Which Sites Strip EXIF Data — and Which Don't
September 13, 2026 · 6 min read
Almost every article on this subject answers one question: does Instagram remove EXIF data? The answer is yes, and it has been written about hundreds of times.
It is also the least useful version of the question, because Instagram is one of the platforms that does strip metadata. The risk lives everywhere else — the routes people use without thinking, which pass your file along exactly as it came off your phone, GPS coordinates included.
What is in there
A photo from a phone typically carries the date and time to the second, the device make and model, the camera settings, and — if location services were on for the camera — the latitude and longitude where it was taken, often accurate to within a few metres.
That last one is the reason this matters. Everything else is trivia.
The rule that predicts most of it
You do not need to memorise a table. One principle covers the majority of cases:
If the service re-encodes your image, metadata is usually lost. If it just moves the file, metadata survives.
Social platforms re-encode everything. They resize your photo to fit their layout and re-compress it to save bandwidth, and the metadata does not survive that pipeline. Removing it is partly deliberate and partly a side effect of rebuilding the file.
Anything that transfers the file as a file — email attachments, cloud storage links, AirDrop, a document sent through a chat app, an upload to your own website — has no reason to touch the contents. What arrives is what you sent.
So the question to ask about any service is: does my photo come out the other side looking resized and recompressed, or byte-for-byte identical?
Where metadata usually survives
These are the ones worth being careful with:
Email attachments. Mail clients do not modify attachments. A photo emailed straight from your camera roll carries everything.
Cloud storage shares. Dropbox, Drive and similar store and serve the original file. Anyone with the link downloads exactly what you uploaded.
Direct transfers. AirDrop, Nearby Share and USB copies preserve everything by design — that is the point of them.
Files sent as documents. Sending a photo as a document rather than an image in a messaging app deliberately bypasses the compression step, and therefore the stripping too.
Marketplace and classified listings. Behaviour varies enormously between platforms and changes without announcement. This is the scenario that should worry you most: photographing furniture in your living room and posting it to sell, with your home coordinates attached.
Forums and older websites. Anything running software that stores uploads as-is.
Your own site or CMS. Uploading to WordPress or similar generally keeps the original file available, even if the displayed version is resized.
Where it usually does not
Large social platforms re-encode aggressively and the public version of your photo generally arrives without EXIF. That covers the obvious ones.
But two caveats matter more than the fact itself.
Stripped in public does not mean never received. The platform got your original file with all its metadata before it removed anything. Meta's own privacy documentation confirms it collects location information from uploaded photos. Your followers cannot read your coordinates; the company can. If your concern is the platform itself rather than other users, automatic stripping does nothing for you.
Direct messages may not follow the same path as public posts. Several platforms process DM attachments differently from feed uploads, and researchers have found metadata surviving that route on some services. Do not assume a platform's public-post behaviour applies to everything it carries.
Do not trust any list, including this one
Here is the honest part. Platform behaviour changes without notice, differs between the app and the web version, differs between public posts and messages, and differs by country and file type. Any table you read — on this site or any other — is a snapshot of what someone tested at some point.
So test it yourself. It takes two minutes and gives you an answer that is actually current:
- Take a photo with location services enabled
- Upload it wherever you are worried about
- Download it back from that platform, as a normal viewer would
- Check the downloaded file's metadata
If the coordinates are gone, that route strips them today. If they are there, you know. Repeat it occasionally for anything you use regularly, and repeat it after any major app update.
The approach that removes the guesswork
All of the above is manageable, but it requires thinking about every route your photos take. There is a simpler policy: strip the metadata before you upload anything, anywhere.
Do that and it stops mattering which platforms behave which way, whether the policy changed last month, or whether the file gets forwarded somewhere you did not anticipate. The information is not in the file, so nothing downstream can leak it.
Two ways to do that:
Stop it at the source. Turn off location access for your camera app. On iPhone, Settings → Privacy & Security → Location Services → Camera → Never. On Android, the camera app's own settings have a location toggle. New photos then carry no GPS at all. The cost is that your photo library loses the map view and location-based albums, which some people rely on heavily.
Strip before sharing. Keep location data on for your own organisation, and remove it from the copies you send out. This keeps both benefits, at the cost of remembering to do it.
Whichever you choose, do it with a tool that runs on your own device. Uploading a photo to a website in order to remove its location data means handing that location data to the website first, which is a strange trade. Our tools process everything in your browser — you can verify it by opening developer tools, switching to the Network tab, and watching for an upload request that never comes.
The situations that actually go wrong
Worth naming, because these are where real harm happens:
- Selling something on a marketplace, photographed at home
- A dating profile picture taken in your flat
- A photo emailed to a stranger from a classified ad
- Pictures of children posted to a forum or group
- A photo of a document that also records where you were when you took it
None of these involve the platforms people usually worry about. That is the point.
The short version
Services that re-encode your image tend to remove metadata; services that just move the file do not. Social feeds mostly strip, but only for other users — the platform already has your original. Email, cloud links, direct transfers and many listing sites pass everything straight through. Rather than tracking who does what, remove the metadata yourself before it leaves your device, and test any route you rely on by downloading your own file back and checking it.