Short answer
A phone photograph may contain coordinates, date, time, device model and editing information in its file metadata. The visible image can also reveal a house number, landmark, school uniform, vehicle plate, parcel label, computer screen, weather or routine. A sharing platform may remove some metadata, but you should not assume that every transmission method does so. The real exposure is not only whether a file contains GPS. File information, visual clues, captions and patterns across several photographs can be combined.
A photograph has three information layers
The first layer is the image that a person can see. The second is file metadata, which may include time, orientation, device, dimensions and coordinates. The third is the publication context: account identity, caption, posting time, album order, comments and audience. A privacy check that concentrates on only one layer can miss the other two.
Apple explains that when the Camera app has location permission, an iPhone can use cellular, Wi-Fi, GPS and Bluetooth information to determine the place of capture and embed coordinates in the photograph or video. A recipient of a file containing that metadata may be able to learn the location. Apple provides controls for removing an existing location or disabling it during sharing. Apple: Manage location metadata in Photos
Phones, cameras, file formats and sharing routes do not all behave identically. A social network may recompress an image and strip certain EXIF fields, while email, cloud links, AirDrop or an “original quality” option may preserve more information. Test the actual path being used rather than relying on an old assumption about a platform.
Why coordinates can be more sensitive than a place name
The location of a photograph taken at a famous tourist attraction is usually obvious, so GPS adds little. More sensitive examples include a home, temporary refuge, child's activity, clinic, workplace or regular route. Precise coordinates can narrow “somewhere in a Sydney suburb” to one building and “a child plays sport” to a recurring weekly location.
One image may not create an evident danger, while a sequence establishes a pattern. Morning photographs from one point, evening images elsewhere and a repeated weekend destination can reveal home, work, commute and likely absence. Digital privacy often depends less on the isolated data point than on the ability to combine records over time.
A place can be inferred without GPS
House numbers, street signs, business names, bus-stop identifiers, skylines, mountain profiles and views through a window can help locate an image. Indoors, a parcel, school notice, prescription label, staff badge or meeting invitation on a computer may display an address or organisation. Mirrors, windows, polished metal and television screens can reflect information outside the intended composition.
AI image recognition and large map collections can make inference more efficient, but sophisticated software is not always required. An acquaintance may recognise a balcony view, pet area or regular café immediately. For people facing stalking, family violence or another elevated personal-safety risk, inspecting the pixels matters as much as inspecting metadata.
Time information amplifies location exposure
A capture time may indicate when someone is at home, leaves for work, collects a child or begins a journey. A “live” holiday post can imply that a residence is empty. Even if a platform does not expose the exact capture time, album order, shadows, weather and a real-time caption can provide equivalent clues.
Delaying travel posts therefore adds a protection that GPS removal alone does not. Around family routines, valuable property, keys, vehicles and extended trips, avoid captions that turn an otherwise ambiguous photograph into a precise schedule.
My assessment: the problem is unintended combination, not metadata in isolation
From a systems perspective, “where this was taken” is not one fact stored in one field. It is distributed across coordinates, pixels, text, account relationships and timing. Disabling Camera location removes one high-precision source but cannot remove spatial context from the image. Cropping a house number does not remove coordinates from the file.
The useful goal is not abstract purity in which every piece of metadata is always destroyed. It is to understand the recipient and consequence. An original sent to trusted family, a damage photograph sent to a repairer, a family image posted publicly and accident evidence supplied to an insurer have different information needs. Privacy controls should fit the purpose rather than becoming a mechanical rule to delete everything or retain everything.
A practical pre-sharing review
Open the information panel in the photo application and inspect location and capture time. If location is unnecessary, use the system's “No location”, “Adjust location” or sharing control. When an option says “original”, “all photo data” or something similar, assume it may preserve more metadata until verified. Apple's iPhone guide notes that sharing may include associated metadata such as date, time, location, device and captions. Apple: Share photos and videos on iPhone
Then inspect corners, background, reflections and text. Crop or cover addresses, number plates, QR codes, barcodes, identity documents, children's names, school symbols and screen notifications where appropriate. Ensure redaction is flattened into the exported image. A removable editing layer can leave the underlying original or edit history accessible.
Finally, use the intended sharing method to send the file to a test account or second device, download it and inspect the result. A real test can show whether the platform stripped metadata, sent the original, or created a link exposing more of an album than expected.
Is a screenshot safer?
A screenshot normally does not inherit the original photograph's GPS EXIF fields and can be a quick way to reduce that particular exposure. It creates its own time and device context, lowers quality, and may capture status bars, notifications, gallery interfaces, filenames or other information. It is not automatic anonymisation.
Screenshots may also destroy information that needs to remain intact for evidence, insurance, journalism or technical analysis. Do not remove metadata from material with legal or evidentiary value without understanding the consequence. Privacy and evidence integrity can conflict; preserving the original separately while creating a reduced-information sharing copy is often the better design.
One-minute checklist
- Does the information panel show precise location and capture time?
- Will this sharing path send the original or “all photo data”?
- Does the image show an address, sign, school, plate, label or screen?
- Is sensitive information visible in glass, mirrors or polished surfaces?
- Do the caption and publication time reveal a live location or absence?
- Does an album link expose more than the selected image?
- Must an untouched original be retained as evidence?
- Has the received file been inspected on a second device?
Conclusion
Photographic location risk comes from the combination of coordinates, visible content and publication context. Removing GPS or EXIF is valuable but incomplete. A more durable habit is to decide what the recipient needs, inspect the final file and background, and treat public posting as a record that can be combined over time rather than as one isolated picture.
Related reading
- What Information Can a Screenshot Accidentally Reveal?
- What Does It Mean When an App Requests Photos, Contacts or Microphone Access?
Continue reading: All articles in How Digital Life Actually Works
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.