Photo metadata when the photo is of someone else

Nearly every guide on this site, and nearly every metadata guide anywhere, is written on one assumption: the photo is yours, the risk is yours, and the decision is yours. Most of the photos people actually share break that assumption. A picture of a friend on their doorstep, a niece at her school gate, a colleague at a client's office, a housemate in the kitchen, a stranger who happened to be crossing the road — in each of those, the person carrying the consequences is not the person deciding whether to post. They do not know a GPS tag exists. They will never see the file. And the exposure is not evenly shared: for you it may be trivial, and for them it may be the one thing they were keeping quiet.

Ready to clean a photo? MetadataWipe processes JPEG and PNG files locally — no account and no server transfer.

Open MetadataWipe tool

This is worth separating from the usual advice because the reasoning changes shape. When you are protecting yourself, you can weigh the risk accurately — you know where you live, who you are avoiding, and what you mind being known. When the subject is someone else, you are guessing on their behalf with information you do not have, and your guess is systematically biased towards "this is fine", because nothing in the photo costs you anything. That asymmetry, not any technical gap, is the real problem on this page.

Whose information is actually in the file

The coordinates describe where they were. A GPS tag records the position of the camera at the moment of capture, which is technically your position rather than the subject's. In an ordinary photo of a person standing in front of you, the two are a few steps apart, so the tag places them there too. When the location is their home, their child's nursery, a clinic, a shelter, a place of worship, a workplace they have not told anyone about, or a meeting they would rather not be linked to, a tag that is harmless information about you is meaningful information about them.

The timestamp describes their day, not just yours. Date and time fields turn a picture into a placement: this person was at this spot at this minute. One photo is a data point. A handful across months is a pattern — which evenings they are at a particular address, which weekday mornings they are at a particular building. The reason a group of images says more than any single one is worked through separately in why a set of photos leaks more than one photo alone, and the same effect applies when the pattern being drawn out belongs to someone who never posted anything.

Names can end up in the file itself. Some photo libraries and editing applications can write people-tagging information — including the names you have attached to faces — into the image's XMP block, alongside keywords, captions, ratings and album titles. Whether yours does depends on the application, its version, and its export settings, so treat it as something to check on a file you are about to share rather than something to assume in either direction. The point is that a field you filled in privately, for your own organisation, can be a name attached to a face for anyone who opens the file.

Authorship fields point at you, which points at them. Copyright, artist, creator and camera-identity fields are usually discussed as your own privacy problem. In a photo of someone else they work in the other direction too: they connect the image, and therefore the subject, to you — your name, your business, your usual circle. For a picture that was meant to be an anonymous crowd shot or an unattributed example, that connection is itself a disclosure about the people in it.

The frame carries more than the header does. This is the part no metadata tool touches. Faces are the obvious one, but the reliable identifiers are usually mundane: a house number, a letter on a kitchen counter, a school crest on a jumper, a lanyard, a delivery label, a parked car, a prescription box, a view out of a window that places the building within a street. Stripping the file leaves every one of those exactly where it was.

A short sequence to run before you post a photo of someone else

  1. Name the subjects, out loud if it helps. Who is identifiable in this picture, including people at the edge of the frame and in reflections? The mental step of listing them is what breaks the default assumption that the photo is about you.
  2. Ask what any of them might not want attached to the file. Not "would they mind being photographed" — almost nobody minds that — but whether this place, this date, this pairing of people, or this audience is a problem for any of them. Someone recently separated, job-hunting, unwell, in an immigration process, or estranged from family has a list you cannot see.
  3. Read the frame before the header. Zoom in. Check the background, the reflections, the paperwork, the screens, the uniforms, the plates, the door numbers. Crop or reshoot if something identifying is there — and remember that cropping changes the picture, not the header.
  4. Clean the outbound copy, not the original. Strip the copy you are about to publish. Leave the version in your library alone if it is a photo you or the subject may want the details of later; a wedding, a birth, a trip, or anything that might be printed or dated afterwards.
  5. Check your caption and tags separately. A cleaned file under a caption naming the street, the venue, or the child's school has gained nothing. The caption is usually the biggest single leak on a photo of another person, and it is the one nobody audits.
  6. Consider delay as a control. Posting a group photo from a place while everybody is still standing in it is a live location update for all of them. Posting the same photo a day later is a memory. The change costs nothing and removes the real-time signal even on platforms that would have stripped the file anyway.
  7. Make it easy for them to change their mind. Tell people it is posted, and say plainly that you will take it down if they would rather you did not. Consent given once at a party is not consent for the rest of the internet's memory.

Where the browser tool fits is deliberately narrow. MetadataWipe takes a single JPEG or PNG you choose from your own device, runs a fast heuristic scan of the front of the file for EXIF, GPS and PNG metadata markers, redraws the image to produce a metadata-free copy, and offers it back with -metadatawipe appended to the filename. That work happens locally in your browser — no account, no server transfer — which matters more than usual when the file is a picture of somebody else's child. It handles step four of the list above and nothing else: it cannot see faces, cannot assess the frame, does not process HEIC or video, works on one photo at a time, and its check is a quick screen rather than a forensic audit.

