2026-08-10
What domestic violence safety guides say about photo metadata — and where a scrubber like NearScrub fits
When someone rebuilds a life after leaving an abusive relationship, photos come back into the picture faster than people expect — a listing photo for a new apartment, a profile picture for a dating app started fresh, images attached to a GoFundMe, exhibits for a protective-order filing. The safety guidance that keeps surfacing for exactly this moment isn't about who can see the photo. It's about what's riding inside the file underneath it.
What the safety guides actually say
The National Network to End Domestic Violence's Safety Net Project — the organization's technology-safety arm, published at techsafety.org — puts it plainly in its guidance on limiting location exposure: "all the pictures that you take will have the location information embedded in the photograph... This is called geotagging," and turning that setting off is "especially important" for survivor safety. Its companion guide to cameras makes the same point about the file itself, not the app: "Many video and picture files downloaded from cameras embed time, date, and location information in the file" — data that travels with the photo however it's shared, days or years after it was taken.
The scale behind that advice is documented, not assumed. In a national survey of U.S. domestic violence programs that NNEDV still cites on its own site today, 97% reported working with survivors whose abusers had misused some form of technology to stalk, monitor, or harass them. As NNEDV's Toby Shulruff put it, "every survivor is different and will likely have different safety needs" — which is exactly why a single tool, including a file scrubber, is one piece of a plan rather than the plan itself.
Two different location risks, and only one lives in the file
The guidance above is actually describing two separate ways a photo can expose where someone is — and a metadata scrubber only reaches one of them.
What NearScrub actually clears
Drop a JPEG or PNG onto NearScrub and it processes entirely inside the browser tab — nothing uploads anywhere, which matters specifically here, since a photo tied to a new address is exactly the kind of file someone shouldn't want passing through an unknown third-party server just to get the GPS tag removed. For a JPEG, NearScrub drops the entire EXIF block (including GPS coordinates), any XMP metadata, IPTC/Photoshop fields, and comment segments, while leaving the pixel data untouched. For a PNG it drops the equivalent text and timestamp chunks. The same applies to documents that carry their own hidden fields — a PDF's Info dictionary (Title, Author, Creator, dates) and XMP metadata stream, or a Word, Excel, or PowerPoint file's docProps (author, company, last-modified-by, custom properties) — which matters for a lease application, a court exhibit, or a resume for a new job started after leaving. A report shows which files actually carry GPS or other metadata before anything is scrubbed, and a multi-file batch comes back as a single zip.
The catch: iPhone photos are usually HEIC, not JPEG
This is worth stating plainly, because it affects the phone most people already carry. Since
iOS 11, an iPhone's default camera format is HEIF (saved as a .heic file), not JPEG —
Apple's own support documentation confirms High Efficiency is still the default capture format on
current devices. NearScrub reads JPEG, PNG, PDF, and Office files; it doesn't parse HEIC. A photo
pulled straight from an iPhone's camera roll and dropped onto NearScrub as-is will show up
unsupported, with nothing removed — which, in this context, is the opposite of the mistake to make.
The fix is usually already in place without anyone noticing: Apple's documentation says sharing HEIF media "using other methods, such as AirDrop, Messages, or email" to a device that doesn't support the newer format converts it "in a more compatible format, such as JPEG" automatically. A photo received by text, saved from a website, or AirDropped from someone else's phone is often already a JPEG. If it isn't, Settings → Camera → Formats → Most Compatible switches new photos to JPEG going forward (existing HEIC photos still need converting — Photos or Preview's File → Export saves a JPEG copy). Check the file extension before assuming a photo was scrubbed when it was actually never read.
What metadata removal can't do
Clearing a file's EXIF and XMP data doesn't touch the right-hand column in the diagram above, and none of it is a small gap. A device with stalkerware installed will keep reporting location regardless of what any individual photo file contains. A car with a tracker attached, a shared family-locator app still logging both accounts, or a platform that stamps its own metadata onto an upload after the fact are all outside what a client-side scrubber can reach by design — it only ever sees the file before it leaves the device, not what happens to a copy, or a tracking device, on the other side. This is the reason NNEDV's own guidance frames technology safety as a plan built with an advocate rather than a single checklist: what's relevant depends on which of these risks actually applies to a specific situation. Anyone in immediate danger should call 911; the National Domestic Violence Hotline (1-800-799-7233, thehotline.org) helps build the fuller technology safety plan that a metadata scrubber is only ever one piece of.
Before a photo or document goes anywhere
Look at the frame itself first — a street sign, unit number, or landmark that gives away a new address doesn't live in metadata, so no scrubber will catch it. Confirm the file is actually a JPEG, PNG, PDF, or Office document rather than HEIC, converting first if it isn't. Then run it through NearScrub so GPS coordinates, camera details, and any XMP, IPTC, or document-property fields are gone before the file exists anywhere outside the device — and treat that step as one part of a safety plan, not the whole of one.