The Real Risks of Location Sharing Through Photos, Snap Map, and EXIF Data
How your location leaks through photo EXIF data, Snap Map, and app tracking, with the exact settings path to stop it on each platform.
The Real Risks Of Location Sharing Through Photos, Snap Map, And EXIF Data
Strip the location data from every photo before you share it. Then check the background for anything that identifies where you are. Then wait a few hours before posting. None of these steps works alone. EXIF data embedded in every photo you take, live-location features like Snap Map, and background tracking by apps you forgot you installed leak your whereabouts silently and persistently. For a Singaporean, the risk is compounded: location sharing has become a primary vector for phishing scams, stalking, and data broker profiling. A photo of your coffee at a Tiong Bahru café carries GPS coordinates precise enough to identify which table you sat at. That is a recoverable data field inside the file.
You will find the exact settings path on each platform, the tool to check any image for embedded location data before you share it, and the legal backstop under the Personal Data Protection Act that makes unauthorised location collection a breach of the consent obligation and protection obligation. You will also learn what a stranger using open-source intelligence can deduce from the background of a single photo: landmarks, street signs, shop names, even the angle of shadows that fixes the time. Each section tells you what that setting protects and what it does not.
How EXIF Data Leaks Your Exact Location From Every Photo
What EXIF Data Contains
Exchangeable Image File Format (EXIF) data is the metadata your camera or phone writes into every image file at the moment of capture. It includes the device make, model, date, time, and GPS coordinates if location services were enabled. The fields are named GPSLatitude, GPSLongitude, GPSAltitude, and GPSImgDirection. A photo taken at Merlion Park stores those coordinates as decimal degrees readable by any metadata viewer.
Strip Location Before Sharing
To check an image before sharing, use ExifTool or Exifdata.com. Drag the file onto the viewer. If you see a GPS section with latitude and longitude, the photo is geotagged. Do not assume your phone strips this automatically. Most phones do not unless you turn off location permissions for the camera app. On an iPhone running iOS 14 or later, go to Settings > Privacy > Location Services > Camera and select Never. On Android 12 or later, go to Settings > Location > App permissions > Camera and select Deny. This stops the camera from writing GPS data into new photos. It does not remove EXIF data from photos already in your library. To strip existing EXIF, use an app like Exif Eraser on Android or the built-in Remove Location option in the iOS Photos share sheet before sending a picture.
What Platforms Strip And What They Keep
Platforms vary in what they strip on upload. Instagram removes EXIF from photos you post to the feed but retains it in direct messages. Facebook removes EXIF from uploaded images. X strips GPS coordinates. TikTok removes EXIF from uploaded videos. These policies change without notice and none of them strip metadata from files you send via WhatsApp or Telegram unless you use the compression option. A photo sent as a document retains all EXIF data. Strip location metadata manually before sharing anything, regardless of platform.
Snap Map Location Privacy Risks: What Your Friends (And Strangers) Can See
How Snap Map Broadcasts Your Position
Snap Map is a live-location sharing feature in Snapchat that displays your Bitmoji on a map at the precise location your phone reports. The default setting is Ghost Mode, but many users switch it to Share My Location, often without checking who can see it. The audience options are: My Friends (all friends), My Friends Except (exclude specific people), or Only These Friends. A contact you added once from a group chat can see where you are right now. The Singapore Police Force advisory on real-time location sharing in messaging apps, issued in 2024, explicitly warns against this for minors and adults.
To disable Snap Map location sharing, open Snapchat, pinch the camera screen to open the map, tap the gear icon, and select Ghost Mode. This stops broadcasting your location entirely. It does not delete your location history from Snapchat's servers. For that, go to Snapchat Settings > Privacy > Location History and clear it. Ghost Mode hides you from other users, but Snap Inc. still receives your location data under its privacy policy. Prevent that by denying location permissions to Snapchat entirely: on iOS, Settings > Privacy > Location Services > Snapchat > Never; on Android, Settings > Location > App permissions > Snapchat > Deny.
Live Location In Other Messaging Apps
Snap Map is not the only live-location feature. WhatsApp introduced live location sharing in 2017. You can share your real-time location for a set duration (15 minutes, 1 hour, or 8 hours) with a specific chat. The risk is forgetting to stop sharing. The location continues broadcasting until the timer expires or you manually stop it. To check active live locations, open WhatsApp, tap the chat, and look for the live location banner. Tap Stop Sharing. Never use live location except in a genuine emergency, and revoke the permission after use. Telegram's proximity-based People Nearby feature was removed in September 2024. That vector no longer exists, but other Telegram location features remain: sharing a location pin in a chat embeds coordinates visible to all group members.
