File Formats File Formatsmetadata
Journal Entry

That Vacation Photo You Just Posted Probably Has Your Home Address in It

How Phone Cameras Hide Location Data in EXIF Metadata

Photo by Faz Islam on Unsplash

Every JPEG and HEIF file that leaves a smartphone camera carries a data section most people never see. Buried inside the file, in a block the image-viewing software deliberately keeps out of frame, sits a record of exactly where the shutter opened — latitude, longitude, sometimes altitude, and a timestamp accurate to the second. The photo looks like a photo. The EXIF block reads like a GPS log.

This isn’t a bug, and it isn’t new. It’s a deliberate feature of how the Exchangeable Image File Format specification handles location data, and understanding the mechanism — rather than just knowing vaguely that “metadata exists” — changes how you think about which photos you share and where.

What EXIF Actually Is, and Where Location Data Lives Inside It

EXIF is a container standard, not a compression format. When your phone takes a picture, the camera subsystem writes the raw sensor output, then an image encoder (HEIC or JPEG, most commonly) packages that pixel data together with a structured metadata block. That block has defined fields: shutter speed, aperture, ISO, white balance, focal length, device make and model, software version, and — when location services are enabled — a GPSInfo sub-directory.

The GPSInfo sub-directory is a nested structure inside the main EXIF IFD (Image File Directory). It stores coordinates using degrees, minutes, and decimal seconds in separate rational-number fields, along with a hemisphere indicator (N/S and E/W). A separate field records GPS altitude in meters above sea level, using a reference indicator to distinguish above from below sea level. There are also fields for GPS timestamp (UTC, stored independently of the camera’s local clock), GPS processing method (which describes the positioning technology used — satellite, network, Wi-Fi triangulation, or a combination), and in some implementations, GPS speed and heading direction.

The data is structured, machine-readable, and precise enough that a coordinate pair from a GPSInfo block can be dropped directly into a mapping application. Decimal-degree conversion from the stored rational format is straightforward arithmetic, which is why any number of EXIF-reading tools — including browser-based ones — can parse it instantly.

Why Your Phone Records This by Default

Modern smartphones use assisted GPS (A-GPS), which combines satellite positioning with cell tower data and known Wi-Fi access point locations to produce a fix far faster than satellite alone. That fix is available within seconds of opening the camera app, which means the phone has accurate coordinates ready to embed before most users have composed their shot.

Camera applications on both major mobile platforms embed GPS coordinates by default when location services are enabled for the camera app. The rationale is entirely practical: geotagged photos can be sorted on a map, matched to a travel itinerary, or used to identify where a specific landscape was photographed. Photo library software has offered map views for years precisely because the data is there.

What the default configuration doesn’t do is remind you that the same coordinate will travel with the image when you share it. When the shot is your back garden, your front porch, or the window of your apartment, the GPS record is effectively your home address.

The Specific Risk When Images Are Shared

The concern compounds in a specific way that’s worth spelling out clearly. Most major social platforms strip EXIF metadata from images on upload — they do this partly to save storage, partly because they harvest that location data separately and don’t need to pass it on to viewers. But “most” and “by default” are doing a lot of work in that sentence.

Direct file sharing — via email attachment, AirDrop, cloud storage links, messaging apps that preserve original file quality — typically carries the full EXIF block intact. If you send the original JPEG or HEIF file to anyone, or post it to a platform that doesn’t strip metadata (and this varies by platform, by upload path, and sometimes by whether you’re using an app versus a web interface), the coordinates go with it.

The practical exposure pattern tends to be: images shared in original quality, possibly years before anyone thought to check what they contained. The metadata is persistent. A photo taken three years ago at your previous address still contains that address in machine-readable form if the original file has been kept.

We’ve covered the downstream consequences of this in more detail in our article on scammers using AI to pinpoint photo locations from metadata — the short version is that the barrier to extracting and acting on EXIF location data has dropped considerably as tools for parsing and cross-referencing it have become more accessible.

How to Control What Gets Embedded

The cleanest intervention is upstream: preventing the coordinate from being written in the first place. Both iOS and Android allow you to revoke location access for the camera application specifically, rather than disabling GPS system-wide. With location denied, the GPSInfo sub-directory simply isn’t populated — no data to strip later.

If you want geotagging for your personal archive but not for shared files, the workflow involves a second step before any file leaves your device:

  1. Check whether the destination strips metadata automatically. Don’t assume — this changes across platform versions and upload methods.
  2. Use the platform’s native share sheet or export option if it offers an option to remove location before sharing. iOS’s built-in share sheet has offered this as an optional step for several generations of the OS.
  3. Strip metadata manually before sharing original files. A dedicated EXIF editor can clear the GPSInfo block without touching the pixel data or other metadata fields. The file size change is negligible — GPS metadata is measured in bytes against a JPEG that may be several megabytes.
  4. Verify the result by inspecting the exported file’s EXIF before it goes anywhere. On a Mac, Get Info → More Info shows GPS fields if present. On Windows, right-click → Properties → Details does the same. A browser-based EXIF viewer will also surface the full IFD structure.

One detail worth knowing: some third-party export workflows (including certain editing apps that process and re-export files) copy EXIF blocks from the original to the output automatically, which means a stripped-and-re-edited version of a photo can have location data reintroduced if the app pulls metadata from the source. Check the output, not just the step where you thought you removed it.

A Note on HEIF and Whether the Format Changes Anything

HEIF — the container format increasingly used as the default on recent smartphones — stores EXIF in much the same way as JPEG, in a metadata box within the file structure. The GPS fields are identical in meaning, and any tool that can read HEIF metadata will find location data in the same places. Switching between JPEG and HEIF doesn’t improve or worsen your exposure to this issue. Our File Formats coverage addresses the technical differences between these containers in other contexts, but for metadata behavior specifically, the EXIF structure is consistent enough across both that the same controls and the same stripping tools apply.

The format specification allows for metadata to be stored in other boxes within an HEIF file (XMP, for instance, can also carry location data), so a thorough strip should address all metadata containers, not just the EXIF block.

What to Actually Do Before Sharing Original Files

The actionable step here is simple but requires making it a deliberate habit rather than an afterthought: treat the original, unmodified file from your phone as a file that contains your location until you’ve verified otherwise. For personal archiving, geotagging is valuable and worth preserving. For anything leaving your control — especially original-quality shares — inspect the EXIF before it goes.

If you share photos via email or direct file transfer regularly, consider setting a recurring check: open one of your sent originals in an EXIF viewer and confirm what GPS data, if any, is present. The field names to look for are GPSLatitude, GPSLongitude, GPSAltitude, and GPSDateStamp. If they’re populated, the coordinate went with the file.

More File Formats material is indexed in the Journal and on the File Formats page.