What EXIF Data Does Twitter/X Store or Strip?
Short answer: X strips the entire EXIF block — GPS, camera model, capture date, copyright — from every image it publishes. It does that after receiving your original file, which still had all of it. Below: the field-by-field split, how Twitter's policy got here and what the rebrand did and did not change, a two-minute check on whether GPS survived your upload, and why geotagged photos are a specific hazard for journalists and activists.
Stored, Stripped, or Still on Your Phone
Almost every argument about X and metadata comes from mixing up three different copies of the same photo. They contain different things, and only one of them is public.
The published image
Re-encoded by X's media pipeline, served with no EXIF. A stranger who downloads it gets pixels and nothing else — no coordinates, no camera, no shutter time. This is the copy the word "stripped" refers to.
What X received
The original file, byte for byte, metadata included. Stripping is something the receiving server does — your device uploaded the fields before anyone removed them. X had the GPS, whatever it does with it afterwards.
The file on your device
Untouched. Posting to X does not edit your camera roll. Send that same photo by email or as a chat attachment later and the GPS goes with it, because nothing ever removed it locally.
So "does X store your EXIF data" has two honest answers. It does not store it in anything the public can reach. It certainly received it. The difference matters if your threat model includes anyone other than a random person saving your picture.
What X Keeps vs. Strips, Field by Field
| Metadata field | In the published image? | Received by X on upload? |
|---|---|---|
| GPS coordinates | Stripped | Yes — sent in the upload |
| Original capture date/time | Stripped | Yes — sent in the upload |
| Camera or phone make and model | Stripped | Yes — sent in the upload |
| Lens, aperture, ISO, shutter speed | Stripped | Yes — sent in the upload |
| Copyright, artist, IPTC credit | Stripped — your credit too | Yes — sent in the upload |
| Orientation tag | Tag gone, rotation baked into the pixels | Yes, as a tag |
| Post timestamp and handle | Published — not EXIF, attached to the post | Created by X, not by your camera |
| Alt text and any location label you added | Published in full | Typed by you, unaffected by stripping |
The bottom two rows are where people get caught out. EXIF stripping is thorough and it is also narrow: it cleans the file and leaves everything you attached around the file completely intact. A post with no photo metadata at all can still say where you were, because you wrote it in the alt text.
How Twitter's Metadata Policy Got Here
The stripping is old, but it was not always there, and the pieces around it have moved more than the stripping itself:
- Before 2011, Twitter did not host photos at all. Images went through third-party services — TwitPic, yfrog, and others — and each one made its own call about metadata. Several passed EXIF through untouched, which is why archived photos from that era can still carry GPS today. If you are examining an old link rather than a modern post, check the file rather than assuming.
- Native photo hosting arrived in 2011, and with it a media pipeline that re-encodes uploads and serves them from Twitter's own image CDN. Re-encoding is what discards the EXIF block; the privacy result is a side effect of a bandwidth decision, which is worth remembering when you rely on it.
- Per-post location tagging was a separate feature and always has been. It was opt-in, it was visible on the post, and Twitter narrowed precise location tagging years before the rebrand. It has never been connected to your photo's EXIF — a post can carry a place label on a photo with no metadata, or carry no label on a photo that reached X with coordinates in it.
- The images kept getting bigger. Successive changes raised the resolution X serves, and higher-quality upload options have come and gone with subscription tiers. This does not affect EXIF, but it does affect what a reader can see: street signs, house numbers, and reflections that were unreadable in a 2013 render can be legible now.
What Changed After the Rebrand to X
Twitter became X in 2023 and the primary domain moved to x.com. For metadata specifically, the rebrand was cosmetic:
Unchanged: images are still re-encoded and served without an EXIF block. Post attachments, profile pictures, header banners, and photos sent in DMs all run through the same pipeline and come out stripped.
Unchanged: images are still served from the pbs.twimg.com image host, and the name= parameter on an image URL still selects the render size. That is what makes the check in the next section work on x.com links exactly as it did on twitter.com links.
Changed: ownership, policies, staffing, and the rate at which product surfaces get rebuilt. None of that shows up in a file, and all of it is a reason to verify current behavior rather than trust a policy summary — including this one.