Background Location Tracking By Apps: What You Allow Without Realising
Audit Your App Permissions Now
Apps request location permissions for a stated purpose: navigation, weather, ride-hailing, food delivery. Many continue collecting location data in the background long after that purpose is served. The gap between a privacy policy text and actual data handling is documented in PDPC enforcement decisions. In 2023, the PDPC issued a financial penalty against an organisation for unauthorised disclosure of location data, citing a breach of the protection obligation under the Personal Data Protection Act. The organisation had collected precise geolocation data from users who had granted location permissions for a specific feature, then used that data for an unrelated purpose without fresh consent.
To audit which apps on your phone have location permissions, go to Settings > Privacy > Location Services on iOS. You will see every app and its permission level: Never, Ask Next Time, While Using the App, or Always. For Android, go to Settings > Location > App permissions. Android 12 introduced the Approximate location permission, which gives apps your general area (within about a city block) rather than your precise coordinates. Choose Approximate location unless the app's core function requires precision. A weather app does not need your exact GPS location. A ride-hailing app does, but only while you are booking a ride. A flashlight app that requests location permissions is a red flag.
Google Maps Timeline And Your Movement History
Google Maps Timeline is a separate risk. Until December 2024, Google stored your location history in the cloud by default. On December 1, 2024, Google changed the default to store new Timeline data on-device. Users who did not migrate their existing cloud data by May 18, 2025 lost that history. If you want to keep Timeline active but local, ensure the on-device setting is enabled. To stop location tracking entirely, go to Google Maps > Settings > Personal content > Location History and toggle it off. This prevents Google from recording where you have been. It does not prevent Google from using your current location for search results or navigation in the moment. To stop that too, deny Google Maps background location access in your phone's settings.
What A Stranger Can Deduce From Your Photo's Background: The OSINT View
The Tools And Techniques
Open-source intelligence practitioners use photo geolocation as a core technique. From a single image, a trained analyst can identify the location by matching landmarks, street signs, shop names, vegetation, weather, and shadow angles. The toolset includes Google Earth Pro for historical imagery, SunCalc for shadow and sun position calculations, and the InVID-WeVerify plugin for verification workflows. This is taught in digital forensics courses and used by journalists and law enforcement.
The Singapore context makes this easier. The city is dense, well-mapped on Google Maps Street View, and full of distinctive HDB block numbers, bus stop names, and franchise coffee shops. A photo taken at a hawker centre shows the stall name, the table number, and the column of a nearby block with a visible address. A photo taken from a condo balcony shows the swimming pool shape and the neighbouring building's facade. A reverse image search on Google Lens or TinEye can match that image to existing online photos of the same location, narrowing the area to a specific building.
Cropping Is Not Enough
Do not believe that cropping the image or blurring the background removes the location clue. It does not. The EXIF data is still in the file unless you strip it. The background context is still visible unless you deliberately obscure every identifier. Check the image with a metadata viewer before sharing, and consider what the background reveals even without GPS coordinates. A Singapore Police Force advisory on disabling location services when not in use, part of the 2024 cyber safety tips, is the simplest first step.
| Platform | Setting Path | What It Protects | What It Does Not Protect |
|---|---|---|---|
| iOS Camera | Settings > Privacy > Location Services > Camera > Never | Stops GPS coordinates being written into new photos | Does not strip EXIF from existing photos; does not prevent sharing EXIF via messaging apps |
| Android Camera | Settings > Location > App permissions > Camera > Deny | Stops GPS coordinates being written into new photos | Same gap as iOS; existing photos retain EXIF |
| Snapchat | Pinch map > Gear icon > Ghost Mode | Hides your Bitmoji from other users on Snap Map | Snap Inc. still receives location data; does not clear location history |
| WhatsApp Live Location | Open chat > Tap live location banner > Stop Sharing | Ends real-time location broadcast to that chat | Does not prevent future live location shares; does not remove location from past chat history |
| Google Maps Timeline | Google Maps > Settings > Personal content > Location History > Off | Stops Google recording your location history | Google still uses current location for search and navigation; does not delete past history |
| iPhone Location Services Global | Settings > Privacy > Location Services > Off | Blocks all apps from accessing location | Breaks navigation, weather, ride-hailing; does not prevent Wi-Fi-based approximate location |
| Android Location Global | Settings > Location > Off | Blocks all apps from accessing GPS location | Breaks navigation and location-dependent features; apps may still use Wi-Fi and Bluetooth for approximate location |
Legal Backstop: The PDPA And Your Location Data Rights
Your Rights Under The Law
The Personal Data Protection Act defines personal data to include geolocation data. The PDPA's nine core obligations, consent, purpose limitation, notification, access and correction, protection, retention limitation, transfer limitation, accountability, and the newer data portability obligation, all apply to location data. An organisation that collects your location must inform you of the purpose, obtain your permission, use the data only for that purpose, protect it, and stop retaining it when the purpose ends.