Situations where the stakes are not yours to weigh

Children. The subject cannot consent in any meaningful sense, the parents may have a view you have not asked for, and the file can outlive every assumption anyone made about it. Rules about photographing and publishing images of children vary a lot by country and by setting — school, club, hospital, sports league — and this page is not legal advice, so where it matters, check what applies to you. Technically, the habit that helps most is to treat location and date on a child's photo as the sensitive fields, because a school run is a schedule.

People in a difficult situation. Someone dealing with a stalker, an abusive ex, or sustained harassment is running a plan that depends on which current facts are public. A geotagged photo of them at a new address undoes that in one post, and you may have no idea the plan exists. The way that threat model works, and why a current location matters so much more than an identity in it, is set out in photo metadata when the person you're worried about already knows you. The conclusion for you as the photographer is short: if someone asks you not to post pictures of them, that is the whole conversation.

Colleagues, clients and strangers. An office photo can reveal a client's site, a whiteboard, a badge, or simply that two organisations were in a room together. A street photo can place a bystander somewhere they did not choose to be recorded. Neither person gets a say unless you give them one.

Files that are not yours to begin with. When the photo was sent to you rather than taken by you, a different set of questions applies — including when stripping is the wrong move because the file may need to stay as it arrived. That is a separate decision, covered in should you strip metadata from photos other people send you.

Common mistakes and misconceptions

"They're fine with photos, so they're fine with this photo." Broad permission is not permission for a specific place, date, or audience. The objection, when there is one, is almost always to a detail rather than to the existence of the picture.

"It's my photo, I took it." Ownership of the file and responsibility for what the file discloses are different things. You control the decision precisely because it costs you nothing — which is the reason to be more careful, not less.

"The platform strips metadata anyway." Some do, on some paths, for some kinds of upload, and platform behaviour changes without announcement. It is also irrelevant to the copies you send directly to people, post in a group chat, email, or hand over on a drive — and irrelevant to everything visible in the frame.

"I blurred their face, so it's anonymous." A blurred face over an intact header still carries the coordinates, the timestamp, and possibly the names you tagged. Anonymising the picture and cleaning the file are two separate jobs, and doing one is often mistaken for doing both.

"I'll strip everything in my library to be safe." Bulk stripping destroys the dates on photos other people may want later, and it does not reach anything you have already shared. Cleaning at the moment of sharing keeps the archive intact and puts the control where the exposure actually happens.

"Nobody looks at this stuff." Reading the details of a photo takes no skill and no special software — ordinary file information panels and free viewers show plenty. Assume anything left in the file can be read casually by anyone the photo reaches.

Related guides

See also:

Frequently asked questions

Whose location does the GPS tag in a group photo describe?

Strictly speaking it records where the capturing device was when the shutter fired, which is your position, not theirs. In practice that distinction rarely helps anyone: in an ordinary photo of a person, the camera and the subject are a few steps apart, so the coordinates place everyone in the frame at that spot at that minute. If the picture was taken at their home, their child's school, their clinic, or a place they have reasons not to be publicly connected to, the tag is effectively about them. Treat the coordinates on a photo of another person as their information even though your device wrote them.

Do I need to ask permission before posting a photo of someone else?

That is a social and legal question rather than a technical one, and the answer varies a great deal by country, by setting, and by whether the person is an adult, a child, or someone in a sensitive situation — this page is not legal advice, and where it matters you should check the rules that apply to you. The practical habit that works regardless is narrower: ask about the specific thing rather than the general idea. People rarely object to existing in a photograph, and often do object to a particular place, a particular date, a particular child being named, or the picture reaching a particular audience. A short, concrete question gets a usable answer where a vague one does not.

If I strip the metadata, is the photo now safe for the other people in it?

No. Stripping removes one channel. It does not change the picture, and the picture is usually the larger disclosure when other people are in it: faces, a house number, a school crest, a name badge, a uniform, a car and its plate, a hospital wristband, a street visible through a window. It also does nothing about your caption, your tags, the account you post from, or the fact that you posted while everyone was still there. Cleaning the file is the easy part and it is worth doing, but for a photo of someone else it is the frame and the context that decide most of the exposure.

Can MetadataWipe help with photos of other people, and does it see the file?

It does one narrow job on one file at a time. You pick a JPEG or PNG from your own device, it runs a quick heuristic check of the front of the file for EXIF, GPS and PNG metadata markers, then redraws the image to build a cleaned copy you can download with -metadatawipe added to the filename. It all happens locally in your browser — no account and no server transfer, so the picture of your friend's child is not being handed to anyone. It cannot read faces, cannot judge what is visible in the frame, does not process HEIC or video, and handles one photo per pass rather than a whole album. The built-in check is a quick screen, not a forensic audit.

Remove EXIF data, GPS location, and common photo metadata in your browser — one file at a time, before you share it.

Try MetadataWipe free