Can strangers read where you live, when you wake up, what phone you use from the photo you posted to your social feed? That’s not scaremongering — phone photos by default write a bunch of EXIF metadata, including GPS coordinates, device model, and shooting time. This post covers what’s hidden in EXIF, why it’s a privacy disaster, and how to batch sanitize. Pair with the Piick image converter to strip all EXIF in one click.
What your photos are leaking
You take a “view from my balcony” landscape shot and post it to your feed — looks like just a landscape, right? Actually the photo hides:
- GPS latitude and longitude: precise to 6 decimal places, error less than 1 meter
- Shooting time: precise to the second, lets people infer your routine
- Phone model: iPhone 15 Pro / Xiaomi 14 / Huawei P60
- Lens parameters: aperture, focal length, ISO (reveals your photography skill level)
- Software version: which system, which camera app
A stranger who gets the original image (WeChat compresses it, but email attachments, cloud drives, and original-image sharing don’t) can read all of this with a single exiftool command — home address, device, and routine are gold mines for stalkers.
7 categories of privacy hidden in EXIF
Ordered by risk from high to low:
- GPS coordinates — highest risk, exposes home / work address
- Shooting time — infers your routine and commute times
- Device serial number — some cameras write the body serial number
- Phone model — helps match identity via social engineering databases
- Lens parameters — technical details; commercial photographers leaking work may affect copyright
- Software version — exposes device OS version, enabling targeted exploits
- Author / copyright field — if you actively fill it in, your real name leaks directly
Real case: A Japanese blogger tweeted a cat photo, and someone used the EXIF GPS to track them down to a specific apartment and stalk them to their home. This isn’t a joke — it’s happened.
How social platforms “clean up”
The good news is that major social platforms process EXIF:
- WeChat: Images posted to Moments or chats get re-encoded, EXIF fully stripped
- Weibo: Image EXIF stripped, but shooting time kept (shown in lower-right corner)
- Instagram: EXIF fully stripped, no metadata at all
- Twitter/X: EXIF stripped, but shooting time kept (shown below the image)
- Xiaohongshu: EXIF fully stripped
- Telegram: Depending on privacy settings, EXIF may be kept by default
The bad news: Email attachments, cloud drive sharing, AirDrop, original-image transfer, and screenshot tools all don’t strip it. The most dangerous scenario is “original image sharing” — many people don’t realize this leaks their location.
Batch sanitize with Piick
The Piick image converter automatically strips all EXIF when converting formats — this is a privacy feature by design, not a bug. Even if you only want to “convert PNG to JPG,” the converted image has no EXIF — GPS, shooting time, device model all cleared.
3-step batch sanitization:
- Drag the photos you want to share into the Piick image converter
- Pick the target format (you can keep the original, e.g., PNG -> PNG)
- Click convert, download the ZIP — all EXIF is gone
Use cases: Run a batch conversion before emailing attachments, before sharing family photos via cloud drives, and before uploading second-hand item photos (don’t let buyers know your home address).
Open the Piick image converter now, drag in a few photos you want to share, convert them, and watch all the EXIF disappear.