Image Inspector app icon Image Inspector

Image Inspector/Guides/Find location from a photo

Guide

Can someone find your location from a photo you sent?

TL;DR

Yes, if the photo kept its GPS block and reached them as an original file, accurate to a few metres. But most uploaded photos lose their coordinates to recompression, and roughly 2% of scraped web images carry GPS at all. The bigger exposure is usually the picture itself.

The honest answer has two halves that point in opposite directions, and most articles on this subject only print the alarming one. A geotagged photo pins you to a doorway. Most photos are not geotagged by the time anyone else sees them. Both are true, and which one applies to you depends entirely on how the file travelled.

What can someone actually learn from your photo?

If the GPS block survived, they get coordinates, altitude, the compass bearing the lens faced, and how fast you were moving, plus a field stating the fix's own accuracy in metres. Berkeley researchers matched geotagged photos against Street View imagery to within roughly one metre.

They also get the things people forget are in there: your exact handset, your iOS version, the second you pressed the shutter, and your timezone offset. On an iPhone, Apple's private tags add how long the phone had been awake and the tilt of your hand at the moment of capture.

Precision is what makes this different from an approximate guess. A photo file does not just claim a location; GPSHPositioningError grades its own confidence. An iPhone SE sample reported 5 metres. That is a building, not a neighbourhood.

Image Inspector plotting an iPhone photo's embedded GPS coordinates on a map with the camera bearing and the distance from where you are now
The same reading anyone receiving your file could perform, in about ten seconds.

Has photo metadata ever really located someone?

Twice, famously. In both cases the folklore overstates what the metadata did. It has destroyed alibis and corroborated identifications. Finding a documented case where EXIF alone led investigators to a person who was otherwise unknown to them is considerably harder than the retellings suggest.

John McAfee, December 2012

Vice published "We Are With John McAfee Right Now, Suckers" on 3 December 2012. The photo was taken on an iPhone 4S and still carried its GPS block: 15.658167, -88.992167, near Río Dulce, in Guatemala's Izabal department. The security researcher Mark Loveless spotted it within hours.

McAfee first insisted he had falsified the coordinates deliberately, then admitted the truth on 4 December. He was arrested in Guatemala City on 5 December, for illegal entry.

Timeline of the John McAfee photo metadata incident, December 2012 On 3 December 2012 Vice published a photo taken on an iPhone 4S still carrying GPS coordinates placing McAfee near Rio Dulce in Guatemala, spotted within hours by researcher Mark Loveless. On 4 December McAfee, having first claimed he falsified the coordinates, admitted the truth. On 5 December he was arrested in Guatemala City for illegal entry, after surfacing publicly himself and giving press interviews. The metadata destroyed his cover story rather than leading police to him. 3 DEC 2012 Vice publishes iPhone 4S photo, GPS intact 15.658167, -88.992167 Río Dulce, Guatemala, spotted within hours 4 DEC 2012 McAfee admits it first claimed he faked the coordinates deliberately, then conceded he was in Guatemala after all 5 DEC 2012 Arrested in Guatemala City, for illegal entry, after he surfaced publicly himself, gave interviews, sought asylum What the metadata did: destroyed his alibi. What it did not do: lead anyone to him.
The three days that get compressed into "metadata caught McAfee." It caught his cover story.

What the metadata actually did: it proved he was lying about being in Belize. It did not lead police to him; he surfaced publicly himself, gave press interviews and sought asylum. "Metadata exposed his cover story" is accurate. "Metadata led to his capture" is not.

Higinio Ochoa III, March 2012

The FBI's affidavit is public, and it does not say what the headlines said. A photo posted alongside a hack carried iPhone 4 GPS coordinates pointing to a suburb east of Melbourne, Australia, where the girlfriend who appeared in it lived.

Two details are routinely mangled. The photo had been edited in Photoshop, and the GPS survived that edit. And the EXIF was corroborating rather than decisive: the affidavit's identification chain rests on a screenshot Ochoa had tweeted showing his own desktop with Skype logged in as anonw0rmer and an IRC client logged in as @higochoa; both identities, one machine; plus subscriber records from a subpoena. He was arrested in Galveston, Texas, on 20 March 2012.

The case nobody can produce

There is no documented instance of photo EXIF exonerating someone. If you find the claim asserted, ask for the citation. We could not verify one.

Which famous metadata stories are misremembered?

