2026-08-14
What EFF's and AFSC's protest safety guides actually say about your photos' metadata
Most advice about posting protest photos safely leads with the same instruction: blur the faces. That's necessary and it's not enough. A photo can have every face carefully blurred and still carry the exact GPS coordinates of where it was taken, the model of phone that took it, and — depending on how the photo was captured and named — details that trace back to whoever was holding the camera. Two different privacy problems live in the same file, one visible and one invisible, and safety guides that cover protest photography are explicit that both need separate handling.
What EFF's and AFSC's own guides say about the invisible part
The Electronic Frontier Foundation's Surveillance Self-Defense guide has a dedicated "Attending a Protest" module, and its language on photo metadata is direct: a photo's metadata "can include information such as the model of camera the photo was taken on, the exact time and location where the photo was taken, and even your name." The American Friends Service Committee's own "Digital Security Guidelines for Protests" carries almost identical wording in its section on what to do after a protest. Neither organization is speculating about a hypothetical risk — both are describing the same EXIF fields that live in essentially every photo taken on a phone or camera with location services on: a GPS tag precise enough to place a photo at a specific corner or building, a device identifier, and a timestamp.
The workarounds the guides suggest, and where they run out
EFF's guide doesn't just name the problem — it offers two ways around it, and both are worth looking at honestly. The first: move the photo to a desktop computer and take a screenshot of it, then post the screenshot instead of the original file. The second: send the photo to yourself through Signal, since Signal strips metadata from images on send, then repost the copy Signal delivers back. Both work. Both also cost something — a screenshot re-encodes the image and can visibly soften detail that matters in a documentation photo (a badge number, a vehicle plate, a banner's text), and the Signal round-trip only helps if everyone in the chain already has Signal installed and remembers to use it that way in the moment, which is a lot to ask of someone filming with shaking hands. AFSC's guide, for its part, warns about the same metadata fields but stops there — it doesn't recommend a specific removal step at all. Neither gap is a criticism of either guide; digital-security guides are necessarily general-purpose. But the space between "here's the risk" and "here's a lossless way to remove it without a workaround" is real, and it's exactly where a purpose-built tool belongs.
A tool already built for exactly this
That tool already exists in one specific form, and it's worth naming because it's precedent, not competition: Image Scrubber, a free, open-source, browser-based tool built by programmer Everest Pipkin specifically for protest photography, first covered by Inverse and by Vice's Motherboard back in 2020 and still live today. It runs entirely client-side, strips EXIF metadata, and lets you paint or blur over faces before you export the image — the same two-part job EFF's guide describes, done in one pass, with no screenshot re-encode and no dependency on a specific messaging app. Its continued use inside activist communities is itself evidence that "strip it locally, in the browser, before it's shared" isn't a theoretical best practice — it's a workflow people documenting protests already trust.
Why this isn't hypothetical in 2026
The guides above were written as general protest-safety advice, but the specific concern they describe — that identifying details in a shared photo can end up in the hands of an agency actively building a profile of who was present — has recent, documented grounding. NPR reported in June 2026 that then-acting ICE director Todd Lyons acknowledged, in an April 2026 letter to Congress, that the agency collects "biographic and biometric information" on people encountered at operations who were never arrested — protesters and observers included — while still denying it maintains a formal "database." The same report cites a January 2026 DHS memo directing agents in Minneapolis to collect protesters' license plates, IDs, and images. None of that changes what a metadata scrubber can or can't do, but it's a straight answer to the obvious question of who, specifically, a stripped GPS tag or device identifier is being kept away from.
Where NearScrub fits, and where it doesn't
NearScrub does one half of what EFF's and AFSC's guides describe, and it's worth being precise about which half. It strips EXIF and GPS data, XMP, and IPTC/Photoshop metadata from JPEG and PNG photos entirely in the browser — no upload, same no-server architecture as everything else this app does — which covers the exact fields both guides quote: camera model, timestamp, location, and any embedded name. It does not blur or redact anything in the image itself; faces, plates, and banners still need a separate pass, whether that's Image Scrubber, an editing app, or manual blurring — the same second step every guide above lists as a distinct task. Where NearScrub reaches slightly further than a photo-only tool is the paperwork that circulates around an action alongside the photos: a legal-observer intake form, a bail-fund contact sheet, or a flyer saved as PDF or docx can carry an author name or last-modified-by field in its own hidden properties, the same way any Office document does — NearScrub clears those too, in the same drag-and-drop pass, for the organizers handling that side of things.
Before it leaves your device
The order matters more than the tool. Blur what's visible, strip what isn't, and do both before the file is posted or handed off — not after someone has already saved a copy of the original. A screenshot or a Signal round-trip gets the metadata out at a real cost to image quality or workflow friction; a scrubber built for the job removes it losslessly, locally, in the time it takes to drag a file into a browser tab.