A photo is never just a photo. Every image taken on a modern phone carries a hidden record of where it was taken, when, on what device, and sometimes who was holding the phone. None of it shows on screen. All of it travels with the file.
For most people, most of the time, that’s harmless. A holiday snap to the family WhatsApp group. A meal posted to Instagram. The metadata sits there, unread, doing nothing.
In a conflict zone, in a protest, in any situation where being identified or located is dangerous, that same metadata becomes a problem with consequences. People have been arrested because of it. Targets have been hit because of it. In a few documented cases, people have died because of it.
This is a piece about why that matters and what removing metadata before posting actually does. The tools that do this job are common; Metacleaner is one of them, Signal is another, and so are a handful of others. The point isn’t which tool. The point is that a lot of people who should be using one, aren’t.
What’s actually in a photo
The technical name is EXIF data. It’s a standard from the mid-1990s, embedded automatically by almost every digital camera and smartphone made since. Open any photo from your phone in a desktop EXIF viewer and you’ll typically see:
- GPS coordinates, often accurate to within a few metres
- Date and time, down to the second
- Camera make, model, and frequently the device serial number
- Lens, focal length, aperture, shutter speed
- Software used, if the photo was edited
- A small embedded thumbnail of the original image
If you took the photo from your bedroom window, the file knows where your bedroom is. If you took it on the walk home from work, the file traces a line between your office and your front door. The phone wrote it all down. You probably didn’t notice.
The first time most people heard about this
In 2012, the antivirus founder John McAfee was on the run from authorities in Belize and had crossed into Guatemala. A reporter from Vice magazine was travelling with him and posted a photo of the two of them online. The image had been taken on the reporter’s iPhone. The EXIF data contained GPS coordinates pinpointing McAfee’s location to within a city block. He was arrested within days.
The McAfee case became a textbook example because it was so clean. There was no hack, no informant, no leak. The information that gave him up was sitting inside the JPEG, where it had been all along. Anyone with a free EXIF viewer could read it.
The lesson stuck for a while in privacy circles. It largely did not stick with the general public.
Crimea, 2014
Ten years ago, when Russian forces were operating in Crimea while Moscow officially denied they were there, a number of Russian servicemen took photos of themselves on duty and posted them to VKontakte, the Russian social network. The photos carried full EXIF data, including GPS coordinates that placed the soldiers inside Crimea on dates the Kremlin was insisting it had no troops in the country. The contradiction was visible to anyone who downloaded the images.
The pattern repeated often enough that in 2019 Russia made it illegal for active-duty servicemembers to use smartphones at work. The genie was already out by then. The principle had been established: ordinary phones taking ordinary photos can produce intelligence-grade evidence, accidentally, by default.
Ukraine, 2022 onwards
When the full-scale Russian invasion began in February 2022, the people most exposed to metadata risk were ordinary Ukrainians. A photograph of damage in a residential area, posted to show family abroad that the building was still standing, could carry GPS coordinates that helped Russian forces calibrate the next strike. A short video of an air-raid shelter could give away the location of dozens of civilians sheltering inside. The visible content of the post was often harmless. The invisible content, embedded by the phone, was not.
Ukrainian civilians and the volunteer organisations supporting them adapted quickly. Digital security guidance circulated through Telegram channels and community groups, asking people to strip metadata from photos and videos before posting, to avoid filming military positions or critical infrastructure, and to think carefully before sharing locations of shelters or aid points. The principle was simple: the file knows more than you do, and what your phone records can be read by people you don’t want reading it.
The reasoning didn’t need spelling out. Russia has spent the war targeting civilian infrastructure including residential blocks, hospitals, power stations and shelters. Any data a civilian posts that helps narrow down a target is data that endangers other civilians.
In parallel, the open-source intelligence community working on the Ukrainian side has used metadata to do the opposite job: hold Russia accountable. Bellingcat, the Centre for Information Resilience and the Atlantic Council’s DFRLab have used image metadata, geolocation analysis and satellite imagery to document strikes on civilian targets, identify perpetrators of atrocities such as the Bucha killings, and build evidentiary records for international war crimes prosecutions. The same field that creates risk for civilians who post carelessly creates accountability for the regime targeting them.
For an ordinary person reading this, the lesson from Ukraine is the one Ukrainians themselves arrived at within weeks of the invasion. If you’re somewhere a hostile actor wants to target, the metadata in your photos is part of their reconnaissance. Removing it is part of your defence.
Through all of it, the underlying mechanism is the same one that gave up McAfee in 2012. A phone takes a photo. The phone writes the GPS into the file. Someone uploads it. Someone else reads it.
