Every photo your phone has taken outdoors carries the latitude and longitude of where you stood when you pressed the shutter, accurate to within a few metres. The location is written into the JPEG's EXIF block in two fields: GPSLatitude and GPSLongitude, with a third (GPSAltitude) noting how far above sea level you were. GPS in phone photos is a default behaviour, not a feature you opt into, and it has been the way iPhones, Android handsets and modern cameras work for well over a decade.
Most people know the data is there. Far fewer realise what survives uploading a picture, attaching it to a message, or dragging it into a CV.
Where GPS actually sits in a JPEG
EXIF (Exchangeable Image File Format) is a metadata block stitched into the start of a JPEG, just after the file's marker bytes. It holds camera make and model, exposure settings, white balance, the orientation flag, the lens used, and the GPS Information Directory (GPSInfo IFD).
The GPSInfo block stores coordinates in degrees, minutes and seconds, plus rationals representing the decimal portion. There is also GPSDateStamp and GPSTimeStamp, written from the satellite signal independently of the device's clock. On modern phones it can include heading (which way you were facing), speed (whether you were moving), and the horizontal positioning error in metres.
Some phones additionally write Apple- or Google-specific extensions inside the EXIF MakerNote: face detection regions, the burst-photo group ID, the iCloud asset identifier, and on Pixel devices the precise model of camera sensor used.
What survives where
Social platforms
Major social networks (Instagram, Facebook, X, TikTok) strip EXIF on upload. They re-encode the image and discard the metadata, partly because they do not want people scraping it. That is a reasonable safety net, but it does not cover everything: messages sent through their direct-message systems sometimes preserve the original file (especially when the recipient downloads at full resolution), and links to images stored on third-party CDNs almost never go through the same scrub.
Email and messaging
WhatsApp, Signal and Telegram process images differently in their default mode (compressed, EXIF stripped) versus when sent as a "document" or "file" (untouched). iMessage attaches the original by default. Outlook, Gmail and other email clients preserve EXIF entirely. A photo emailed to a stranger goes with its GPS still attached.
Cloud storage and shared links
Dropbox, Google Drive and OneDrive shared links serve the original file unaltered. Anyone who downloads the shared image gets the GPS too.
Marketplace listings and ad photos
This is the consistent failure case. eBay, Vinted, Facebook Marketplace, Gumtree and Etsy do not always re-encode product photos; they often preserve EXIF for the seller's benefit. A flat advertised on Marketplace can have GPS coordinates pointing to the front door.
Dating apps
This was the well-publicised problem of the early 2010s. Most dating apps strip EXIF now, but the apps and services that re-host their images (third-party verification tools, screenshot archives, leaked databases) do not. The history of the leak persists even where the live product is patched.
Forwarded screenshots and AirDrop
Two everyday channels people forget. iOS screenshots inherit no location, but a screenshot of a photo viewer showing the photo's metadata pane re-encodes the coordinates straight into the screenshot's pixels. AirDrop, in its default mode, transfers the original full-resolution file with EXIF intact. A photo handed across the office "just for a second" carries the same GPS as the original. Apple's recent privacy settings let the sender decide whether to include location, but the option defaults differently depending on the share sheet used.
Why GPS in a single photo is more revealing than people expect
One geotagged photo is a coordinate. Three are a pattern: home, work, somewhere social on a Friday night. A small album of geotagged photos pulled from a public profile reconstructs the daily trajectory of the person who took them. Open-source intelligence researchers have been doing exactly this for years — identifying military installations, tracing the movement of corporate executives, building dossiers on stalking targets — and the photos are almost always voluntarily uploaded.
The defensive answer is not to stop taking geotagged photos. They are useful inside your own device. The answer is to strip the GPS before the file leaves your control.
Removing GPS without losing the photo
You do not have to re-encode the image (which loses some quality) or recompress it. EXIF is a separate block; it can be cleanly excised while the JPEG bytes underneath stay byte-identical. Tools like exiftool do this from a command line. The cleaner on the homepage does the same thing in a browser, in one drop, on any image format that carries EXIF, IPTC or XMP — including HEIC from iPhones, RAW files from cameras, and PNGs that have picked up a stray location tag.
If you take one preventative habit away from this, make it the simple one: photos meant for the world should not carry the coordinates of where you live, work, or stood last Saturday afternoon.