Can you stop metadata from being written in the first place?

Nearly everything written about photo metadata — including nearly everything on this site — is about cleanup. A file already exists, it already carries more than you want it to, and the question is how to get that out before you send it. This page asks the opposite question. Before the file exists, how much of this can you simply decline? The honest answer is: a meaningful amount, including the single field that matters most, and nowhere near all of it.

Want to see what your settings actually produced? MetadataWipe reads and rebuilds a JPEG or PNG in your browser — no account, and the file stays on this device.

Open MetadataWipe tool

This matters because remediation and prevention fail in different directions. Stripping is precise: you choose a file, you clean it, you know the outcome. But it is a ritual, and rituals get skipped — on the busy day, on the photo you sent in a hurry, on the one somebody else took with your phone. Prevention is the opposite shape. It is imprecise, it cannot reach every field, and it quietly protects the files you were never going to think about. The two are not alternatives. Prevention is a floor under the files you forget; stripping is the ceiling on the files you publish.

What you can actually switch off at the source

Location, at the operating-system level. This is the one with real leverage, because coordinates are the field with the largest gap between how small it looks and how much it gives away. Apple documents Location Services as a system-wide control at Settings > Privacy & Security > Location Services, with per-app access listed underneath it, so the camera can be denied while maps and directions keep working. Android phones expose an equivalent per-app location permission, though the exact menu wording has moved around between versions and manufacturer skins, so check your own device rather than trusting a remembered path.

Location, inside the camera app itself. Most camera apps also keep their own preference — commonly labelled something like save location, location tags or geotagging — which decides whether the app writes a coordinate into the file even when it is allowed to know where you are. Again, wording and placement vary by phone, app and version. It is worth understanding that these are two distinct layers rather than two names for the same switch: the app preference is a request, and the OS permission is the enforcement. If you only have the appetite to change one thing, change the permission, because an app cannot write a coordinate it was never given.

Identity strings on a dedicated camera. Many interchangeable-lens bodies let you type an owner name, an artist string or a copyright notice into the menus, and then write it into every file for the life of that setting. If you set one up years ago for a job and forgot, it is still going out with your photos. That one is worth checking precisely because it is invisible in normal use.

GPS attachments and phone pairing. If a camera has no GPS receiver it cannot invent coordinates — but a GPS accessory, or a companion app paired to your phone that logs a track and stamps it onto the files, can add them after the fact. That path is easy to forget because the tagging happens during import rather than at the shutter.

What has no switch at all

Here is the part that makes prevention a partial answer rather than a complete one. A substantial block of metadata is not an optional extra the camera offers you; it is a byproduct of producing the file. In a typical phone or camera JPEG that normally includes the device make and model, the capture timestamp and its time zone offset, the exposure triplet, focal length and lens information where the camera knows it, the software or firmware version that wrote the file, an orientation flag, a colour profile, and frequently an embedded thumbnail. Some bodies also write a serial number for the body, the lens, or both. There is no settings screen for any of this, because the firmware is not asking.

So the realistic outcome of good prevention is a photo with no coordinates that still identifies the device that took it and the minute it was taken. That is a genuine improvement and it is not anonymity. A device fingerprint plus a clock is exactly the pair that lets two posts in different places be attributed to one camera and one person's day. For the full field-by-field picture of what you are up against, see what metadata your phone camera records.

A prevention checklist that holds up

  1. Deny location at the OS permission level, not just in the camera's own settings. One change, at the layer that enforces it.
  2. Take one test photo immediately and inspect it. Not a photo from last week — a new one, taken after the change, with the app you actually use. This is the step that converts a belief into a fact.
  3. Check each camera-capable app separately. Stock camera, scanner apps, filter apps, and any social app that shoots in-app all have their own permission state.
  4. Re-test after OS updates, device migrations and backup restores. Permissions are commonly re-prompted in those moments, and a re-prompt answered quickly is a setting you did not choose.
  5. Clear any owner or copyright string you are not deliberately using on a dedicated camera body.
  6. Keep stripping anything that goes public. Prevention does not reach the device fields, so the final pass before sharing still earns its place.