The PDPC advisory on the use of personal data in mobile applications, issued in 2022, addresses in-app permission for location data. It states that organisations must obtain active, informed agreement before collecting precise geolocation data, and that background collection requires a separate, specific authorisation. The 2023 enforcement decision involving unauthorised disclosure of location data is the precedent: the organisation was fined for failing to protect location data, in breach of the protection obligation. The financial penalty under the PDPA can reach 10 percent of annual turnover in Singapore or S$1 million, whichever is higher, a cap that took effect in October 2022.
How To Exercise Those Rights
For the individual, the rights are practical. You have the right to access the location data an organisation holds about you (Section 21). You have the right to withdraw agreement for future collection (Section 16). You have the right to request correction of inaccurate location data (Section 22). And the organisation must cease retaining your location data when it is no longer needed for the purpose (Section 25). Do not fall into privacy resignation, the belief that because data breaches happen, there is no point in exercising these rights. The PDPC publishes enforcement decisions that show the opposite: organisations that violate the consent obligation or protection obligation are penalised, and the system works when individuals report breaches.
Geotagging Dangers Social Media: The Specific Scams Targeting Location Data
The Parcel Delivery Phishing Scam
Geotagging dangers social media users face in Singapore are not abstract. The Singapore Police Force's scam typology framework identifies phishing scams that exploit location data. A common variant in 2025 was the parcel delivery phishing message: 'Your parcel is at the warehouse, confirm delivery address.' The scammer already has your name and phone number from a data breach. Your reply confirms your current location, which the scammer then uses for a follow-up impersonation call claiming to be from a bank.
The success rate of this method is high because the location pretext feels legitimate. The Singapore Police Force anti-scam helpline (1800-722-6688) and the ScamShield app, upgraded with AI-powered scam detection in September 2024, are the primary defences. ScamShield blocks known scam numbers and SMS messages using a database updated by the police. It also allows users to report suspicious messages. The app is available on iOS and Android and was launched in November 2020. ScamShield blocks known scam numbers but cannot block a spoofed SMS that uses a legitimate sender ID. No app can. The human verification step, checking the URL, the tone, the urgency, remains essential.
The Fake Friend-In-Distress Call
Another location-exploiting scam is the fake friend-in-distress call. The scammer uses location data from social media to establish credibility: 'I saw you are at Jurong East, so I know you are near the hospital. I need you to transfer money for my mother's surgery.' The Singapore Police Force advisory on real-time location sharing in messaging apps, issued in 2024, directly addresses this: disable location sharing on social media, never post your location in real time, and verify any urgent request through a separate channel.
Remove EXIF Data From Photos: The Step-By-Step For Every Device
On iPhone
Removing EXIF data from photos is the single most effective action you can take. On iPhone (iOS 14 or later), open the Photos app, select the image, tap the share icon, and tap Remove Location before sending. This strips the GPS coordinates from the copy you are sharing but leaves the original intact. To bulk remove location from multiple photos, use the shortcut method: create a Shortcut that runs 'Remove Location' on selected images. The share-sheet option removes only the GPS fields, not the camera make, model, or date. For full EXIF removal, use a dedicated app like Exif Metadata Cleaner.
On Android
On Android, the built-in option varies by manufacturer. On Google Pixel phones, open the photo, tap the three-dot menu, select Details, and tap Remove location. On Samsung phones, open the photo, tap the i icon, and tap Edit to remove location. The universal method is to use a third-party app like Photo Exif Editor or Exif Eraser. Both allow batch removal of all metadata fields. Sending a photo as a document via WhatsApp or Telegram bypasses the app's image compression and sends the original file with all EXIF data intact. Use the share-sheet compression or strip metadata before sending.
