Image Quality Image QualitymetadataAI
Journal Entry

The GPS Coordinates Hiding in Your Photos Are a More Useful Target Than You Think

Scammers Using AI to Pinpoint Photo Locations From Metadata

Photo by David Spiers on Unsplash

Every unedited photo your phone shoots arrives carrying a payload of structured data that has nothing to do with the image itself. Shutter speed, lens focal length, white balance setting, device serial number, and — if location services were active — the latitude and longitude where the shutter fired. That last item is precise to within a few meters on modern smartphones. It has always been there. What has changed recently is who is reading it, and how efficiently.

Researchers and investigative journalists have documented a pattern of fraud operations using AI-assisted tools to extract EXIF geolocation data from photos shared in online marketplaces, social platforms, and even direct messages. The goal isn’t the image itself. It’s the coordinate pair buried inside it.

What EXIF Actually Stores and How Precise It Gets

EXIF (Exchangeable Image File Format) is a metadata standard embedded inside JPEG, TIFF, HEIF, and RAW files. The GPS block within an EXIF payload typically stores GPSLatitude, GPSLongitude, and GPSAltitude as separate rational number fields — each coordinate expressed as degrees, minutes, and seconds, or as a decimal degree value. A smartphone with a good GPS fix can record position to five or six decimal places of latitude/longitude. At that precision, the coordinate resolves to roughly a meter or two on the ground.

That kind of resolution is more than enough to distinguish your front door from your neighbor’s.

Beyond GPS, the EXIF block also carries:

The MakerNote field in particular is a black box by design — manufacturers can store whatever they want there, and some do include additional device identifiers or network information depending on the firmware version.

How AI Changed the Scale of This Problem

Reading EXIF data from a single image has required nothing more than free software for decades. Any image viewer worth the name can surface it. The shift AI introduces is not capability — it’s throughput and targeting.

A fraud operation monitoring a marketplace listing can automate the download and metadata extraction of every uploaded photo across thousands of listings simultaneously, then flag any that contain GPS coordinates, cross-reference those coordinates against mapping data, and build a profile of the seller’s likely home address without any human having looked at a single image. The same pipeline can cluster coordinate data across multiple listings from the same seller to confirm a location. What once required a technically motivated individual spending twenty minutes on one target now scales to industrial volume.

AI vision models add a second layer: where EXIF data is absent, scene analysis can sometimes approximate location from architectural style, street signage, vegetation, topography, and sky conditions. This is a harder problem and the accuracy varies considerably by setting, but combined with whatever metadata did survive, it meaningfully closes the gap when GPS fields are empty or stripped.

This matters especially for photos taken and shared directly from a phone, because smartphone cameras record GPS data by default and most platforms that accept uploads don’t display a visible warning that the metadata is present.

Where the Metadata Goes When You Share

Platform behavior on EXIF varies widely and has changed repeatedly over the years — check any platform’s current documentation rather than relying on a specific behavior being permanent.

As a general pattern: major social platforms (Instagram, Facebook, X/Twitter) strip most or all EXIF data server-side before serving images to other users, which reduces the exposure for photos uploaded through those channels. But this stripping happens at the platform’s discretion, applies only to images served through their delivery infrastructure, and doesn’t necessarily apply to images sent via direct message, exported in bulk, or accessed through older API pathways.

Peer-to-peer sharing — AirDrop, email attachments, messaging apps, direct file transfers — almost always preserves EXIF intact, because there’s no intermediary platform making a stripping decision.

Online marketplaces are the specific high-risk context here. When a seller photographs an item at home and uploads those photos through a listing interface, the platform may or may not strip GPS data, and the behavior can differ between the mobile app and the desktop web interface, between different file types, and between platforms entirely. A HEIF file and a JPEG uploaded to the same platform can be handled differently because the stripping logic may not be format-agnostic.

Removing Metadata Before You Share

The cleanest solution is to strip GPS data from files before they leave your device. This doesn’t require third-party software, though it does require intentionality about when you take that step.

On iPhone: In Settings → Privacy & Security → Location Services → Camera, set the camera’s location access to “Never” to prevent GPS from being embedded at all. For files you’ve already taken, iOS’s share sheet includes an “Options” button when sharing a photo that lets you strip location data before sending. That option applies to the specific share action; it doesn’t modify the stored file.

On Android: The Clock Camera app and most stock camera apps include a location toggle in camera settings. The exact path varies by manufacturer and Android version.

On desktop: Most operating systems’ built-in file properties panels allow removing metadata. On Windows, File → Properties → Details → “Remove Properties and Personal Information” strips EXIF fields from a copy. On macOS, the Preview app’s inspector shows EXIF but doesn’t offer bulk strip; command-line tools and free utilities handle this more cleanly.

A few things to verify regardless of method:

  1. Check the output file afterward rather than trusting that the strip worked — open it in an EXIF viewer and confirm the GPS fields are gone
  2. Confirm that whatever tool you used preserved the actual image data; some aggressive metadata strippers re-encode the file and introduce compression artifacts in the process
  3. If you’re sharing HEIF files specifically, note that stripping tools handling JPEG may not handle the HEIF metadata container identically — the metadata is stored in a different structural location

For anyone sharing photos of items for sale, the most reliable habit is to photograph those items in a location that isn’t your home, or to strip GPS coordinates as a fixed step in your workflow before any upload.

The Broader Point About File Contents and Trust

This threat vector is a useful reminder that a photo file is not just pixels. The container holds structured data across multiple blocks, some of it machine-readable in ways that aren’t visible when you look at an image on screen. Our Image Quality coverage returns to this tension repeatedly — what a file contains technically and what it appears to contain visually are different questions, and the gap between them is where a lot of practical problems live.

The specific risk here is real and documented, but it’s also straightforwardly addressable. GPS embedding is a configurable feature on every modern smartphone. Stripping it from files before sharing is a five-second action once the habit is established. The AI amplification of the downstream threat changes the urgency of the precaution, not the precaution itself.

Check what your current camera app settings actually record, verify that the last photo you shared doesn’t contain your home coordinates, and build the strip step into any workflow that ends with a file being sent to someone you don’t know.

More Image Quality material is indexed in the Journal and on the Image Quality page.