← back to tools

Photo Privacy Audit

Scan what's secretly embedded in your photos — location, device, timestamps, camera settings. The data you never knew you were sharing.

Runs entirely in your browser — photo never uploaded
GPS will be found in: Original camera shots transferred via USB, cable or AirDrop · iCloud / Google Photos downloads · Email attachments sent as "original" · TIFF & HEIC from iPhone
⚠️ GPS is stripped by: WhatsApp · Instagram · Facebook · Twitter/X · Telegram · Screenshots · PNG exports from editing apps
🔍

Drop any photo to audit its hidden data

JPG · PNG · TIFF · HEIC · WebP  ·  or browse files

Scanning…
Analysing EXIF metadata embedded in your photo.

Before you post a photo online, it's worth knowing what's hidden inside it. This free photo privacy checker reads the invisible EXIF metadata embedded by your phone or camera and tells you, in seconds, whether it contains your GPS location, device model, or exact capture time — the same kind of hidden metadata scanner journalists, photographers, and privacy-conscious users rely on before sharing an image publicly. Drop a photo below to check for hidden location data, or read on for a full walkthrough of how photo metadata works.

What is the Photo Privacy Audit tool?

The Photo Privacy Audit is a free online EXIF data viewer that inspects any photo — JPG, PNG, TIFF, HEIC, or WebP — for hidden metadata that isn't visible when you simply look at the image. Cameras and smartphones silently write dozens of technical details into every photo they capture: where it was taken, on which device, at what exact second, and under what camera settings. This tool reads all of that out and presents it as a clear, easy-to-understand privacy report, so you know exactly what you'd be sharing before you post, email, or upload an image anywhere.

Unlike most metadata tools, nothing here is ever uploaded to a server. The scan happens entirely inside your browser tab, using JavaScript to parse the photo's binary EXIF data on your own device — making it a genuinely private way to check if a photo reveals your location before anyone else sees it.

How to use the photo metadata checker

Auditing a photo takes three steps and a few seconds — no account, no install, no upload.

  1. Add your photo. Drag and drop an image onto the drop zone above, or click "browse files" to select one from your device. For the most accurate results, use the original file straight from your camera roll rather than one downloaded from social media.
  2. Let it scan instantly. The tool reads the file locally in your browser and parses its EXIF metadata in real time — there's no waiting on an upload or a server response.
  3. Review your privacy score. A privacy exposure score, a breakdown of GPS location, device details, timestamps, and camera settings, plus a map pin (if GPS is present) appear automatically.
  4. Strip the data if needed. If GPS or other sensitive fields are found, follow the built-in step-by-step instructions for Windows, macOS, iPhone, or Android to remove that data before you share the photo.
  5. Save or copy your report. Use "Copy Full Report" to keep a text record of every metadata field found, or "Copy GPS" to grab just the coordinates.

Who uses this tool?

Anyone who shares photos online can benefit from checking what's hidden inside them first.

🏠

Everyday photo sharers

Parents, homeowners, and everyday users who want to make sure a photo of their kids, pets, or house doesn't quietly reveal a home address before posting it publicly.

🏡

Real estate & rental listers

Agents and hosts listing property photos who want to strip embedded location and device data before it goes on a public marketplace or classifieds site.

📰

Journalists & researchers

Reporters and OSINT researchers verifying the authenticity, origin, or capture time of a submitted or found photo as part of source verification.

📸

Photographers

Professionals and hobbyists checking their own camera settings — ISO, aperture, shutter speed, lens — after a shoot, or confirming copyright metadata is embedded correctly.

🛒

Online sellers

Marketplace sellers who photograph items at home and want to confirm no GPS coordinates are attached before uploading product photos.

⚖️

Legal & investigative use

Anyone needing to confirm a photo's original timestamp, device fingerprint, or GPS data for documentation, evidence review, or timeline verification.

Why use our photo privacy checker?

🔒

100% private, zero uploads

Your photo is read locally in your browser and never leaves your device — not even temporarily. Nothing is sent to a server.

