What Metadata Does a Scanned Document Have?

A flatbed or sheet-fed scanner writes a different metadata profile than a phone camera. You often get scanner model, scanning software name and version, and scan date/time — sometimes an ICC color profile — and usually not GPS. That is safer for location privacy than a phone photo of the same page, but device and software tags can still be worth stripping before you share a sensitive scan.

Ready to clean a photo? MetadataWipe processes JPEG and PNG files locally — no account, and the file stays on this device.

Open MetadataWipe tool

Not all “scans” are scanner hardware. A Brother flatbed export and an iPhone “document scan” in Notes can look similar on screen while carrying totally different headers. Know which pipeline produced the file before you decide what to strip.

Phone camera baseline: what metadata does your phone camera record. Hands-on wipe for scans: remove EXIF data from scanned document.

Typical scanner-embedded fields

Driver and scan utility software write Make/Model-like fields for the device, Software or CreatorTool strings (VueScan, manufacturer utilities, Adobe Scan desktop bridges), and CreateDate / ModifyDate for the session. ICC profiles describe color handling for print fidelity — useful for design, identifying for forensics of “which shop scanned this.”

Multi-page PDFs from scanners may also store document-level Producer/Creator strings separate from per-image EXIF inside embedded JPEGs. Inspect both layers when the share format is PDF.

Why GPS is usually absent

Flatbeds and office MFPs are not GPS radios. They do not know your street address unless software merges location from the PC (uncommon in basic consumer drivers). That is a meaningful privacy difference from phone photos of passports and statements taken at home — those often include precise coordinates by default.

If scan software ever offers “add location from computer,” turn that off for sensitive documents. Default drivers rarely do this; mobile scan apps are the usual GPS source.

Phone camera “scan” apps are photos in disguise

Apps that open the camera, detect a page edge, and warp perspective still capture with the phone sensor. Expect the same EXIF family as any other photo — including GPS if Location Services were on. Treat them like camera photos: strip before sharing sensitive documents. See phone camera metadata.

Some apps export PDF wrappers around those camera images. The PDF Producer string may name the app while the embedded JPEG still holds GPS. Strip or re-export carefully — wiping only the PDF Info dictionary can leave image-level EXIF untouched.

Office MFPs and email-to-self workflows

Walk-up scanning on a workplace multifunction printer often injects device asset names, firmware versions, and department codes into metadata or into the filename itself. Even without GPS, that can tie a leaked HR PDF to a specific floor machine. Home inkjet “scan to cloud” features similarly stamp software banners. Strip before the file leaves your control if the recipient should not learn your equipment fingerprint.

Practical implication

Scanned documents are lower location risk by default, not metadata-free. Software strings can reveal office equipment or that a home scanner was used. For medical, legal, or HR scans, strip routinely with remove EXIF from scanned document, then verify.

When you have a choice between photographing a page and using a real scanner for a sensitive share, the scanner usually wins on location privacy — then finish the job with an explicit metadata wipe so device tags do not travel either.

Scenarios

Office MFP email-to-self PDF. Producer tags; rarely GPS.

Phone “scan ID” for a marketplace. Likely full photo EXIF — strip.

Archive TIFF from a museum scanner. Rich device/software history; strip if the public share should be anonymous.

Receipt scan for expense software. Harmless in many orgs; still strip if the receipt photo was actually a phone capture with home GPS.

Mistakes

Assuming every scan lacks GPS. Camera-based scan apps do not.

Ignoring software tags because “there’s no map pin.” Still identifying.

Stripping the JPEG but emailing an unsanitized PDF wrapper. Check the container you send.

Trusting “scan to Google Drive” as an anonymizer. Cloud ingest may keep producer strings and any embedded image EXIF unless you cleaned first.

Inventory the capture path (flatbed vs phone camera vs MFP), strip with a dedicated tool, and verify — especially when the document is an ID, medical form, or financial statement destined for strangers.

Related guides

See also:

Frequently asked questions

Do scanned documents have GPS metadata like phone photos?

Usually not — most scanners aren’t location-aware, so GPS data typically isn’t embedded the way it is with phone cameras.

What metadata do scanners typically add?

Device and software info like scanner model, scanning software name and version, and scan date/time, plus sometimes a color profile.

Is a scanned PDF safer to share than a phone photo, privacy-wise?

Somewhat, since it usually lacks GPS data, but device and software metadata can still reveal information worth removing.

Does this apply to phone scanning apps too?

No — apps that use your phone’s camera to “scan” a document typically carry the same metadata profile as a regular phone photo, including GPS.

Remove EXIF data, GPS location, and common photo metadata in your browser.

Try MetadataWipe free