2026-09-03
National Preparedness Month: FEMA says photograph everything you own — what rides along in that home inventory
Each September, FEMA's Ready campaign runs National Preparedness Month — 2026's theme is "Americans Stand Ready" — and the advice at the center of it has been steady for years: before anything happens, photograph what you own and gather copies of the documents that prove who you are. It is good advice, and the agencies giving it are unusually specific about the deliverable. What none of them mention, because it isn't their job to, is that following it produces a folder of files carrying an unusually complete set of embedded metadata — and that the same guidance, quite correctly, tells you to send copies of that folder out of your house.
What the official advice actually asks you to make
FEMA's one-page handout Safeguard Critical Documents and Valuables (FEMA P-1096) opens with "The first step is to take an inventory of your household documents, contacts, and valuables," then spells out what belongs in it: vital records — "birth, marriage, divorce certificate, adoption, child custody papers" — plus "Passport, driver's license, Social Security card, green card, military service identification," the housing file ("lease or rental agreement, mortgage, home equity line of credit, deed"), and the vehicle file ("loan documents, VIN, registration, title"). Its companion sheet, Document and Insure Your Property (FEMA P-1097), covers the belongings side: "You can take photos or videos to help you record your belongings, but be sure to also write down descriptions, including year, make, and model numbers, where appropriate."
State insurance regulators say the same thing in more operational terms. The NAIC's disaster preparedness guidance tells consumers to "take photos of each item and include any receipts," or, if time is short, to "quickly videotape and/or photograph every room." Its own free home-inventory app is described as one that will "produce a back-up file that you can easily email to yourself or your insurance agent."
Then comes the part that matters most here: every version of this guidance tells you to get copies out of the building. FEMA P-1097: "Leave copies with trusted relatives or friends. Secure electronic copies with strong passwords and save them on a flash or external hard drive in your waterproof box or safe." Ready.gov's financial preparedness page: "Store important documents either in a safety deposit box, an external drive or on the cloud to make it easy to access during a disaster." The NAIC: keep back-ups "somewhere besides your home, like with a family member or your insurance agent, so that you can access it even if you have to evacuate and cannot return home." All three are right — a fireproof box is worthless if the house is gone. All three also describe a file leaving your control.
What that folder looks like from the outside
Do the whole exercise properly and you end up with something most households never otherwise assemble: a few hundred photos walking room by room through your home, and a stack of scans of the exact documents on FEMA's list. It is, in one directory, a floor plan, an asset list, and an identity kit. That is the point — it is supposed to be complete enough to rebuild a life from. It is also the single worst folder in your possession to copy carelessly, and the guidance above asks you to copy it at least twice.
The photos carry the layer people forget. A phone photo's EXIF block records where the shutter was pressed, and for a home inventory that location is, by definition, your home — repeated across every file. The Defense Department's own news service put the mechanic plainly in Geotags invade privacy and OPSEC (2011), quoting Maj. Rocky Williams: "Every time you take a picture, shoot video and share it with your friends, you pass grid coordinates of where you did that action." The same piece quotes Cpl. Jose Ramos on the second-order problem, which is exactly the evacuation scenario the preparedness advice is written for: "I never thought about what would happen if I checked into a location and accidentally let the entire world know I wasn't home." A geotagged inventory photo says both things at once — this is the address, and this is what is inside it.
The scans have a layer of their own
The document half of the folder carries a different set of fields. A PDF keeps a document information dictionary — Title, Author, Subject, Keywords, Creator, Producer, CreationDate, ModDate — which is where the scanning app or word processor writes its own name and, very often, yours; a PDF can also carry a separate embedded XMP metadata stream saying much the same thing again. If any part of your inventory is a spreadsheet or a Word file, Microsoft's own Document Inspector documentation describes what is in there: "Document properties, or metadata, include details about your document such as author, subject, and title. Document properties also include information that is automatically maintained by Microsoft 365 programs, such as the name of the person who most recently saved a document and the date when a document was created." None of that is visible on the page, and all of it travels with the file.
Why the master set should keep its metadata
The obvious reaction — strip everything, everywhere — is the wrong one, and it is worth saying so on a metadata scrubber's own blog. The whole purpose of the inventory, in the NAIC's framing, is to help you prove what you owned; FEMA P-1097 makes the same point about speeding a claim. Original files with their original capture dates are the strongest version of that record you will ever have, and there is no benefit to you in weakening the copy nobody else will see. Microsoft's Document Inspector page gives the same instruction for its own tool, for the same reason: "It's a good idea to inspect a copy of your original document, because it's not always possible to restore the data that the Document Inspector removes."
So the rule is a split, not a purge. One master set, untouched, protected the way FEMA already tells you to protect it — "Secure electronic copies with strong passwords and save them on a flash or external hard drive in your waterproof box or safe." Then a second, scrubbed set for every destination that isn't you: the relative holding a backup, the shared cloud folder, the agent's inbox, and — the one that arrives suddenly and under pressure — the damage photos you post in a neighborhood group or a fundraiser after something actually happens.
Why the cleaning step can't itself be an upload
This is the specific case where "just use an online metadata remover" collapses. The files in question are scans of a passport, a Social Security card, and a deed. Handing that folder to a web service to have its metadata cleaned means uploading exactly the documents you were trying to handle carefully, to a server you know nothing about, to solve a privacy problem. NearScrub runs the whole operation inside the browser tab: the file is read locally, rewritten locally, and handed back as a download. Nothing is uploaded, and there is no server to have a copy.
Concretely, on the file types this folder is made of. For a JPEG it drops the APP1 Exif segment (GPS coordinates, timestamps, camera make and model), the APP1 XMP segment, the APP13 IPTC/Photoshop block, and any COM comments, copying the pixel data through untouched — the one thing deliberately re-added is the EXIF orientation flag, values 1 through 8, so portrait phone shots don't come back sideways. PNGs lose their tEXt, zTXt, iTXt, eXIf and tIME chunks. PDFs have the Info dictionary keys deleted outright — Title, Author, Subject, Keywords, Creator, Producer, CreationDate, ModDate — and the XMP metadata stream removed with them. docx, xlsx, pptx, odt, ods and odp files get docProps/core.xml, app.xml and custom.xml blanked, which is where author, last saved by, company and custom properties live. Two details that matter for a job this size: you can drop the whole set in at once and get a per-file report of what each one is carrying before anything is removed, and a batch comes back as a single zip rather than one download at a time.
What it doesn't fix
Being exact about the gaps matters more than usual with a folder like this one. Scrubbing metadata does nothing about visible content: the passport number is printed on the page, the house number is in the photo of your front door, and no metadata tool touches pixels. It is not encryption — FEMA's "strong passwords" step is a separate job, and a scrubbed file is exactly as readable to anyone who gets it. iPhones shoot HEIC by default and NearScrub doesn't parse it, so convert to JPEG first; the same goes for the video walkthrough FEMA and the NAIC both suggest, since MOV and MP4 aren't supported at all. And it is retroactive for nothing — a copy already sitting in a relative's cloud drive still carries whatever it carried when it was sent.
The folder worth being careful with
The reason to bother is on FEMA's own disaster fraud page, which warns that "con artists and criminals may try to apply for FEMA assistance using names, addresses and Social Security numbers they have stolen from survivors." A preparedness folder is a pre-assembled version of precisely that combination, and it is built during the calm part of the year specifically so it can be sent somewhere in a hurry during the bad part. National Preparedness Month is a good month to build it. It is also the right month to decide, once, which copy is the master and which copies get cleaned on the way out — because the copy you make while evacuating is not the one you'll be thinking carefully about.