Remove Metadata From a Photo Before a Whistleblower or Leak Submission
Tip-line photos can carry GPS, capture time, and device fingerprints that undermine source protection. Strip metadata locally on this device before you submit — this is practical privacy hygiene, not legal advice.
Ready to clean a photo? MetadataWipe processes JPEG and PNG files locally — no account and no server upload.
Open MetadataWipe toolWhistleblower and leak submissions often start as ordinary phone photos: a safety hazard on a factory floor, a document on a desk, a public-records folder open on a screen, a protest scene, a screenshot of an internal dashboard. Editors and investigators need the visible evidence. The file header can still carry GPS of the exact building, DateTimeOriginal that proves when you were present, and device tags that correlate this tip with another tip sent months later from the same phone. That is source-protection risk in the envelope, not in the caption.
This page is practical privacy education for people preparing a legitimate tip or leak submission. It is not legal advice. It does not tell you whether disclosure is protected, how to contact counsel, or what you may lawfully share. For newsroom tip workflows in general, see strip metadata before submitting to a newsroom. For proof-of-concept screenshots aimed at security programs rather than press, see remove metadata from a screenshot before a bug bounty submission. MetadataWipe rebuilds the image in your browser so typical metadata is not copied into the cleaned download. Processing stays on this device.
Why whistleblower submissions need a stricter strip-before-send habit
Adversarial readers. Unlike a social post, a tip may eventually be examined by employers, opposing parties, or anyone who obtains a forwarded copy. Treat the attachment as evidence that will be inspected, including the header.
Correlation across tips. A single GPS pin is bad. The same Make/Model and serial-adjacent pattern across several submissions can paint a source even when each email address differs. Wipe every file; do not assume one clean send sanitizes the next.
Channel uncertainty. Secure drop boxes, Signal tips, and ProtonMail addresses reduce some risks. They do not rewrite EXIF inside the JPEG you attach. Source protection starts before transmission.
Higher stakes than a casual newsroom hobby submission. Citizen journalism pages on this site cover tip hygiene broadly; this page emphasizes anonymity-preserving prep when the source specifically needs to stay detached from the workplace or identity tied to the evidence.
What metadata can undermine source protection
GPS. A photo taken inside an employer facility, a home office used to photograph documents, or a hotel used as a temporary workspace can locate you more precisely than the city named in the tip email.
Timestamps. Capture time can align with access logs, CCTV retention windows, or who was on the floor. Vague prose in the email does not erase DateTimeOriginal in the file.
Device fingerprints. Make, Model, Software, and sometimes MakerNotes help link files. If you submit multiple exhibits over time, shared device tags are a pattern.
Screenshots versus camera photos. Desktop PNGs often lack GPS but still carry software and time. Phone screenshots and photos of monitors can carry both visual workplace identifiers and mobile metadata. Inspect each file.
Limits of a metadata wipe. MetadataWipe does not remove faces, badges, reflections, open chat sidebars, or document letterhead in the pixels. Redact or crop those first. A clean header on an image that still shows your nameplate is not source protection.
How to strip tip photos locally in MetadataWipe before you submit
- Copy exhibits to a working folder you will use only for submission prep. Prefer files you are willing to send after visual review.
- Redact visible identifiers (names, faces, badge numbers, URLs that include your account) using a tool that flattens pixels — then save a new PNG or JPEG.
- Open the MetadataWipe tool on a device you control. Drop the redacted file. Read GPS, DateTimeOriginal, and device fields before stripping.
- Strip locally. Typical EXIF, IPTC, and XMP are not copied into the cleaned download. The original remains on disk until you decide what to keep.
- Verify the cleaned download in the panel, rename it neutrally (for example
exhibit_01.jpgwithout personal naming patterns), and attach only that file through the channel the newsroom or recipient specified.
Turning off Location Services helps future captures. It does not clean the photos you already took at the site. Wipe what you have.
Realistic high-stakes submission scenarios
A workplace safety tip photographed on a personal phone inside the building. The pixels show the hazard; GPS can show the facility. Strip after cropping anything that identifies coworkers who are not part of the tip.
Documents photographed at home for a leak to press. The content is the page; the header may be the apartment. Wipe before the tip email or drop-box upload.
A series of tips over months from the same handset. Device tags can cluster the set. Wipe every exhibit; consider whether reusing one device across many tips fits your threat model at all — metadata wipe is one layer, not a complete anonymity plan.
A screenshot of an internal system prepared like a bug-bounty PoC but destined for a journalist. Same envelope problem as researcher OPSEC: time, software, and device context in the file. Wipe after visual redaction.
Mistakes that weaken source-protection hygiene
Assuming the newsroom will strip metadata on intake. Do not rely on platform or desk stripping. Send a cleaned file.
Sending the live camera roll original “because Signal is encrypted.” Encryption protects transit; it does not remove EXIF inside the attachment.
Wiping metadata but leaving identity in the pixels. Pair header hygiene with visual redaction.
Using a cloud “EXIF remover” that requires uploading the tip photo. Prefer stripping in your browser on this device so the sensitive original is not sent to MetadataWipe or another processor for cleaning.
Treating this checklist as legal clearance. Metadata hygiene is not advice about whistleblower statutes, privilege, or employment consequences. When stakes are high, speak with a qualified lawyer; use this page only for the file-prep step.
Related guides
See also:
- Strip metadata before submitting to a newsroom
- Remove metadata from a screenshot before a bug bounty submission
Frequently asked questions
Is this legal advice about whistleblowing?
No. This page is privacy education: how photo and screenshot metadata can identify a source, and how to strip typical tags locally before a submission. It does not tell you whether to leak, what is lawful to disclose, or how to structure a protected disclosure in your jurisdiction.
Do newsrooms or tip platforms strip metadata for me?
Do not rely on them. Some desks strip on intake; others do not, especially on nights, weekends, or overloaded inboxes. Your first layer of control is the file you send. Wipe on this device before transmission.
What metadata is most dangerous on a tip photo?
GPS that pins an employer building or home, timestamps that align with badge logs or shift schedules, and device Make/Model or serial-adjacent tags that link multiple tips to one handset. None of that is required for an editor to see the pixels.
Does MetadataWipe send whistleblower photos to a server?
No. JPEG and PNG are read into browser memory on this device. Typical EXIF, IPTC, and XMP blocks are not copied into the cleaned download. The original is not sent to MetadataWipe for processing.
Remove EXIF data, GPS location, and common photo metadata in your browser.
Try MetadataWipe free