Can strangers read where you live, when you wake up, what phone you use from the photo you posted to your social feed? That’s not scaremongering — phone photos by default write a bunch of EXIF metadata, including GPS coordinates, device model, and shooting time. This post covers what’s hidden in EXIF, why it’s a privacy disaster, and how to batch sanitize. Pair with the Piick image converter to strip all EXIF in one click.

What your photos are leaking

You take a “view from my balcony” landscape shot and post it to your feed — looks like just a landscape, right? Actually the photo hides:

  • GPS latitude and longitude: precise to 6 decimal places, error less than 1 meter
  • Shooting time: precise to the second, lets people infer your routine
  • Phone model: iPhone 15 Pro / Xiaomi 14 / Huawei P60
  • Lens parameters: aperture, focal length, ISO (reveals your photography skill level)
  • Software version: which system, which camera app

A stranger who gets the original image (WeChat compresses it, but email attachments, cloud drives, and original-image sharing don’t) can read all of this with a single exiftool command — home address, device, and routine are gold mines for stalkers.

7 categories of privacy hidden in EXIF

Ordered by risk from high to low:

  1. GPS coordinateshighest risk, exposes home / work address
  2. Shooting time — infers your routine and commute times
  3. Device serial number — some cameras write the body serial number
  4. Phone model — helps match identity via social engineering databases
  5. Lens parameters — technical details; commercial photographers leaking work may affect copyright
  6. Software version — exposes device OS version, enabling targeted exploits
  7. Author / copyright field — if you actively fill it in, your real name leaks directly

Real case: A Japanese blogger tweeted a cat photo, and someone used the EXIF GPS to track them down to a specific apartment and stalk them to their home. This isn’t a joke — it’s happened.

How social platforms “clean up”

The good news is that major social platforms process EXIF:

  • WeChat: Images posted to Moments or chats get re-encoded, EXIF fully stripped
  • Weibo: Image EXIF stripped, but shooting time kept (shown in lower-right corner)
  • Instagram: EXIF fully stripped, no metadata at all
  • Twitter/X: EXIF stripped, but shooting time kept (shown below the image)
  • Xiaohongshu: EXIF fully stripped
  • Telegram: Depending on privacy settings, EXIF may be kept by default

The bad news: Email attachments, cloud drive sharing, AirDrop, original-image transfer, and screenshot tools all don’t strip it. The most dangerous scenario is “original image sharing” — many people don’t realize this leaks their location.

Batch sanitize with Piick

The Piick image converter automatically strips all EXIF when converting formats — this is a privacy feature by design, not a bug. Even if you only want to “convert PNG to JPG,” the converted image has no EXIF — GPS, shooting time, device model all cleared.

3-step batch sanitization:

  1. Drag the photos you want to share into the Piick image converter
  2. Pick the target format (you can keep the original, e.g., PNG -> PNG)
  3. Click convert, download the ZIP — all EXIF is gone

Use cases: Run a batch conversion before emailing attachments, before sharing family photos via cloud drives, and before uploading second-hand item photos (don’t let buyers know your home address).


Open the Piick image converter now, drag in a few photos you want to share, convert them, and watch all the EXIF disappear.