The Photo You Just Posted Knows Where You Live

The Photo You Just Posted Knows Where You Live

August 2, 2026 · Updated August 2, 2026

In December 2012, John McAfee was on the run from police in Belize and telling reporters he was still in the country. Vice sent two journalists to travel with him and published a triumphant piece headlined that they were with him right now. The article included a photo taken on an iPhone 4S.

A reader downloaded the photo, opened its metadata, and read the GPS coordinates the camera had written into the file: a spot in Rio Dulce, Guatemala. McAfee first claimed he had faked the data, then admitted it was accurate. He was arrested in Guatemala within days.

Nobody hacked anything. The photo simply said where it was taken, the way nearly every photo on your phone right now does.

What your camera writes into every shot

Since the late 1990s, cameras have embedded a block of information called EXIF inside image files. It rides along invisibly, and depending on the device it can include:

  • GPS coordinates — latitude and longitude, often accurate to within a few metres, and sometimes altitude.
  • The exact date and time the shutter fired, down to the second.
  • The device — make and model of the phone or camera, and the lens.
  • Camera settings — shutter speed, aperture, ISO, whether the flash fired.
  • A serial number, on many DSLRs and mirrorless bodies, unique to that specific camera.
  • Editing history — the software used, and sometimes the original filename before you renamed it.

Most of this is useful. Photographers rely on it to learn from their own shots. Your phone uses the location tags to build those "places" maps and to group photos by trip. It exists for good reasons.

The problem is that it was designed for the era when a photo lived on a memory card, and now every photo you take is one drag-and-drop away from a stranger.

The assumption that gets people

Ask most people whether their photos contain their home address and they'll say no, because they've never seen it. That's the whole issue. Nothing in your phone's photo viewer shows you the coordinates unless you go looking.

The second assumption is more dangerous: that uploading strips it. Sometimes it does. The big social platforms — Facebook, Instagram, X, Reddit — re-encode images on upload and discard the EXIF block in the process. If your entire online life happens inside those apps, you've been protected by accident.

But plenty of paths don't touch the file at all:

  • Email attachments. The file arrives exactly as it left.
  • Cloud storage links. Sharing a Drive or Dropbox folder shares the original files.
  • Your own website. Uploading a photo to WordPress, Squarespace, or a listing on your own domain generally preserves it.
  • Direct transfers. AirDrop, a USB copy, a memory card handed to someone.
  • Anywhere that offers a "download original" option, which is the point of the option.

And platform behaviour changes without announcement. A site that stripped metadata two years ago may not today, and you have no way to audit it from the outside. Treating "the platform probably handles it" as a privacy strategy means your privacy depends on someone else's engineering decisions that you'll never be told about.

Where this actually bites

The McAfee story is fun because it's absurd. The everyday versions are duller and closer to home:

Selling something online. You photograph a couch in your living room and post it on a marketplace or a local group. If the listing preserves the original, every stranger who replies now has your address, and knows you own something worth stealing.

Photos of your kids. A grandparent forwards a school-morning photo, and the file carries the coordinates of the front door plus a timestamp that shows what time everyone leaves the house.

Working from home. Product shots for your own shop, taken at your kitchen table, uploaded to your own site. Your business address is a PO box; your photos aren't.

Dating profiles and anonymous accounts. An account carefully kept separate from your real name can be undone by one photo taken in your apartment.

Anyone with a reason to be careful. Journalists protecting a source's location, someone who has moved away from a person they don't want finding them, anyone photographing something sensitive. In these cases the stakes stop being embarrassment.

How to check a photo you already have

You don't need a tool to look — every operating system will show you.

On a Mac: open the image in Preview, then Tools → Show Inspector, and click the tabs. If there's a GPS tab, that photo knows where it was taken, and Preview will show you the spot on a map.

On Windows: right-click the file, choose Properties, then the Details tab. Scroll to the GPS section.

On a phone: in iOS Photos, swipe up on an image or tap the info button — if there's a map under the photo, the coordinates are in the file.

Try it on the last photo you took. It's a more convincing demonstration than anything I can write here.

Two things worth doing

Turn off location tagging at the camera. On iOS: Settings → Privacy & Security → Location Services → Camera → Never. On Android it's a "location tags" or "geotagging" toggle inside the camera app's own settings. The tradeoff is real — you lose the map view and the automatic trip albums — so some people leave it on and handle it at the other end instead.

Strip metadata from anything you publish. This is the step that matters regardless of the first one, because it also covers photos other people sent you, old photos taken before you changed the setting, and camera serial numbers. Our Remove Image Metadata tool clears the EXIF block from JPEG, PNG, WebP, and HEIC files and hands the image back unchanged in every visible way — which matters, because iPhone photos are HEIC by default and are exactly the ones carrying coordinates.

Worth knowing: screenshots and images that have been through an editor and re-saved usually have no GPS data, because the coordinates were never in the screenshot and most editors don't carry them forward. Usually. It's not a rule to bet on.

One thing about doing this online

There's an obvious tension in uploading a photo to a website in order to remove the location data from it. You'd be handing the coordinates to a server to prove you didn't want anyone to have them.

Our tools run entirely in your browser. The image is read and rewritten by JavaScript on your own machine and never leaves it. You can verify that yourself: load the page, disconnect from the internet, and the tool still works.

Short version

Your photos have been quietly recording where you stood since the day you got the phone. Most of the time it doesn't matter. The times it does, it matters a lot, and you won't get a warning — because the whole point of this data is that you never see it.

Strip metadata from your photos now

Free to start, no upload, nothing leaves your browser. Create an account and clear the EXIF from your next batch in about ten seconds.

Get started free →

Keep going

← Back to Blog