NearScrub

2026-09-01

Yes, social platforms strip your EXIF — after reading it: what IPTC's tests and Facebook's own policy show

Bring up photo metadata in almost any forum and the same reassurance appears within a few replies: it doesn't really matter, because the big platforms strip EXIF on upload anyway. Half of that sentence is true, and it's the half that protects you from other users. The other half — the part the reassurance quietly skips — is that stripping happens on the platform's servers, after your original file has already arrived there in full. Two organizations have documented both halves better than anyone: the IPTC, the standards body behind news-photo metadata, which has been uploading test images to social platforms and measuring what survives since 2013; and Facebook itself, whose own privacy policy states in plain language what it collects from the files you hand it. Read together, they turn "the platform strips it anyway" from an answer into a question: stripped for whom?

What the stripping actually protects: viewers, mostly

The IPTC's Photo Metadata Working Group ran its social media metadata tests in 2013, 2016, and 2019, using a reference image filled with known values in every standard field, then checking what a viewer could still extract after upload. The consistent result: most social platforms remove most embedded metadata from the copies other people see or save. In the 2019 round, Twitter stripped both Exif and IPTC fields from saved files, Instagram offered no original download at all, and Facebook removed all XMP metadata. So the reassurance is not wrong about its own narrow claim — a stranger right-clicking your Facebook photo generally does not get your GPS coordinates. It's worth saying clearly that this viewer-facing stripping is real and does useful work; the October 2025 Partiful case, where a platform failed to do it, shows what happens when it's missing. The IPTC's own complaint, incidentally, ran the opposite direction: the tests were built to show that platforms delete photographers' rights and credit information along with everything else.

What stripping can't do: unread the file

Upload doesn't send the platform a cleaned copy — it sends the file, and the file is whatever your camera wrote. The stripping the IPTC measured happens during the platform's own processing, which means the original bytes, GPS block included, sit on the platform's infrastructure first. And in Facebook's case there's no need to infer what happens next, because the Data Policy said it outright: the company collects "information in or about the content that you provide (e.g. metadata), such as the location of a photo or the date a file was created." That's not a leak or a lab finding — it's the disclosure document. The EXIF stripping and the metadata collection are not in tension; they're two steps of the same pipeline. The platform reads the metadata, keeps what its policy covers, and then serves other users a copy with most of it removed. Stripping, in other words, is something platforms do for you to other people — not something they do to themselves.

Facebook doesn't just read metadata — it writes its own

In July 2019, software engineer Edin Jusupovic posted a hex dump of a photo that had passed through Facebook, showing a block of data the camera never wrote — covered by Forbes as hidden codes embedded in downloaded photos. The IPTC ran its own investigation and published the specifics: Facebook inserts values into two IPTC fields of photos saved from its site. The Instructions field gets a value beginning with "FBMD" that stays constant even when the image is re-uploaded, and the Job ID field gets an identifier that changes with each separate upload. What are they for? The IPTC was careful: "The role of these values is not publicly documented by Facebook, so they are currently the subject of significant speculation," and it made no assumptions of its own. What's not speculation is the mechanism: a photo saved from Facebook carries machine-readable codes tied to its history on the platform, and re-sharing that file carries them wherever it goes next.

1 · The file you upload EXIF (GPS, timestamps, device), XMP, IPTC, comments — everything the camera and editors wrote, intact. 2 · The platform's copy — read first, stripped after Arrives with metadata intact; policy: collects metadata "such as the location of a photo or the date a file was created." 3 · The copy viewers can save GPS and most fields gone; rights fields can survive; Facebook adds its own FBMD Instructions + per-upload Job ID. "The platform strips EXIF anyway" describes only stage 3. Scrubbing before upload changes what exists at stage 2.
The reassurance is about stage 3; the privacy question is about stage 2. Only a scrub that happens before upload changes what the platform's own copy contains.

Even stage 3 isn't a clean slate

One more wrinkle from the IPTC's Facebook findings: the stripping isn't total. Facebook preserves the rights-related fields — Creator, Creator's Job Title, Copyright Notice, Credit Line, Source, Description Writer — in the copies people save. For a working photographer that's the one decent behavior in the whole pipeline, and it's what the IPTC has spent a decade asking platforms to do more of. But it cuts the other way for anyone whose photo software quietly filled in a Creator field with their real name: that identity can ride along to whoever downloads the image, on the very platform everyone assures each other "strips it anyway." Which is the general lesson of all three test rounds — what survives upload is a platform-by-platform, field-by-field matter that has changed between 2013, 2016, and 2019, and none of it is under your control once the file leaves your device.

What scrubbing before upload actually changes

Run the photo through NearScrub first and the pipeline above starts from a different stage 1. For a JPEG it drops the entire EXIF block — GPS, timestamps, device identifiers — plus XMP, the IPTC/Photoshop segment, and any embedded comments, entirely in your browser tab: no upload, no server, and the pixel data is copied untouched, with only the display-orientation flag re-added so portrait shots don't render sideways. PNGs get the same treatment for their text, EXIF, and timestamp chunks, and you can drop files in to see a report of what they carry before anything is removed. There's a second, less obvious use: the FBMD codes above live in IPTC fields, which a JPEG carries in exactly the Photoshop/IPTC segment NearScrub removes — so a photo saved from Facebook and scrubbed before being shared somewhere else doesn't take its platform-issued codes with it. And to be symmetrical about it: if you're a photographer who wants the Creator and Copyright fields to survive, a scrubber does the opposite of what you need — this habit is for photos where the metadata serves the platform, not you.

What it honestly doesn't change

Scrubbing before upload closes one channel, and it's worth being exact about the ones it leaves open. It does nothing for photos already uploaded — the collection described in that policy happened at upload, and there's no retroactive scrub. It doesn't stop a platform's app from knowing your location by other means: the policy quote above is about file metadata, but apps with a location permission, or just your IP address, don't need your EXIF. It can't touch what's visible in the pixels — a storefront or street sign identifies a place with no metadata at all. And two practical notes from NearScrub's own limits: iPhones shoot HEIC by default, which NearScrub doesn't parse — convert to JPEG first, or share through a path that converts automatically and scrub the JPEG — and a photo taken with a platform's in-app camera goes straight into the app, so there's never a file on your device to clean first.

Stripped for whom

The IPTC's decade of tests says viewer-facing stripping mostly works; Facebook's own policy says the platform reads what it strips; the FBMD finding says at least one platform writes metadata of its own on the way out. None of those three facts contradicts the others, and together they draw the actual boundary: the platform's stripping protects you from its users, and nothing in that pipeline is designed to protect you from the platform. Only one party can do the scrub before the upload, because only one party has the file while it's still just a file. The metadata a platform can't read, keep, or overwrite is the metadata that never arrives.

Sponsored
← NearScrub

This page shows ads only if you consent.