Four of the most-cited "photo metadata" cautionary tales are not about photo metadata at all, and a fifth rests on a single officer's recollection. They get repeated because they are vivid. Knowing which is which is the difference between understanding the risk and performing it.

The story What it actually was
BTK / Dennis Rader, 2005 Metadata in a Word document on a floppy disk. No photograph involved.
Ena Matsuoka, 2019 A stalker located a Japanese singer from the reflection in her pupil, matched to Street View. The image, not the metadata.
Reality Winner, 2017 Printer microdots on a scanned document identified the source printer. Not EXIF.
Strava heatmap, 2018 Aggregate fitness GPS tracks exposing base perimeters. Nothing to do with photos.
The 2007 Apache helicopters Real, but thinner than told. See below.

The Apache story deserves its own paragraph, because it is probably the single most-cited geotagging anecdote in existence. The primary source is a US Army article, "Geotagging poses security risks," published 7 March 2012, in which an officer recalls that in 2007 soldiers photographed newly arrived helicopters on a flightline in Iraq, uploads let the enemy locate them, and a mortar attack destroyed four AH-64s.

It may well be true. But note what the source does not say: it never specifies the device. The widely-repeated "insurgents used cell phone geotags" headline is an embellishment, and an anachronistic one. The original 2007 iPhone had no GPS at all. It is one officer's recollection, five years later, in an operational-security awareness piece, with no unit, date or incident report attached. Cite it to the Army or leave it alone.

How likely is your photo to carry a location at all?

Roughly 2% of scraped web images carry geolocation EXIF, according to Clearview AI's own estimate in a 2025 UK tribunal judgment. A Berkeley study put geotagged Flickr uploads at 4.3%. Platforms recompress on upload, and recompression drops EXIF as a side effect.

Those numbers deserve to be said out loud, because this genre of article almost never says them.

~2% of 3 billion images

Clearview AI's own estimate, January 2022: "EXIF data is usually stripped away in the uploading process"

4.3% of 158M Flickr uploads

Berkeley, 2010, and falling, from a 9.3% peak in late 2006

1.3% of 68,729 Craigslist images

Same study: 48% kept some EXIF, but Craigslist recodes uploads

±1 m when it does survive

Same study: geotagged photos matched to Street View imagery

Separate studies, separate populations, separate years, reported individually rather than plotted on a shared axis, because they do not measure the same thing. An earlier 10% figure from Clearview's CEO was given, the tribunal records, without any search being run.

So the panic framing is wrong. The complacent framing is also wrong, for three reasons that survive the arithmetic:

  1. Two per cent of three billion is sixty million photographs. As the Berkeley authors put it, "even a seemingly small fraction like 1% can already translate into several hundred relevant cases."
  2. Stripping is a side effect, not a promise. Platforms drop EXIF because they recompress, not because they undertook to protect you. Flickr publishes GPS deliberately.
  3. Direct paths bypass all of it. AirDrop, email, WhatsApp document mode, a USB copy: none re-encode, so none strip. The photo you send a person you know is far likelier to carry GPS than the one you post publicly.

That last point inverts the usual advice. Your public Instagram post is probably clean. The original you AirDropped to a colleague is probably not.

Can they find you from the picture itself?

Frequently, and this is the exposure that stripping metadata does nothing about. Signage, architecture, vegetation, skyline and reflections all locate a photo. In 2019 a stalker in Japan identified a singer's train station from the reflection in her pupil, then followed her home.

The Ena Matsuoka case is the one to remember precisely because it is unglamorous: no metadata, no hacking, just a high-resolution selfie, a zoom, and Street View. She had also posted photos from her apartment where the view from the window was identifiable.

Machine vision has made this cheaper every year. A photo carries readable text, recognisable logos, QR codes with URLs inside them, and faces, all extractable in seconds. Removing EXIF does not make a photo anonymous. It removes one channel of several, and often not the widest one.

