# File metadata — the photo has your GPS, the document has your name

> You strip your identity everywhere — aliased email, compartmentalized phone, clean browser — then attach a photo, and the file quietly carries the exact GPS coordinates where you took it, the phone that took it, and the second the shutter fired. Documents are worse: a PDF or Word file usually embeds your real name, your username, the software licence, and sometimes the full edit history of text you thought you deleted. The content is what you meant to share. The metadata is everything you didn't.

Markdown twin of https://xmr.club/opsec/18-file-metadata. CC-BY-4.0. Attribute "xmr.club".

## At a glance

- Canonical: https://xmr.club/opsec/18-file-metadata
- Series: #OPSEC52 — weekly threat-model-first OPSEC cards
- Week: 18
- Pillar: Digital identity compartmentalization
- Difficulty: beginner
- Cost: $0
- Language: en
- Published: 2026-09-21

## Body

# OPSEC52 / Week 18 — File metadata: the photo has your GPS, the document has your name

> You strip your identity everywhere — aliased email, compartmentalized phone, clean browser — then attach a photo, and the file quietly carries the exact GPS coordinates where you took it, the phone that took it, and the second the shutter fired. The content is what you meant to share. The metadata is everything you didn't.

**Threat model:** anyone who receives a file you send — a forum mod, a marketplace counterpart, a support desk that logs attachments — plus every platform that *doesn't* strip metadata on upload, and any analyst who collects your files over time and correlates the embedded author/device/GPS fields to merge a "pseudonymous" identity back into a real one. The leak isn't in the picture; it's in the header no one looks at.

## The easy 20% most people know

"Photos have GPS." True — most know a phone photo can carry **EXIF** location, and many turn off camera geotagging. That's the easy part, and it's worth doing. But EXIF is a fraction of the surface, and turning off geotagging doesn't touch the rest of what a photo carries, nor documents at all.

## What actually rides along

- **Photos (EXIF/XMP):** GPS lat/long *to a few metres*, exact timestamp, camera/phone make + model + serial, lens, and often a unique device identifier. Two "anonymous" photos with the same camera serial are the same camera.
- **Documents (PDF, Word, Office):** author name, the OS **username**, the software + licence, creation/modification times — and for Office files, frequently **tracked-changes and revision history**: text you cut before sending can still be recovered.
- **Screenshots and "cropped" images:** cropping in some apps only *hides* the removed area — the original pixels can be recoverable (the "Acropalypse" class of bug). A redaction drawn as a black box over selectable text isn't a redaction at all.
- **Thumbnails:** a file can embed a small preview generated *before* you edited it — so the thumbnail shows the un-blurred, un-cropped original.
- **The upload myth:** big social platforms strip EXIF on upload — but forums, marketplaces, chat apps, email attachments, IPFS, and "download the original" links frequently do **not**. Never assume the receiving side cleans it.

## The fix, by file type

1. **Photos:** don't rely on "geotagging off." Run every image through a metadata stripper before it leaves your device — `exiftool -all= file.jpg` (desktop), or **ExifEraser / Scrambled Exif** (Android), or "remove location" *plus* a re-export. Screenshotting a photo and sending the screenshot also drops most EXIF as a crude fallback.
2. **Documents:** use the built-in **"Inspect Document → Remove Personal Information"** (Word) or export to a **flattened PDF** and run it through a metadata scrubber (`exiftool`, `mat2`). Better: for anything sensitive, **paste the text into a plain editor** and rebuild — no author, no revision history, no licence trail.
3. **Redaction:** never draw a box over text. Delete the content, flatten to an image, *then* redact the image — or use a real redaction tool that removes the underlying data.
4. **The universal tool:** **`mat2`** (Metadata Anonymisation Toolkit) handles images, PDFs, Office, audio — one command to strip a file clean. Make it a habit before *any* upload.

## Verify — look at what you're about to send

Assume a file is dirty until you've checked. `exiftool <file>` prints every embedded field; skim it for GPS, author, username, serial, timestamps. Do this once on a phone photo and once on a PDF you made — seeing your own name and coordinates staring back is the moment the habit sticks.

## The privacy-coin corner

This is the quiet deanon of the no-KYC world. You buy Monero, run a clean node, keep a pseudonym — then post a **photo of a receipt, a QR code, or a hardware wallet** to prove a point or get support, and the EXIF hands over the GPS of your kitchen and your phone's serial. A screenshot of a swap "proof" can carry your OS username. Every file you attach to a pseudonymous identity is a chance to staple your real one to it. Strip before you send, every time — the on-chain privacy you paid for shouldn't be undone by a JPEG header.

**One thing to do today:** take the last photo you sent in any chat and run `exiftool` on the original (or drop it into an EXIF viewer). If it shows GPS or your device serial, that's what your recipient got — install `mat2` or a mobile EXIF stripper now and make cleaning files the reflex before every upload.

---

*Curated by [Cyber Satoshi](https://x.com/xbtoshi). Part of OPSEC52 — 52 weeks, 52 privacy pillars, threat-model first. See also Week 13 (card metadata) and Week 14 (message metadata).*

## Related

- HTML: https://xmr.club/opsec/18-file-metadata
- Series index: https://xmr.club/opsec
- Twin index: https://xmr.club/llm/opsec.txt
