Sending a Photo as a Document Is Handing Over Your Location
Published September 27, 2026
Photos sent as documents travel completely unmodified, GPS coordinates included. Here is how to strip that metadata before you share anything.

There is one habit almost everyone follows without thinking. We pick "send as document" so the photo quality does not get mangled. In that mode the file travels from your phone to the recipient's device without a single byte changed. The entire EXIF block comes along too, GPS coordinates included, sometimes accurate to within a few metres.
In other words, when someone asks for your original file and you send it over WhatsApp or Telegram in document mode, you are not sending a photo. You are sending a map of where you live.
What is actually hidden inside a photo
EXIF is a metadata block embedded in the image file. What makes it different from an ordinary file is that you cannot see it when you open the picture, yet it is read every single time the file is sent.
- GPS coordinates โ latitude and longitude, sometimes precise to a few metres
- Device make and model, plus lens details such as aperture and ISO
- The exact date and time the shot was taken, which is not the same as when you shared it
- Serial numbers and the editing software that touched the file
- Edit history โ some cameras write their editing mode straight into the file
There is one more leak people forget about. The file name gives the time away on its own. Android produces names like IMG_20250723_103045.jpg, which tells anyone exactly when the photo was taken, even after the metadata inside has been stripped.
Two sending modes, two very different risks
Several teams retested this behaviour in 2026 using ExifTool to inspect what actually arrived on the other end. The pattern was consistent. Compression removes metadata, and no compression keeps all of it.
- WhatsApp, photo mode โ EXIF is dropped, GPS included
- WhatsApp, document mode โ all metadata is kept, and the file reaches the recipient identical to the original
- Telegram, photo mode โ EXIF is dropped
- Telegram, file mode โ metadata is kept entirely. On Telegram Desktop, simply dragging a photo into the chat window often triggers this mode without you noticing
- Signal โ the rarely mentioned exception, because it strips metadata in both modes
- Instagram, Facebook, X โ they remove EXIF from the public copy but still keep it themselves
- Email, Google Drive, Dropbox, AirDrop, and iMessage โ metadata is preserved as-is, because the file is moved rather than processed again. Discord behaves the same way, including in document mode
So the practical rule is this. The moment you hit "send as document" to protect quality, you have switched on the mode that preserves the most metadata. Image quality goes up, and privacy goes down.
The Meta case: 30,000 private photos from a single script
In April 2026, the Metropolitan Police was investigating a former Meta employee. According to court papers seen by reporters, he was alleged to have accessed and downloaded approximately 30,000 private images belonging to Facebook users, and to have written a script designed to get around Meta's own internal detection systems. He was arrested in November 2025 on suspicion of unauthorised access to computer material, and the case reached the UK through a referral from the FBI.
One thing is worth stating plainly. This case had nothing to do with EXIF. The access came from a program inside the company, not from metadata inside a photo. And that is exactly the part that matters. Metadata is one layer among several, and the layer people ignore most is the one that is easiest to protect.
Checking your own photo before you share it
You do not have to guess. Look at what is in there first.
- On Windows โ right-click the photo, open Properties, go to Details, choose Remove Properties and Personal Information, and create a copy
- On macOS โ open the image in Preview, choose Tools, Show Inspector, click the GPS tab, then Remove Location Info. For everything else, re-exporting the file is usually enough
- On iPhone and Android โ there is no built-in remover at all, so you need a dedicated third-party app, such as Scrambled Exif on Android or ViewExif on iOS. On macOS, Preview can only strip location details, so a full clean still needs a tool such as ExifTool
- Avoid online EXIF viewers that upload your file to their server. If you are already worried about metadata, handing a photo to a stranger's server creates a second problem. Pick a tool that runs inside your browser
There is one free trick that genuinely works. Send the photo to yourself on Signal, which strips metadata in both modes. It is not elegant, but it is free and needs no account.
Removing metadata before you send
The principle is simple. Metadata does not disappear because something deleted it, but because the pixels are written again from scratch. A tool like this loads your image into a canvas in the browser, draws it again, and re-encodes it. The re-encoded file has nowhere left to keep EXIF, because no data other than pixels was carried across.
- Nothing is uploaded to any server
- No account needed, and nothing is stored
- You can check the result yourself instead of trusting the tool's word
There is a free tool for this on Loonix. Open Remove EXIF Metadata, drop in your photo, and it will show you what is inside the file before it cleans anything. Once it is done the resulting bytes are scanned again, so you know the output is clean because it was inspected, not because somebody claimed it was.
What survives even after the metadata is gone
Cleaning EXIF does not make a photo anonymous. Other things still leak identity or location.
- The file name may still carry the date and time
- What is visible in the frame โ a wall clock, a calendar, a smartwatch screen, a school uniform, a window that reflects the room, a shop sign that happens to be in shot
- Communication metadata โ who sent it, when, and from which device. This lives outside the file and cannot be removed from inside it
- The destination platform โ if you ever uploaded the original to Instagram or Google Photos, its metadata is already recorded there
So for genuinely sensitive photos, cleaning the file alone is not enough. The safer combination looks like this. Turn location tagging off in your camera, clean the file, then send it through a channel that does not store metadata, such as Signal or Proton Mail, which offers a "Remove metadata" option for image attachments.
One thing to keep in mind every time you are about to hit send. Your metadata is not your recipient's to keep. Removing EXIF closes one layer only, but that layer is cheap to fix and entirely in your hands.
Share this article
Share to
Related articles

September 27, 2026
A Quarter of Long-Form Social Posts Are Fully Machine-Written
Pangram scanned over a million posts and found 41 percent of LinkedIn long-form fully machine-written. The detector itself has a bigger problem.

September 27, 2026
Passkeys Can Be Hijacked Without Ever Touching Your Fingerprint
Windows malware can reuse your Google-synced passkey with no biometric, no device unlock, and no consent. Here is what actually happened.

September 26, 2026
5 Potensi Sanksi yang Mengintai Manchester City dalam Kasus 115 Tuduhan Premier League
Proses hukum Manchester City terkait dakwaan pelanggaran finansial masih berjalan tanpa keputusan final per September 2026. Berikut adalah rincian kasus, preseden liga, dan 5 bentuk sanksi yang berpotensi dijatuhkan komisi independen.



