You post a photo of a room and assume the location went with it. Or you post it and assume the platform took care of that. Both assumptions are wrong often enough to matter, and the truth varies by platform, by upload path and by month.
The short answer is that Instagram does remove EXIF data from the image other people can download. The longer answer, which is the one that actually protects you, involves what stripping does not cover.
Does Instagram remove EXIF data from your photos?
Yes, from the file served to other users. Instagram re-encodes every upload to its own dimensions and compression settings, and metadata is discarded as a consequence of that pipeline rather than as a deliberate privacy feature.
This distinction matters more than it sounds. Stripping is a side effect of processing, which means it happens because of how the platform prepares images, not because of a promise made to you. Change the pipeline and the behaviour changes with it, without an announcement.
Facebook behaves the same way, which is unsurprising given the shared infrastructure. X re-encodes and strips. Reddit strips on direct image uploads. TikTok, Snapchat and Pinterest all process images heavily enough that metadata rarely survives.
Which platforms strip metadata, and which quietly do not
The pattern is simple once you see it: anything that re-encodes strips, and anything that stores your original does not.
Re-encoding platforms include the large social networks, most modern image hosts and any service that generates multiple sizes for responsive display. If a service shows your photo at a different resolution than you uploaded, it re-encoded it.
Pass-through cases are the ones that catch people out. Many forums store the uploaded file directly. A good number of small business websites and older content management systems serve exactly what was uploaded. File-sharing links hand over the original by definition. Marketplace and classified sites vary enormously, and several of them display the photo you gave them without touching it.
We deliberately are not publishing a table of platform-by-platform behaviour with dates attached, because that table would be wrong within months and people would keep citing it. Test your own file if it matters: upload it, download it back, and read the result in our image metadata viewer.
The WhatsApp document path keeps everything
This is the single most useful thing on this page.
WhatsApp has two ways to send an image. The photo path compresses aggressively, resizes and drops the metadata, which is why a picture received in a chat is usually clean. The document path attaches the file as-is, and the recipient gets the bytes you sent — GPS, serial number, timestamps and all.
People use the document path on purpose, to preserve quality when sending photos to family or clients. That is a good reason to use it, and it means those files carry everything. If you have ever sent holiday photos as documents to avoid the compression, you sent your coordinates with them.
Telegram works the same way, with a compression toggle at send time. Signal strips metadata from images it processes, which is consistent with the rest of its design, but the same file-attachment caveat applies.
Video follows a different pipeline again. WhatsApp re-encodes clips far more aggressively than photos, which is why people end up reaching for a WhatsApp video compressor to get under the cap in the first place. We measured what that cap actually is in the piece on WhatsApp file size limits.
Email attachments keep EXIF almost every time
Mail was never in the image-processing business. A client treats an attachment as an opaque blob and passes it through untouched, so a photo emailed to an estate agent, an insurer or a job application arrives exactly as it left your camera.
Inline images are less predictable. Some clients resize a picture pasted into the message body, some do not, and webmail behaves differently from desktop software. The safe assumption is that anything attached is the original.
This is where cleaning first genuinely earns its place. Email is the most common way people send photos to organisations they have no relationship with, and it is the path least likely to protect them. Our metadata remover handles this in a few seconds without re-encoding the picture, so the recipient still gets full quality.
Does the platform still see your GPS after stripping?
Almost certainly, and this is where a lot of privacy advice goes quiet.
Stripping happens during upload processing, which means the service had the complete file first. Whether it retains anything it read is a matter of policy and infrastructure that you cannot inspect from outside. The stripped image protects you from other users downloading your photo and reading its coordinates. It says nothing about what the service kept.
We are not accusing anyone of anything specific. The point is structural: uploading a file to a service means that service has the file. If a photo's location is genuinely sensitive, the only reliable control is to remove it before the upload rather than to rely on the upload to remove it. That is the entire argument for cleaning locally, and it holds regardless of which company you trust.
What stripping does not touch
Three things survive every pipeline described above.
The picture itself. A street sign, a house number, a distinctive view from a window, a reflection in a kettle. Metadata is the easy half of what a photo gives away, and no amount of stripping addresses the other half.
Your account. The platform knows who posted, when, from what device and from what IP address. Removing metadata from a file does nothing about any of that.
Anything encoded into the pixels. Invisible watermarks and content credentials are designed to survive re-encoding. We do not claim to remove them, and neither should anyone else.
The habit that actually works
Stop trying to remember which platform strips what. The rules change, they are undocumented, and getting it wrong is silent.
Clean the file before it leaves your machine when it is going anywhere public or to anyone you do not know. Check it once with a photo location lookup if the coordinates are the specific worry. And if you would rather the data was never written at all, switching off camera geotagging takes two minutes and covers every photo you take afterwards. The full pre-upload routine is in our checklist for posting photos online.
If the fields themselves are new to you, start with what a camera actually records. And before you use a surviving metadata block to settle an argument about when or where a photo was taken, read how little any of it proves — editable fields make poor evidence, whichever side you are on.
