Photo Metadata and Workplace Confidentiality: What to Know
Internal photos pick up lab-level coordinates from Wi-Fi-assisted location, MDM asset tags, and Slack attachments that never go through Instagram’s stripper. That is a corporate leak path, not a social-privacy checklist.
Ready to clean a photo? MetadataWipe processes JPEG and PNG files locally — no account and no server transfer.
Open MetadataWipe toolWorkplace photo leaks are not “I posted a brunch plate with a home pin.” They are a JPEG of a prototype on an antistatic mat, a whiteboard in a war room, or a visitor’s face in a lab aisle — attached to Slack, dumped into Jira, or forwarded to a contract manufacturer. Those channels do not run Instagram’s re-encoder. The EXIF GPS can be Wi-Fi-assisted indoor location that still names the campus. The camera serial can match the laptop cart’s iPhone in Intune or Jamf. The filename can be the MDM device name. None of that appears in a consumer “strip before social” article because the consumer file never entered those systems.
MetadataWipe is a local last step before an internal photo leaves the device: rebuild JPEG/PNG in the browser, drop typical EXIF/IPTC/XMP, keep the original in the project folder that records retention already covers. Document metadata (Author on a Word file) is a sibling problem — clean metadata from work documents. Support tickets with screenshots are another — remove metadata from a screenshot before a tech support ticket. This page is camera stills of the workplace itself.
Indoor coordinates that still name a lab
Core Location and Android Fused Location do not need a rooftop. A phone that saw the office Wi-Fi yesterday can estimate a position from BSSID crowdsourcing. EXIF GPSLatitude on a photo taken in a basement lab may be accurate to a building or a courtyard. For a competitor or a journalist, “which campus” is enough. For a foreign intelligence threat model, it is more. For an ordinary leak to a vendor, it still tells them which site runs the line they are quoting. Turn off Camera location access on company devices if policy allows. Still wipe files already shot. Policy does not rewrite last week’s JPEGs.
Timestamps are operational security too. DateTimeOriginal on a photo of a board deck can prove a number was on the wall before an earnings call. DateTimeOriginal on a factory still can contradict a “we started production in Q4” narrative. Internal channels keep those clocks.
Asset tags, serials, and the inventory spreadsheet
Company iPhones are often named. iOS Camera does not always put that name in EXIF, but AirDrop, Files, and mail clients preserve the filename IMG_2044 next to a device that backups label “Finance iPhone – serial.” Some workflows stamp IPTC. MakerNotes and BodySerialNumber on a mirrorless body issued by the studio team match the insurance schedule. If a photo of a confidential fixture leaks, counsel will ask which asset took it. That can be necessary attribution. It can also identify an employee who was supposed to be an anonymous reporter of a safety issue. Wipe the copy that will be broadly shared; keep a tagged master in a restricted evidence folder if Legal wants attribution later. Two copies again — the same pattern as freelance client work, different building.
Screenshots of internal dashboards are not always “camera” files, but they pick up software tags and sometimes GPS if a phone screenshot inherited location (less common) or if someone photographed a monitor with a phone (very common). Photographing a monitor is a camera JPEG with office GPS. Wipe it like a camera JPEG.
How to clean an internal still before Slack or email
- Export JPEG or PNG. HEIC from a company iPhone must be JPEG before this tool will open it. Do not drop a RAW from a studio camera unless you have already made a JPEG select.
- Open the MetadataWipe tool on this device — not on a kiosk browser you do not control, if policy forbids processing confidential images on shared machines. Drop the file. Confirm GPS and Make/Model.
- Strip. Download the
-metadatawipefile. Rename it if the original name contains a project code you should not send to a vendor. - Attach only that file to Slack, Teams, or the ticket. The composer thumbnail will look identical. The header will not.
- If Legal needs a tagged original, put it in the matter folder, not in #general.
Internal scenes that should never travel geotagged
A contract manufacturer asking for “a photo of the fixture.” They need the metal. They do not need the plant’s coordinates or the company phone’s serial. Wipe, then send.
A facilities photo of a badge reader for an access ticket. Pixels may show a badge number. Crop that first. Then wipe GPS so the ticket vendor does not get a map pin of the door.
A recruiting Instagram that someone filled from the office camera roll. That is the one case that might hit a stripper — and the originals remain on the shared photo album. Wipe before the album syncs to a personal phone.
A whiteboard packed for a vendor workshop. Photograph, crop secrets, wipe, then share. The EXIF pin says which office hosted the workshop.
Mistakes copied from consumer privacy advice
Assuming Slack is Instagram. It is email with emoji. Headers keep.
Wiping only the photos that will be “external.” Internal channels get produced in discovery. Treat #engineering as a records system.
Using a cloud EXIF site from a managed browser. You may have just sent the prototype to a processor your DPA never mentioned. Local wipe exists for this reason.
Leaving the Live Photo MOV in the same Slack message. The still is clean; the clip is not.
Related guides
See also:
Frequently asked questions
How is this different from wiping photos before Instagram?
Instagram re-encodes public posts and typically strips EXIF from the tile other people save. Slack, Microsoft Teams, email, intranet wikis, and ticketing tools usually keep the file you attached. The audience is coworkers, vendors, and whoever later gets a litigation hold on that channel. The tags still describe a building, a badge, or a company phone.
Why would GPS fire inside an office with no clear sky?
Phones use assisted location: Wi-Fi BSSIDs, cell towers, and, on Apple devices, crowdsourced Wi-Fi positioning. A “GPS” EXIF pin can be the campus, the wing, or a lab you thought had no satellite lock. Prototype areas, trading floors, and clinics show up as coordinates even when the photographer never opened Maps.
What workplace-specific tags show up besides GPS?
MDM-enrolled phones may write device names (“Acme iPhone 12 – IT-4481”) into the file name or, less often, into IPTC/UserComment. Camera Make/Model plus a serial can match an asset-inventory spreadsheet. Screenshots of internal tools add software tags. Badge photos and whiteboard shots combine pixels and headers.
Does MetadataWipe send internal photos to a vendor?
No. JPEG and PNG are processed in browser memory on your device. That is the point for files that cannot go to a random EXIF website under company policy.
Remove EXIF data, GPS location, and common photo metadata in your browser.
Try MetadataWipe free