Treat "X strips EXIF" as an observation you can re-run in two minutes, not a guarantee anybody made you. Pipelines change without announcement, and a habit built on one is only as good as the last time you tested it.
How to Check if GPS Data Survived Your Upload
This is the test that answers the question for your own photo, on today's pipeline, without taking anyone's word for it:
- Establish a baseline. Open the original photo — the one in your camera roll, not a screenshot — in our EXIF viewer and confirm you can see
GPSLatitude/GPSLongitudeon the map. If there is no GPS to begin with, the test proves nothing. - Post it somewhere you control. A protected account works, or post publicly and delete it straight after. Remember that the upload has already happened either way — deleting the post does not un-send the file.
- Save the published image back down.Right-click and "Save image as…" on desktop, or long-press and save on mobile. This is the copy every other user gets.
- Test the largest render, not a preview. Copy the image address, and change the
name=parameter at the end of the URL toname=orig. That fetches the biggest version X will hand anyone — so a clean result cannot be dismissed as "you only checked the thumbnail." - Run both saved files through the viewer. On a properly stripped image there is no GPS block, no
MakeorModel, and noDateTimeOriginal. Pixel dimensions and color space still show up — those are properties of the image itself, not the EXIF block, and their presence does not mean the stripping failed. - If GPS is still there, check which file you opened. Nearly always it is the original from your own camera roll, or a copy somebody sent you as a file attachment rather than one downloaded from a post. A file sent as an attachment is the untouched original, not X's copy.
The viewer parses files locally in your browser, so you can run this on a photo containing your real home coordinates without uploading it to us or anyone else. And be clear about what a clean result proves: the published image is clean. It says nothing about what X received, because that upload already happened in step two.
Check the photo before X does.
See a photo's GPS, capture date, and camera details in your browser — nothing is uploaded anywhere.
Open the EXIF ViewerCan You See What X Holds From Past Uploads?
Partly. X lets you request an archive of your data from the account settings, and it includes the media from your posts. Download it and run a few of those files through the EXIF viewer — it will tell you what the archive returned, which is worth knowing.
What it will not tell you is what X derived from your originals on the way in, how long anything is retained, or whether the stripped copy is the only one kept. An export shows what a company chooses to give back. Nobody can determine the rest from the outside, and a page that gives you a confident number for it is guessing. That uncertainty is the argument for the next section rather than a reason to shrug: what you never upload cannot be retained.
Geotagging Risks for Journalists and Activists
For most people, EXIF stripping closes the case: no stranger can pull coordinates out of your photo. If you are reporting from a protest, documenting abuses, or posting from somewhere you are not supposed to be, the residual risks are the ones that matter, and none of them are solved by the platform:
- The pixels geolocate you, not the metadata. This is how open-source investigators actually place photos: signage, architecture, vehicle plates, shop fronts, the shape of a skyline, shadow angles against a known time. Stripping EXIF does nothing here, and the higher-resolution images X now serves make it easier, not harder.
- Timing is a location signal. A post published minutes after the shutter fired puts you at the scene at a public, precise, permanently recorded time — attached to your handle. The capture timestamp was redundant.
- Your own labels leak more than EXIF would.A place tag or an alt-text description like "from my window on Rue X" is plain text anyone can read, no forensic tooling required. It is also entirely under your control.
- The original file outlives the post. You uploaded it with coordinates in it, and deleting the post does not recall it. Where sources or safety are involved, plan for the upload itself, not for the published result.
- Cross-posting breaks the assumption. The same photo sent to a colleague as an email attachment, a chat document, or a cloud-drive link travels with full EXIF — those paths strip nothing. One habit that survives every platform is cleaning the file, not remembering which service is safe.
- Faces and identifying detail are not metadata problems. Blur or crop before posting. No metadata tool addresses who is recognizable in the frame, and for people photographed at a protest that is usually the higher-stakes exposure.
The practical version: strip the file first, post the clean copy, and treat everything outside the file — your caption, your alt text, your posting time, and what is visible in the frame — as the part that actually needs a decision. Our photo privacy guide covers the platform-by-platform picture, including the services that strip nothing at all, and the photo privacy checklist is the short version to run before a sensitive post.
