EXIF Metadata & Geotags: What Photos Reveal About Your Location
The Hidden Footprint Inside Every Digital Photograph
When you snap a photograph on a modern iPhone, Android device, or DSLR camera, the image file contains far more than just pixel color values. By default, cameras record extensive metadata headers known as Exchangeable Image File Format (EXIF).
EXIF data was originally created in 1998 by the Japan Electronics and Information Technology Industries Association (JEITA) to help photographers record technical camera settings such as aperture, ISO speed, shutter duration, and focal length. Over the last two decades, however, smartphones integrated high-precision Global Positioning System (GPS) chips directly into camera firmware, turning ordinary photographs into pinpoint location beacons.
- GPS Coordinates: Exact latitude, longitude, and altitude to within 3 meters (revealing your home address, child's school, or secret workplace).
- Timestamp: Precise date, hour, minute, and second down to millisecond precision.
- Device Identifiers: Smartphone make, model, operating system version, and unique sensor serial numbers.
- Facial & Scene Attributes: Direction of view (compass heading), flash state, and embedded preview thumbnails.
How Threat Actors Exploit Image Geotags
When private photos are shared over unencrypted or unscrubbed channels, anyone who saves the image can extract the embedded GPS tags using standard free operating system utilities. On macOS, opening the file in Preview and pressing Cmd + I reveals an interactive satellite map showing precisely where the photo was taken.
For investigative journalists, domestic abuse survivors, political dissidents, and everyday users sharing casual photos of pets or household items, this creates severe real-world stalker risks. In multiple documented forensic incidents, online stalkers triangulated private residential addresses simply by downloading raw JPEG files shared in public forums.
How Client-Side Sanitization Protects Your Identity
Many popular websites strip EXIF data on their servers after receiving the file. While this protects other users from downloading the metadata, it means the server operator still receives and could log your GPS coordinates.
Locky takes an uncompromising client-side first approach:
- When you select a photo in Locky, a browser-native binary reader parses the JPEG and PNG markers before any network byte is sent.
- The sanitizer identifies the
APP1 (0xFFE1)segment containing the EXIF TIFF header and strips it completely from the binary buffer. - The sanitized array buffer is reassembled in memory. Only the pure image raster data without GPS or device tags is transferred to Cloudflare R2 storage.
Because the sanitization runs in JavaScript on your local machine, your geographic location never touches Locky's servers or intermediate networks.
Best Practices for Everyday Photo Privacy
- Disable Location Services for Camera Apps: In iOS Settings > Privacy > Location Services > Camera, set permission to "Never" if you do not need photo geotagging.
- Always Use Ephemeral Sharing: Use zero-knowledge tools like Locky with automatic 24-hour self-destruct when sharing private pictures with acquaintances or clients.
- Be Mindful of Background Clues: Strip metadata, but also check for street signs, house numbers, or identifiable landmarks visible in the picture itself.