.
Checking metadata on iPhone
Apple's Photos app can show saved photo and video metadata. Open the photo, swipe up, or tap the Info button. Depending on the file, you can see the device that captured it, the date and time, camera settings, file size, and location on a map.
For a quick privacy check:
- Open the photo in Photos.
- Swipe up or tap the Info button.
- Look for a map, location name, date/time, camera model, and file details.
- If location is present, decide whether that place is safe to share.
- If you share from the iOS share sheet, tap Options and turn off Location for that one share.
Two caveats matter. First, the share-sheet Location toggle applies to that sharing action; it does not clean the original file in your library. Second, not every upload path uses the share sheet. A web upload form, cloud file picker, or document attachment may send the original file.
Checking metadata on Mac
On macOS, Preview is the fastest built-in viewer.
- Open the photo in Preview.
- Choose Tools > Show Inspector, or press Cmd+I.
- Open the More Info panel.
- Check the EXIF, GPS, TIFF, and General tabs if they appear.
You can also right-click the file in Finder, choose Get Info, and expand More Info. Finder is useful for a quick look, but Preview usually shows more detail.
If you use the Photos app on Mac, open the image and use the info panel to check date, location, camera, and file information. As with iPhone, this is a readable summary, not a complete metadata dump.
Checking metadata on Windows
On Windows, right-click the image file, choose Properties, and open the Details tab. Look for camera make/model, date taken, dimensions, and GPS fields. If GPS is present, Windows may show latitude and longitude under a GPS section.
The Windows Details tab is useful but partial. It may not show MakerNotes, XMP, IPTC, embedded thumbnails, or metadata in less common formats. If the file is sensitive and the Details tab looks empty, do not assume the file is fully clean. Re-check with a dedicated metadata reader.
Checking metadata in a browser with PhotoTools
PhotoTools is useful when you want a local privacy check without uploading an identity photo, family photo, client image, or product photo to a server.
The workflow:
- Open Remove EXIF.
- Drop in the exact file you plan to share.
- Review the fields shown on the file card.
- Pay special attention to GPSLatitude, GPSLongitude, GPSAltitude, DateTimeOriginal, Make, Model, Software, Orientation, exposure, ISO, focal length, flash, and color-space fields.
- If GPS is present, PhotoTools flags it as a privacy warning.
- Click Strip & Download to export a clean copy.
- Clear the tool, then drop the clean copy back in.
- Confirm the sensitive fields are gone before uploading or sending.
PhotoTools currently focuses on common EXIF/GPS privacy fields rather than every possible metadata tag in a file. The clean export is created by drawing the image pixels to a fresh browser canvas and saving a new JPG or PNG, which drops the old metadata wrapper. That is enough for everyday sharing. For full forensic inspection of all metadata groups, use ExifTool.
JPG/JPEG and PNG are the safest formats for this workflow. HEIC files may inspect correctly in browsers that expose them as image files, but browser support varies. If a HEIC file does not load, export a JPG copy from Photos first, then inspect and clean that copy.
Checking metadata with ExifTool
If you are comfortable with the command line, ExifTool is the most complete way to inspect image metadata.
Use:
exiftool -a -G1 -s photo.jpg
What the flags do:
-ashows duplicate tags instead of hiding them.-G1shows the metadata group, such as EXIF, GPS, XMP, IPTC, or MakerNotes.-sprints short tag names that are easier to scan.
This is useful when a built-in viewer says nothing, but you still want to check IPTC, XMP, thumbnails, maker notes, or editing history. It is also useful for comparing the original and cleaned file side by side.
What to look for first
When you open a metadata viewer, do not try to read every technical field from top to bottom. Start with the fields that change the sharing decision.
GPS fields
Look for:
- GPSLatitude
- GPSLongitude
- latitude
- longitude
- GPSAltitude
- GPSTimeStamp
- GPSImgDirection
Latitude and longitude are the big ones. Paste them into a map and they can point to the capture location. Altitude, direction, and GPS time add context.
Time fields
Look for:
- DateTimeOriginal
- CreateDate
- DateTimeDigitized
- OffsetTimeOriginal
- SubSecTimeOriginal
Capture time can reveal routines. A batch of photos can show when someone leaves home, arrives at work, visits a school, or travels.
Device and software fields
Look for:
- Make
- Model
- LensModel
- Software
- ProcessingSoftware
These are usually lower risk than GPS, but they can identify the device or app used. For anonymous posting, public whistleblowing, sensitive client work, or marketplace listings, strip them.
IPTC and XMP fields
Look for:
- Creator
- Copyright
- Credit
- Caption
- Description
- Keywords
- Location
- City
- Country
- Source
- CreatorTool
These fields are not always bad. Photographers may intentionally keep copyright and creator fields. The risk is accidental context: client names, internal project codes, unreleased product labels, or location words you did not mean to publish.
What to do after you find metadata
If the photo is only going into your personal archive, you may want to keep metadata. EXIF helps with search, photo organization, camera settings, and memory. Do not remove it from your only original unless you mean to.
If the photo is leaving your control, make a clean copy:
- Keep the original in your private archive.
- Strip metadata from a copy.
- Rename the copy if the filename exposes context.
- Re-check the clean copy.
- Upload or send only the clean copy.
For iPhone one-off sharing, Apple's share sheet can turn off Location before sharing. That is convenient, but it is not the same as creating a reusable clean file. For email, forums, cloud links, bug reports, marketplace listings, client uploads, and original-quality chat attachments, clean the file yourself before it leaves the device.
When "no metadata found" is not enough
A metadata reader can only tell you what it can read from that file. A clean result is good news, but it is not the whole privacy review.
Check these too:
- The visible image: faces, documents, mail, license plates, whiteboards, screens, browser tabs, map pins, reflections, school names, and street signs.
- The filename:
client-launch-bedroom-final.jpgsays a lot even with no EXIF. - The exact file: a cloud service may export a new copy with different metadata.
- Live Photos and videos: cleaning the still image does not clean the paired video.
- Sidecar files: raw workflows may store metadata in
.xmpsidecars. - Platform data: a social app may remove public EXIF but still receive the original upload and collect its own location or account data.
- Manual location tags: a caption, check-in, album title, or map sticker can reveal location even after GPS is stripped.
This is why the best habit is simple: inspect, clean, re-check, then share.