Remove Location Metadata from Photos for Domestic Violence Safety
Survivors who have left an abusive relationship often need to rebuild a life without their former partner knowing where they live, work, or spend time.1 A single photo shared with a close friend or family member, if it still carries GPS metadata, can reveal a new address to anyone with access to that image, even someone the survivor never intended to reach.2 The recipients survivors most need to worry about, mutual friends, extended family, or a shared group chat, are often exactly the people hardest to fully restrict, which is why scrubbing the file itself matters more than trying to control who sees it.
Safety Net, the technology safety project at the National Network to End Domestic Violence, has documented this exact pattern: stalking and location tracking carry real physical danger for people fleeing abuse, and photo metadata is one of the quieter ways a new location gets exposed.
Why group chats and direct shares carry the highest risk
Public social media posts are at least somewhat protected, since major platforms generally strip GPS data from what other users see.2 Group chats, email attachments, and shared photo albums offer no such protection, because the recipient typically receives the original file exactly as it was captured, metadata intact. A public post benefits from platform-side stripping by default, which removes GPS before most viewers ever see the file, while a direct share typically does not get that same treatment since it travels as the original file rather than a re-encoded public copy.
Why trust is not a substitute for scrubbing
A survivor may carefully choose who receives a photo, but once a file leaves their device they lose control over where it goes next. A trusted friend may forward it to someone else for advice, save it to a shared computer, or leave it on a phone that another person can unlock. Every one of those handoffs creates a new copy with the original GPS data still embedded, and the survivor has no way to track or recall those copies once they have been sent.
Direct messages and group chats are the most common way a survivor shares a new photo with the people they trust, which is exactly what makes them the most likely path for an unintended leak. The same file you send to one trusted friend can be forwarded, screenshotted, or left on a device another person can access, and every one of those copies carries the original GPS data unless you scrubbed the file before the first send.
A new home address is the most sensitive data point of all
For most privacy concerns, a leaked GPS location is inconvenient.3 For a survivor of abuse, it can be the single piece of information that puts physical safety at risk. A new address is not just a point on a map; it is the place where someone sleeps, eats, and raises their children, so exposing it can undo months of careful planning, legal orders, and relocation steps. Consequently, the standard advice from safety advocates is layered: limit who can see new photos at all, and treat metadata removal as a baseline step rather than an afterthought for any photo that might reveal a current address.
Building a habit around every photo, not just the obvious ones
It is easy to scrub the photo that obviously shows a new front door, but harder to remember the casual photo taken from a porch, a balcony, or a car parked outside. Scrub every photo before sending it to anyone outside a fully trusted, vetted circle, regardless of whether the photo seems to reveal a location, since treating this as a default rather than a judgment call removes the risk of missing the one photo that matters.
The photos that cause harm are rarely the ones that look risky at first glance. A snapshot of a coffee cup on a kitchen counter, a selfie taken inside a living room, or a picture of a pet on a front step can all carry GPS coordinates that resolve to a specific building, even when nothing in the frame looks sensitive to the person sending it.
A simple rule that covers every case
If a photo will reach anyone outside your immediate control, run it through the scrubber first. CapyToolkit requires no account and leaves no trace on the device, which matters when you cannot fully trust the phone or computer you are using. The tool processes the file locally, so no server ever sees the image, and no sign-in means no account an abuser could check to see what you have been doing.
Applying one rule, scrub every photo before it leaves your device, removes the need to judge each file on its own. That consistency is what closes the gap between good intentions and actual safety, since the moment you start deciding which photos are risky enough to scrub is the moment one slips through.
Why shared cloud albums are a hidden metadata exposure point
Shared iCloud Photos albums, Google Photos shared albums, and similar collaborative photo libraries are designed for convenience, not privacy. When you add a photo to a shared album, the recipient typically receives the original file including all metadata, even if the sharing platform displays a stripped version in its own interface. Google Photos shared albums preserve the original EXIF data in the file the recipient downloads; iCloud Shared Albums similarly pass through the full metadata unless the sender has scrubbed the file first.
For a survivor who shares photos with a trusted friend or family member through a shared album, the risk is not the immediate recipient but anyone that recipient subsequently shares with. A photo that travels from a shared album to a group chat, then to a mutual acquaintance, accumulates exposure at each hop, and every copy carries the original GPS data if the file was never scrubbed.
Checking your existing shared albums
Review any active shared albums and remove photos that contain location metadata, replacing them with scrubbed versions downloaded from the scrubber. This cleanup takes minutes and closes a gap that most survivors, and most people in general, never think to check. The photos that cause harm are rarely the ones that look risky at first glance, so a thorough sweep of every shared album is worth the effort even when nothing seems obviously sensitive.
Start by opening each shared album, selecting the photos taken since you moved, and running them through the scrubber one at a time. Once you have replaced every location-tagged file with a clean copy, the album no longer exposes your new address through its metadata, even if a subscriber downloads every photo in the collection.
Device-level settings that reduce future metadata risk
Beyond scrubbing individual photos, changing your phone's camera settings prevents new photos from recording GPS coordinates in the first place. On iPhone, go to Settings > Privacy & Security > Location Services > Camera and select "Never."4 On Android, open the Camera app settings and disable "Store location" or "Location tags," depending on your manufacturer's menu labels.
These settings prevent future photos from carrying GPS data, but they do not affect photos already in your camera roll. The camera settings only stop new leaks; you still need to scrub the older photos still on your phone before you share any of them. Combining both approaches, disabling location for future captures and scrubbing the existing library, provides the most complete protection. Location Services toggles are buried in settings menus that most people set once and never revisit, so an abuser who knows how to check these settings can verify whether location tagging is enabled on a shared or previously shared device. Safety advocates at the National Network to End Domestic Violence include this step in their standard device safety checklist for exactly this reason.5
When to use this
Use this before sharing any photo with friends, family, or on social media if you are rebuilding your life after leaving an abusive or unsafe relationship and need to protect your current location.
Examples
Casual photo shared in a family group chat
GPS Latitude: 39.9526° N GPS Longitude: 75.1652° W Camera: Samsung Galaxy A54 Date: 2026-05-09 18:23:40
GPS, camera, and timestamp fields removed before sending
Group chats and direct shares typically do not strip metadata the way public social posts do.
- 1.
Safety Net Project, National Network to End Domestic Violence, "Choosing and Using Apps: Considerations for Survivors," techsafety.org, accessed June 2026. https://www.techsafety.org/choosingapps
- 2.
Electronic Frontier Foundation, "A Picture is Worth a Thousand Words, Including Your Location," eff.org, April 2012. https://www.eff.org/deeplinks/2012/04/picture-worth-thousand-words-including-your-location
- 3.
ExifTool, "GPS Tags," github.com, accessed June 2026. https://github.com/exiftool/exiftool/blob/78ef8fcf/html/TagNames/GPS.html
- 4.
Apple Support, "Turn Location Services and GPS on or off on your iPhone, iPad, or iPod touch," support.apple.com, January 2026. https://support.apple.com/en-us/102647
- 5.
Safety Net Project, National Network to End Domestic Violence, "Resources," techsafety.org, accessed June 2026. https://www.techsafety.org/resources