Step two deserves emphasis, because it is where most prevention attempts quietly fail. The settings screen reports your intent; the file reports the result. Drop a freshly taken photo into the tool on this site and the scanner tells you what is actually in it — the reading half of the same workflow described in how to verify metadata was removed. Everything happens in the page on your own device, so testing a sensitive photo costs you nothing.

The costs, stated plainly

Capture-time prevention is not free, and pages that pretend otherwise set people up to switch it back off in frustration. Coordinates you never record cannot be recovered later, so you lose map views and place-based albums in your gallery, you lose the ability to work out where an old photo was taken, and you lose automatic trip grouping. For a lot of people that is an easy trade. For someone who relies on their library as a personal archive, it is not, and the reasonable compromise is to leave geotagging on and treat stripping as mandatory on the way out rather than optional. That is a legitimate choice, not a failure of discipline — the point is to make it deliberately instead of discovering it later.

Common mistakes and misconceptions

"Location is off, so my photos are anonymous." They are coordinate-free. The device model, the timestamp and often a serial number are still there, and that is enough to connect files to each other.

"I changed the setting, so my library is fine now." The setting applies going forward only. Nothing already on the device, already synced, or already sent has changed.

"I turned off Location Services entirely to be safe." This usually gets reversed within a week because it breaks navigation, and when it comes back the camera's access comes back with it. Per-app denial survives.

"Airplane mode means no geotag." Not reliably. GPS reception does not require a network connection, and a device may still have a recent position fix available to it. Airplane mode is a radio setting, not a metadata setting.

"My new camera app inherited my choices." It inherited nothing. New app, new permission, new internal defaults.

"My camera has no GPS, so there is nothing to prevent." True for coordinates at the shutter, and it says nothing about an owner string in the menus or a pairing app that adds a track during import.

"Screenshots are safe because the phone was not taking a photo." Screenshots generally carry no coordinates, which is not the same as carrying nothing — they are still files written by your device's software, with the fields that software chooses to include.

Related guides

See also:

Frequently asked questions

If I turn off location for my camera, do I still need to strip metadata?

Yes, because location is one field among dozens. A photo taken with location fully disabled still normally carries the device make and model, the capture timestamp and its time zone offset, the exposure settings, the lens or focal length, the software version that wrote the file, and an orientation flag — and on some camera bodies a body or lens serial number. None of those have a user-facing switch, because the firmware writes them as part of producing the file rather than as an optional extra. Prevention removes the single highest-impact field and leaves the device fingerprint and the clock intact, which is exactly the combination that lets separate posts be tied to one camera and one timeline. Treat the toggle as lowering the worst case, not as finishing the job.

Does turning the setting off clean the photos I already took?

No, and this is the most common misreading of the setting. A capture-time preference affects what gets written into files created after you change it. It is not applied retroactively, it does not rewrite anything already in your library, and it does not touch copies that have already synced to a cloud account, been sent in a message, or been backed up elsewhere. Your existing library is a separate problem that only removal can address, file by file, on the copies you actually intend to share. If you have just changed the setting, the useful next step is to take one new photo and inspect that one, rather than assuming the change propagated backwards.

Should I disable Location Services entirely, or just for the camera?

Per-app is almost always the right grain. Apple documents Location Services as a system-wide switch at Settings > Privacy & Security > Location Services with individual control for each app underneath it, so you can deny the camera without losing maps, transit directions or anything else that genuinely needs your position. Switching the whole system off tends not to survive contact with daily life — it breaks too much, so it gets switched back on, and then the camera's permission comes back with it. There is also a middle setting on recent iOS versions, Precise Location, which Apple describes as giving an app your specific location when on; turning it off narrows what the app receives to an approximate area rather than reducing it to nothing, so for photo geotagging the per-app Never option is the clearer choice.

Do third-party camera apps follow the same setting?

They follow the operating system's permission, but not your built-in camera app's own preference. These are two separate layers, and people routinely change the second one and assume the first. If you install a different camera app, a scanner app, a filter app or a social app that shoots directly, it arrives with its own permission request and its own internal settings, and the choices you made months ago inside the stock camera do not carry across. The same applies after you restore a phone from a backup or set up a new device, where permissions are often re-prompted. Any time a new app starts producing image files, treat it as an unverified source and test one of its outputs.

Test what your settings really wrote — drop a fresh JPEG or PNG in and read the result on this device.

Try MetadataWipe free