The three channels that can locate a photo, and which ones stripping EXIF actually closes Three channels locate a photo. The metadata channel holds GPS coordinates and is closed by stripping EXIF. The image channel holds signage, architecture, skyline, window views and reflections, and stripping EXIF does nothing to it. The context channel holds the caption, the timing, the account and who else was tagged, and stripping EXIF does nothing to that either. Removing metadata closes one channel of three. THREE WAYS A PHOTO LOCATES YOU 1. Metadata GPS coordinates capture time, device Apple MakerNote tags ✓ closed by stripping EXIF the only one that is 2. The image signage, architecture skyline, the view out a window reflections in a subject's eyes ✗ stripping does nothing located Ena Matsuoka in 2019 3. Context the caption, the timing the account that posted it who else was tagged ✗ stripping does nothing and it never touched this Removing EXIF closes one channel of three. It is worth doing. It is not the same as being unfindable.
The metadata channel is the only one a strip closes, and it is the narrowest of the three.
Image Inspector drawing a People and Pets detection box around a child in a beach photo, the image content a vision model can read regardless of metadata
What a vision model reads in the frame: the channel that survives every metadata strip.

What should you actually do about it?

Strip location at the share sheet rather than trusting a platform, verify the result on the file you actually sent, and stop assuming airplane mode helps. The FBI's Portland field office recommends exactly one operational step: use an EXIF viewer to confirm the removal worked.

  1. Remove location when it matters. Share sheet, Options, Location off. Apple's own method, about five seconds.
  2. Verify rather than assume. Send it to yourself through the real path and read the received file.
  3. Do not rely on airplane mode. The FBI states that "devices in airplane mode can still capture geo-location information". GPS reception is passive.
  4. Do not rely on shrinking the image. Per the same notice, "EXIF data and image quality have no correlation."
  5. Look at the picture, not just the file. The window view, the street sign and the reflection outlast every metadata strip.

"Use an EXIF viewer to verify that you were successful in stripping the personal data from the photos before sharing." (FBI Portland, 17 November 2020)

Key takeaways

  • A surviving GPS block locates you to a few metres. Berkeley matched geotagged photos to Street View within about one metre.
  • Only about 2% of scraped web images carry GPS, because platforms drop EXIF when they recompress uploads.
  • The inversion that matters: your public post is probably clean, the original you AirDropped or emailed probably is not.
  • McAfee's EXIF destroyed his alibi rather than locating him; Ochoa's was corroborating, not decisive.
  • BTK, Reality Winner and the Strava heatmap are not photo-metadata cases, and the 2007 Apache story never names a device.
  • Stripping EXIF does not anonymise a photo. Reflections, signage and window views located people without any metadata.
  • Airplane mode does not stop geotagging, and shrinking an image does not remove EXIF.

Frequently asked questions

Can someone find my address from a photo I sent?

If the photo carries a GPS block and reached them as an original file, yes, to within a few metres. Berkeley researchers matched geotagged photos to Street View imagery within about one metre. If it went through a platform that re-encodes uploads, the coordinates were probably dropped.

How often do photos actually contain GPS coordinates?

Less often than the warnings suggest. Clearview AI told a UK tribunal that about 2% of three billion scraped images carried geolocation EXIF. A Berkeley study found 4.3% of Flickr uploads geotagged. Most uploads lose EXIF because platforms recompress them.

Did photo metadata really catch John McAfee?

Not quite. A Vice photo published in December 2012 carried iPhone GPS placing him in Guatemala, which destroyed his claim to be elsewhere. He admitted it the next day, then surfaced publicly himself and was arrested for illegal entry. The metadata exposed a lie rather than leading anyone to him.

Can someone find my location from a photo without GPS data?

Often, yes. The image itself carries clues: signage, architecture, plants, skyline, even reflections in a subject's eyes. A Japanese stalker located a pop singer in 2019 using a reflection in her pupil matched against Street View. Stripping EXIF does not make a photo anonymous.

Does screenshotting a photo remove its location?

Yes, for metadata. A screenshot is a new file created by your device with no camera GPS block. It does not remove anything visible in the picture, and the image contents are frequently more identifying than the coordinates ever were.

Is airplane mode enough to stop geotagging?

No. The FBI's Portland field office states plainly that devices in airplane mode can still capture geo-location information. GPS reception is passive and does not require a network connection. Turn off Location Services for the Camera app instead.

Before you share

Find out what you're sending.

Image Inspector reads the GPS block, the capture time and the device out of a photo on your iPhone: the same reading anyone receiving it could do.

Download Image Inspector on the App Store
Image Inspector app icon

About the author

The Image Inspector team · BigBalli

Image Inspector is an iOS app that reads a photo's EXIF, GPS and Apple MakerNote fields on device and reports what travels with the file. We build metadata parsers, which is why this page went to the FBI affidavit and the tribunal judgment rather than to the retellings.