Skip to main content
← back to blog
Privacy

Platform behavior last verified:

Which apps strip photo metadata? The 2026 platform-by-platform guide

Instagram strips it, Telegram doesn't, and WhatsApp does both depending on how you send. Here's what every major platform does to your photo metadata — including the traps.

  • Instagram
  • WhatsApp
  • Discord
  • Telegram
  • platforms
  • EXIF

"Don't worry, the platform strips metadata anyway" is half true, and the half that's false is exactly where people get burned. Some platforms strip everything. Some strip nothing. Several do both, depending on which button you pressed when sending — and a few read your metadata to make decisions about your content before discarding it.

Here's the platform-by-platform reality as of August 2026. Behaviors change with app updates — treat this as the map, and verify individual files when it matters.

The quick reference

PlatformStrips metadata?The catch
Instagram / FacebookYes, from served imagesReads C2PA/IPTC first — can trigger an "AI info" label
X (Twitter)Yes
TikTokYes, from served video/imagesReads C2PA first for auto AI-labeling
LinkedInMostlyDisplays Content Credentials as a "CR" badge on some images
WhatsApp — photo modeYes
WhatsApp — document modeNoFull metadata delivered, GPS included
Telegram — default photoCompressed, most EXIF dropped"Send as file" preserves everything
iMessageNoFull-quality photos keep EXIF incl. GPS
SignalYesStrips metadata by design
Email (any client)NoAttachments are the original file, always
DiscordPartiallyBehavior differs by format (JPEG vs PNG) — don't rely on it
RedditYes, on standard image uploadsRe-encoding pipeline drops EXIF
Slack / TeamsNo for file sharesFiles transfer as files
Marketplaces (eBay, Craigslist, FB Marketplace…)Varies widelyAssume no until verified
Google Photos / iCloud shared linksPreservedSharing the original shares its metadata

Bolded rows are where real leaks happen.

The three traps that actually catch people

Trap 1: the mode switch. WhatsApp strips metadata from photos sent normally — and preserves 100% of it when someone sends "as document" to keep quality. Telegram is the same story: default sends compress and drop most EXIF; "send as file" delivers the original, coordinates and all. Same app, same contact, same photo — opposite outcomes. People pick the high-quality option precisely for the photos they care about, which are often the sensitive ones.

Trap 2: "it's just between us." The platforms that preserve the most metadata are the intimate ones: iMessage, email, Slack, file links. Feeds — where you're broadcasting to strangers — strip. Direct shares — where the file goes to one specific person along with everything embedded in it — don't. The mental model most people carry is exactly backwards.

Trap 3: read-then-strip. "Strips metadata" doesn't mean "ignores metadata." Instagram and TikTok read your file's C2PA and IPTC tags at upload and use them to decide whether to slap an AI label on your post — then discard the data. Your metadata can trigger an "AI info" label on a real photograph because of a Lightroom edit, even though no viewer will ever see the metadata itself. LinkedIn goes further and displays the Content Credentials badge. What's in your file shapes how platforms treat your content, whether or not it survives.

Why platforms strip at all

Not privacy altruism, mostly: re-encoding images for size and delivery speed happens anyway, and metadata is dead weight at feed scale. Stripping is a side effect of compression pipelines more than a policy. That's exactly why you shouldn't rely on it — a pipeline change, a new "high quality" upload option, or a format edge case (historically, some platforms handled PNG differently from JPEG) can change behavior without anyone announcing it.

Signal is the notable exception that strips metadata as policy. If you need a messenger that treats this as a security property, that's the one designed for it.

What this means for provenance data

One more 2026 wrinkle: as AI-provenance metadata becomes legally standard (EU rules since August 2), the fact that most platforms strip C2PA on upload creates an odd situation — the credentials industry is building an authenticity layer that mostly dies at the platform boundary. TikTok has moved to re-attach credentials so provenance survives download; most others haven't. Until that settles, assume any provenance you embed is for the platform's eyes, not your audience's — and any provenance you don't want read, remove before uploading, not after.

The reliable rule

You control exactly one link in this chain: the file before you send it.

So don't memorize the table — adopt the rule. If a photo is sensitive, clean it before it leaves your device, regardless of platform. Then the platform's behavior, this year's pipeline, and the sender's choice of mode all stop mattering. CleanImages shows you what's in the file and strips it in your browser — the photo never touches a server, including ours. Thirty seconds, and the question this entire article answers becomes irrelevant to you.

For what's actually in your files — GPS, device fingerprints, timestamps, AI generation data — start with what EXIF is and what a single photo can reveal.

TL;DR

Feeds strip, files don't. Instagram, X, TikTok, and Reddit remove metadata from what they serve (though some read it first and label your post accordingly). Email, iMessage, Slack, WhatsApp's document mode, and Telegram's file mode deliver everything, GPS included. The mode switch inside messaging apps is the trap that catches careful people. Clean sensitive photos before sending and the whole table stops mattering.

more in Privacy

see all →