On Desktop
On a desktop, use ExifTool. The command is 'exiftool -all= photo.jpg' which removes all metadata. For Windows users without command-line comfort, Exifdata.com is a web-based viewer and remover. Drag the file onto the site, review the EXIF fields, and click Remove EXIF. Be aware that uploading an image to a web service carries its own privacy risk. Exifdata.com's privacy policy determines whether your uploaded image is stored or analysed. For sensitive photos, use a local tool.
Location Metadata Photo Sharing Safety: The Checklist Before You Post
Location metadata photo sharing safety is not a one-time setting. It is a habit applied to every image before it leaves your device. Use this checklist in order.
First, check the EXIF data. Use a viewer on your phone or desktop to confirm no GPS fields are present. Second, review the background. Look for street signs, shop names, HDB block numbers, bus stop numbers, house numbers, or any text that identifies a location. Blur or crop these out. Third, consider the time. A photo taken at 6:30 pm with long shadows tells a viewer not only where you are but when. If you post it in real time, you have announced your current location. Delay posting by at least a few hours. Fourth, check the platform's metadata policy. As of 2025, Instagram strips EXIF from feed posts but not from DMs. Facebook strips EXIF from uploads. X strips GPS coordinates. TikTok strips EXIF from videos. These policies change without notice, so strip metadata before uploading anywhere.
Do not settle for one step. EXIF removal handles the metadata. Background review handles the visual clues. Time delay handles the real-time risk. Each covers a different vector. None covers all three alone.
Digital Footprint And Digital Shadow: What You Leave Vs. What Is Taken
Your digital footprint is the data you actively leave: posts, check-ins, photo uploads, comments. Your digital shadow is the data collected about you passively: browsing history, location tracking from apps you did not open, data broker profiles built from cross-referenced sources. Location data feeds both. A geotagged Instagram post is a footprint. The background location collection by a weather app you opened once, which then sold the data to a broker, is a shadow.
The PDPA's consent obligation covers the shadow as much as the footprint. An organisation that collects location data must have a stated purpose and your permission. The gap is that authorisation is often buried in a terms-of-service agreement that nobody reads. The PDPC advisory on in-app consent, issued in 2022, requires that agreement be obtained actively, not passively through pre-ticked boxes. Do not fall into privacy resignation, the belief that because data brokers exist, there is no point in managing settings. The PDPA's retention limitation obligation (Section 25) requires organisations to stop holding your location data when the purpose ends. Exercising your right to withdraw consent forces them to delete it.
Common Questions
How do I check if a photo has location data before I share it?
Use Exifdata.com on a desktop or an app like Exif Viewer on mobile. Drag the photo onto the tool. If you see GPSLatitude and GPSLongitude fields, the photo contains location data. On iPhone, open the photo, tap the share icon, and check if Remove Location appears in the share sheet. On Android, open the photo details menu and look for location metadata.
Does Snap Map show my location to people who are not my friends?
No, Snap Map shows your location only to friends you have added on Snapchat, unless you change the audience setting to Everyone. The default is Ghost Mode, which hides you from all users. If you switch to Share My Location, you can choose between My Friends, My Friends Except, or Only These Friends. A friend may share your location with someone else, so Ghost Mode is the safest option.
What is the difference between a digital footprint and a digital shadow?
A digital footprint is data you actively leave, such as a geotagged Instagram post or a check-in on Facebook. A digital shadow is data collected about you passively, such as background location tracking by apps, browsing history, and data broker profiles. Both are searchable and permanent, but the shadow is harder to control because you may not know it exists.
Does the PDPA protect my location data if an organisation shares it without my consent?
Yes. The PDPA defines personal data to include geolocation data. An organisation that collects, uses, or discloses your location data without your permission breaches the consent obligation and the protection obligation. The PDPC can impose a financial penalty of up to 10 percent of annual turnover in Singapore or S$1 million, whichever is higher. You can also file a complaint with the PDPC.
Can a scammer use my photo's location data to target me?
Yes. A scammer can extract GPS coordinates from a photo you posted online and use that information to craft a targeted phishing message. For example, if the photo shows you at a specific shopping mall, the scammer may send a message claiming your parcel is at that mall's delivery point. The Singapore Police Force advisory on real-time location sharing warns against posting photos with embedded location data for this reason.