Venezuela, 2024 to now
Venezuela shows the same problem in a different shape. Where Ukrainians are protecting themselves from a foreign aggressor, Venezuelans have been protecting themselves from their own state.
After the disputed July 2024 election, the Maduro government repurposed VenApp, an existing public-services app, into a tool for citizens to denounce neighbours suspected of opposition activity. Apple and Google removed the app from their stores within days. The web version stayed live, and the version already installed on phones never stopped working.
The Atlantic Council’s DFRLab, in a July 2024 report titled Venezuela: A playbook for digital repression, warned that VenApp could be used as a reporting tool against opposition organising and that “government and police officers could use geolocation to locate protest participants.” Within weeks, Amnesty International was reporting that VenApp denunciations were responsible for many of the post-election arrests.
By late 2025, with US military action looming, Maduro was actively encouraging citizens to use VenApp to report drone sightings and “suspicious people”. A CNN report from Caracas in November 2025 quoted an opposition supporter: “It’s scary that there’s now an app for citizens to denounce each other. How do we know that the app is not spying on you?”
The metadata problem in this kind of environment is doubled. The photo a protester takes at a demonstration carries GPS coordinates. The photo a sympathetic neighbour takes from their balcony carries the same. So does the photo a hostile neighbour takes through their kitchen window before sending it to a denunciation app. All of it is evidence. None of it had to be.
Venezuelan human rights groups have documented over 2,400 arrests connected to the post-election protests, with Amnesty reporting torture and abuse of detainees including children. The chain that gets a teenager from a peaceful demonstration to a detention centre is not always digital, but often part of it is. A photo on social media. A face matched against an ID database. A GPS coordinate in a file someone posted at 4 pm.
What the experts actually recommend
This is where it stops being abstract. The Electronic Frontier Foundation, the ACLU, Amnesty International, and most operational security training for journalists and protesters all converge on the same advice. Before posting any photo from a sensitive context, do at least the following:
- Remove the metadata.
- Blur or block out faces, tattoos, or distinctive clothing.
- Don’t post anything that wasn’t yours to share.
EFF’s Surveillance Self-Defense guide, the most widely cited resource of its kind, puts it plainly: “If you want to keep your identity and location secret, make sure to strip all metadata off of your photos before you post them.” The ACLU of DC’s Know Your Rights guidance for protesters says the same thing in nearly the same words, and adds that metadata can let police identify “the exact time and location a photo was taken, the model of the device the photo was taken on, and even your name.”
The mechanics of how to do it vary. Signal strips EXIF automatically when you send a photo through it. Some operating systems have a built-in option. Dedicated tools like Metacleaner do it in a browser without installing anything. The point isn’t the route. The point is that almost no social platform does this for you reliably, and the gap between “I took a photo” and “I uploaded a photo” is where the risk sits.
The boring version of all this
It would be easy to read the above and conclude that metadata only matters in war zones and police states. That isn’t quite right.
The same EXIF that locates a McAfee on the run also locates a domestic abuse survivor whose new address is encoded in a photo posted to social media. The same data that exposes Russian troop positions also exposes the home addresses of women whose ex-partners go looking for them through their public Instagram feeds. Stalkers have used EXIF data. Harassment campaigns have used it. People doxxed by online mobs have been located through it. The mechanism is identical.
For most people, most of the time, none of this will ever matter. For some people, sometimes, it matters enormously. The cost of getting it wrong is borne by the person in the photo, not by the platform that hosted it. And the cost of getting it right is the small inconvenience of running a photo through a metadata cleaner before posting it.
Tools like Metacleaner exist for exactly this. So do the others. Use one of them. Or, if you’ve ever taken a photo from somewhere you’d rather people didn’t know about, at least be aware that the file knows even if you don’t.
Sources and further reading
- Electronic Frontier Foundation, Surveillance Self-Defense: Attending a Protest, ssd.eff.org
- ACLU of DC, How to Defend Against Police Surveillance at Protests (2025)
- Amnesty International, Venezuela: Tech Companies Set Dangerous Precedent with App for Reporting Anti-Government Protesters (2024)
- Atlantic Council DFRLab, Venezuela: A playbook for digital repression (2024)
- Bellingcat / Centre for Information Resilience, Eyes on Russia project (ongoing)
- Chatham House, Open-source intelligence in Ukraine: Asset or liability? (2022)
- Human Rights Watch, Venezuela: Brutal Crackdown on Protesters, Voters (2024)
- CNN, Venezuela’s Maduro, fearing US attack, promotes app to report suspect behavior (November 2025)