Instant results

Metadata is parsed and displayed the moment you drop a file — no waiting, no queue, no upload progress bar.

🆓

Completely free

No sign-up, no subscription, no paywall, and no limit on how many photos you can audit.

🗺️

Visual, plain-English reports

A privacy score, colour-coded risk pills, and an actual map pin make it clear at a glance what's exposed — no technical EXIF knowledge required.

🛡️

Built-in fix, not just a warning

Every scan comes with exact, OS-specific steps to strip the sensitive data you just found — on Windows, Mac, iPhone, or Android.

Real-world examples

📍 A photo taken on an iPhone at home

An iPhone photo transferred via AirDrop or USB will typically show a GPS latitude and longitude accurate enough to pinpoint a house on a map, plus the device model ("iPhone 15 Pro"), the exact date and time down to the second, and camera settings like f-number and ISO. Running this photo through the audit reveals all of it instantly, along with a map preview of the exact location.

💬 The same photo re-downloaded from WhatsApp

Send that same photo through WhatsApp and download it again — this time, the audit finds no GPS data and no device model. WhatsApp's compression process strips almost all EXIF metadata automatically, which is why a screenshot or a re-shared social media image usually scores as low exposure.

📷 A DSLR product photo for a marketplace listing

A photo shot on a dedicated camera without GPS enabled might show no location, but will often still reveal the camera make, model, lens, and exact settings used — useful for photographers, but something a seller may want to review before publishing to a public listing.

What data is hidden in your photos?

Every JPEG taken by a smartphone or digital camera contains invisible EXIF (Exchangeable Image File) metadata written at the moment of capture. This tool reads that metadata entirely inside your browser — your photo is never uploaded anywhere. Here's what gets embedded and why it matters:

📍 GPS location — the biggest risk

If your phone's location access is on, every photo stores GPS coordinates accurate to a few metres. Posting an unstripped photo from home can reveal your exact home address to anyone. This works on original files from USB transfer, AirDrop, iCloud/Google Photos downloads, or email "original" attachments.

⚠️ Why WhatsApp photos show no GPS

WhatsApp, Instagram, Facebook, Twitter/X and Telegram all automatically strip GPS and most EXIF before storing your photo on their servers. This is a privacy protection — but it also means using this tool on a WhatsApp-received image won't show location. Use it on the original camera file instead.

📱 Device fingerprint in every shot

Your camera model, manufacturer, firmware version, and sometimes even a unique serial number are stored in every photo EXIF. This lets anyone identify the exact device that took a photo — used in legal investigations, copyright disputes, and journalism verification.

🕐 Exact timestamp — down to the second

EXIF stores three timestamps: original capture time, digitized time, and file modification time. These can be used to verify or disprove an alibi, establish a timeline, or detect if metadata was manipulated — which is why courts increasingly request original photo files.

📷 Camera settings reveal your gear

Shutter speed, aperture (f-stop), ISO, focal length, flash status and white balance are all stored. Forensic analysts use these to verify photo authenticity. Photographers use them to review what settings produced a particular result.

🔒 100% private — how does this work?

This tool uses the browser's FileReader API to read your file locally, then parses the binary EXIF bytes using a pure JavaScript parser — no libraries, no servers. Your image never leaves your device. It works offline once the page is loaded.

More questions about photo metadata

Does this work on iPhone HEIC photos?

Yes — HEIC and TIFF files exported directly from iPhone typically carry the same EXIF structure as JPEG, including GPS, device, and timestamp data, and this tool can read them.

Can I check a photo's metadata on my phone?

Yes, this is a mobile-friendly web tool — open it in your phone's browser, select or share a photo into it, and the same instant privacy scan runs directly on your device.

Will this tool store or save my photos?

No. Nothing is uploaded, cached, or stored anywhere. Once you close or refresh the tab, the file and its metadata are gone from memory.

What's the difference between this and a metadata "remover"?

This tool audits and reveals what's hidden in a photo first, then gives you exact manual steps to remove it using your operating system's built-in tools — so you understand what you're removing and why.