2026-07-31
Does Facebook Marketplace or Craigslist strip your photo's GPS data? What two independent tests found
Selling something online almost always starts the same way: point a phone at the item, snap a photo, upload it. Nobody stops to think about the file itself — only the picture. But the file carries more than the picture. Every one of those photos can include an Exif block recording exactly when and where it was taken, and depending on which app you're using to sell that old bike or that spare monitor, that location data may ride along all the way to a stranger's screen. Whether it does is less predictable than most people assume.
What a photo can tell a stranger without you saying a word
Consumer Reports ran this experiment directly: a black-and-white photo of a boy in a Little League uniform at home plate, with no caption and nothing visible in the frame that named a place. Its Exif data alone was enough to establish that the game was played at 7:15 p.m. on June 6, 2018, on "a dirt baseball diamond behind a church in a small town in Ohio," shot on an iPhone X. Nobody had to guess or investigate — the coordinates were sitting in the file the whole time. Jonathan Rajewski, a digital forensics expert and vice president at the cybersecurity firm Stroz Friedberg, told the magazine about the online-marketplace version of the same problem: a Craigslist seller once sent him product photos with the GPS tag still attached. "I'm like, 'I now know where you live, but I don't really want to know where you live,'" he said — and then walked the seller through what had actually just happened, so they could make a better call next time.
Two tests, three years apart, checked which platforms strip it — and mostly agreed
The reassuring-sounding fact is that several major platforms do remove Exif data from photos on upload. Kaspersky's official blog ran its own test in October 2016 and found that Facebook, Twitter, VK.com, Instagram, eBay, and Craigslist all deleted metadata, while Google+, Flickr, Google Photo, and Tumblr did not. Consumer Reports' December 2019 update, run independently three years later, found much the same shape: Facebook, Instagram, WhatsApp, Twitter, Imgur, and Craigslist stripped it; Flickr, Google Photos, and Apple Photos kept it. Four platforms — Facebook, Twitter, Instagram, and Craigslist — showed up on the "strips it" side of both tests, three years apart, which is about as close to corroboration as two independent point-in-time investigations get.
"Tested and found to strip it" is not the same as "guaranteed to strip it"
Two things are worth being precise about here, because the reassuring headline result hides both of them. First, these are point-in-time tests, three years apart, of upload behavior that any of these companies can change without telling anyone — nothing about a platform's Exif-handling policy is contractual or permanent, and neither list above should be read as current fact rather than what two specific investigations found on the dates they ran them. Second, and more important for anyone actually selling something: both tests were about what happens to a photo uploaded through the platform's own public-listing flow. Neither test says anything about a photo sent a different way — attached to a direct message, emailed straight to an interested buyer, texted over after someone asks "got any more pictures?" That's the exact shape of Rajewski's Craigslist anecdote: the leak wasn't in the public listing, it was in the follow-up photos sent directly, outside whatever stripping the platform's main upload path might have applied.
Kaspersky's own caveat is worth repeating, not skipping
It's tempting to read "thieves target sellers using their listing photo's GPS data" as an established fact, because it circulates as one. Kaspersky's own 2016 piece is careful not to claim that: it says "stories abound of items in 'for sale' posts being stolen, presumably a result of thieves figuring out their location from photo metadata" — hedged language, not a documented case with a name and a date attached, unlike the McAfee or Reality Winner stories. The honest version of this post's argument doesn't need that claim to be true. It only needs the two things that are independently verified: the metadata really is in the file by default, and whether any given sharing path removes it is inconsistent and unverifiable in the moment you hit send.
What actually closes the gap
The one step that doesn't depend on which platform, which year, or which sharing path a buyer's follow-up question sends a photo down is removing the Exif data before the file exists anywhere except your own device. That's what NearScrub does for JPEG and PNG files: drop the photo in, and the GPS coordinates, timestamp, device identifiers, and other Exif/XMP/IPTC fields come out entirely inside the browser, before the file goes anywhere — no upload, no server, and no dependence on whether Craigslist's stripping policy in 2026 still matches what a 2016 or 2019 test found. The listing photo, the follow-up shot a buyer asked for, the one texted instead of posted — all of them start from the same clean file, so it doesn't matter which path they take out.