What's Hiding in Your Photos
01 What's hiding in your photos
Camera model, exact GPS coordinates - often accurate to a few meters - the date and time, sometimes the software used to edit it. All stored invisibly inside the file, traveling with it wherever it goes. A second, smaller copy of the photo is frequently hidden inside too, left over from before it was cropped or edited - which means it can show something the final photo doesn't. This tool decodes and shows you all of it, by name, before anything is removed.
Go deeper: what's actually in the file, field by field
Most smartphone photos carry a metadata block called EXIF, which typically includes:
- GPS coordinates - stored as three numbers (degrees, minutes, seconds) per axis, decoded here into an ordinary latitude/longitude you could paste into a map.
- Camera make and model, and often the exact software/app version used to process the image.
- Date and time the photo was taken - not when you shared it.
- Orientation and other capture settings.
- An embedded thumbnail - a small second copy of the image, generated once and then usually left untouched even if you later crop or edit the main photo. If you compare the thumbnail to the final image and something in it is missing or different, that's a genuine, well-documented indicator of after-the-fact editing - not a guess, an artifact of how the file format actually works.
None of this is visible in a normal photo viewer. It travels silently with the file until something - this tool, or a platform's own upload pipeline - strips it out.
Why this matters in practice
This isn't hypothetical. GPS-tagged photos have exposed home addresses from real-estate and rental listings, revealed the location of people who specifically didn't want to be found, and undermined the anonymity of sources in sensitive reporting - all from a single unedited photo, because nobody thought to check what was riding along with it. The camera metadata itself is usually harmless on its own; it's the combination with a public post that turns "just a photo" into a location disclosure.
Dating and social profile photos carry the same risk in a more personal setting. GPS data embedded in a photo posted to a dating app can reveal exactly where you live or spend time, even if your bio never says so - which is precisely the kind of information online-dating safety guides warn against sharing with someone you've only just met. Stripping location metadata before posting is standard advice for this reason, not a niche precaution.
The same risk applies, with higher stakes, to photos of children. An otherwise completely ordinary photo taken at a child's school, daycare, or regular playground carries that location embedded invisibly, even when a parent shares it only with family and friends. Child-safety organizations and law enforcement commonly recommend removing location metadata from children's photos before posting them anywhere public - not because of anything visible in the photo, but because of exactly the kind of data this page is about.
Two more things worth knowing
ICC color profiles aren't a privacy risk the way GPS data is, but they're still metadata - a small embedded description of how colors in the file should be interpreted, sometimes including the name of the software or hardware that created it. This tool decodes and shows that too, under "full metadata detail," mostly for completeness and because it can be one more clue in figuring out where an image came from.
The full chunk map - every single segment in the file, in order, with its offset and size - exists so you don't have to take the tool's word for what it found. If the numbers in the map don't add up to the file's actual byte count, that's a bug worth reporting, not something to trust blindly.