Back to blog
EXIF6 min readSeptember 10, 2026

What a photo really reveals about you

GPS position, camera serial number, software history — a tour through the metadata of a typical smartphone photo.

A photo is never just pixels. Every time you press the shutter, your camera or phone writes a second layer into the file: metadata. It describes where you were, which device you used, how the image was edited — and sometimes much more.

The layers inside a photo

Most photos from phones and cameras are JPEG files with several metadata blocks:

  • EXIF — the technical heart. Camera make and model, lens, exposure settings, timestamps, orientation, and often a GPS position with altitude.
  • XMP — an XML-based format used by editors such as Lightroom or Photoshop. It stores editing history, ratings, keywords and sometimes a copy of the GPS coordinates.
  • IPTC — classic press metadata: byline, copyright notice, captions, city and country.
  • Embedded thumbnails — small previews that can survive heavy editing and still show the original scene.

Why it matters

Three examples from everyday life:

  1. You sell something online. A photo of your sofa, taken in your living room, contains the coordinates of your home. The buyer now knows your address before you ever meet.
  2. You apply for a job. The CV photo carries a camera serial number. It is a unique device fingerprint that can be linked to other photos you published elsewhere.
  3. You post a photo "from the office". The metadata shows a different location, a different time, and editing software that the original never had.

None of this is visible in the image itself. You only see it when you look at the metadata.

What a typical report looks like

When ShredHub analyzes a photo, it groups the findings by risk:

  • Location — latitude, longitude, altitude, city names.
  • Device & hardware — make, model, lens, serial numbers.
  • Identity & authorship — artist, creator, owner, last modified by.
  • Software & edit history — editing tools, version numbers, revision counts.
  • Timestamps — capture, digitization and modification dates.
  • Embedded data — thumbnails, previews, sometimes trailing bytes after the end of the file.

Each field gets a risk rating, and the overall score tells you how exposed the file is.

How to check your own photos

  1. Open the file in ShredHub (it runs entirely in your browser — nothing is uploaded).
  2. Read the report. If there is no location or identity group, you are already in good shape.
  3. Use the standard cleaning preset to remove identifying fields, or minimal if you only want to remove the GPS position and keep the camera details.
  4. Download the cleaned file and scan it again — ShredHub re-analyzes the result and shows a verified clean badge when the metadata is gone.

The takeaway

Metadata is not inherently bad. It is what makes photo libraries searchable and helps photographers prove authorship. The problem starts when files leave your control without you knowing what travels with them. Check before you share — it takes seconds.