Keep the Metadata Out of the Upload
Because X strips on the way out and not on the way in, the only way to keep a field away from it is to remove the field before you post:
- Strip the file in your browser. Our metadata remover rewrites the photo locally and gives you back a clean copy to post. Nothing is uploaded to us, and X gets an image with no EXIF to strip.
- Turn geotagging off at the source.On iPhone: Settings → Privacy & Security → Location Services → Camera → Never. On Android, disable location tags in the camera app's own settings. Photos taken afterwards never have coordinates to remove — details in our iPhone and Android guides.
- Check before posting, not after. Opening a photo in the viewer takes seconds and is the only step that tells you what is actually in this file rather than what is usually in files like it.
- Use a pre-share routine. Our strip metadata before sharing guide is the checklist, and it applies wherever the photo is headed next.
A file you cleaned yourself is safe on every platform at once — on the day the pipeline changes, and on the day you tap the wrong attach button.
Related Guides
Does Twitter/X Remove EXIF Data?
The uploader's question, with the DM and profile-picture edge cases and what a metadata tool can honestly verify.
EXIF Viewer
Check any photo's GPS, capture date, and camera details in your browser.
What EXIF Data Does Facebook Store?
The same split on Meta's side — plus the IPTC tag Facebook adds to every image it serves.
Remove Photo Metadata
Strip EXIF from a photo and download a clean copy before you post it.
Photo Privacy Guide
Which platforms strip metadata, which do not, and how to share photos safely.
Which Social Media Sites Strip EXIF Data?
Platform-by-platform comparison of what gets removed and what gets passed straight through.
Frequently Asked Questions
What EXIF data does Twitter/X store?
Nothing in the image it publishes — GPS, camera make and model, capture date, exposure settings, and copyright tags are all removed from the file other users can download. X does receive the original on upload, with every one of those fields in it, because stripping happens on its servers after your file arrives. What it retains from that original is not something anyone can determine from outside the company.
How do I check if my GPS data survived an upload to X?
Save the image back down from the post, then copy its image address and change the name= parameter at the end of the URL to name=orig so you are testing the largest render rather than a preview. Open both files in an EXIF viewer. A stripped file has no GPS block, no camera make or model, and no original capture date. If you still see coordinates, you almost certainly opened your own original rather than the copy downloaded from X.
Did the rebrand from Twitter to X change how metadata is handled?
Not in any way that shows up in a file. Images are still re-encoded and served without an EXIF block, still delivered from the pbs.twimg.com image host, and the URL parameter that selects the render size still works. What changed is everything around the pipeline — ownership, policies, how quickly product surfaces get rebuilt — which is a reason to re-run the check yourself rather than trust any summary of current behavior.
Has Twitter always stripped EXIF data?
No. Twitter did not host photos itself until 2011; before that, images went through third-party services such as TwitPic and yfrog, several of which passed metadata through untouched. Old archived images from that era can still carry GPS. Since native photo hosting arrived, uploads have been re-encoded and served without their EXIF block.
Can someone find my location from a photo I posted on X?
Not from the photo's metadata — X removes it. They can from a location label you attached to the post, from alt text describing where you were, from the post's own timestamp, and above all from what is visible in the frame: street signs, house numbers, storefronts, recognizable views. Those are the real risks once EXIF is off the table, and none of them are affected by stripping.
Is X safe for posting sensitive photos as a journalist or activist?
EXIF stripping removes one specific risk and leaves the bigger ones in place. Assume the original file reached X's servers with its coordinates intact and that deleting the post does not recall it; assume the visible content of the image can be geolocated, especially at the resolutions X now serves; and assume your posting time places you at the scene. Strip the file before uploading, blur or crop identifying detail, and decide deliberately about captions, alt text, and when you post.
Does X store metadata from photos sent in DMs?
Photos sent in direct messages go through the same media pipeline and come out re-encoded without EXIF, so the recipient cannot read your coordinates from the image. The upload itself works the same way it does for a post: your device sent the original file first. If it matters, strip the photo before sending rather than relying on a pipeline behavior that can change without announcement.
How does X compare to Facebook and Instagram?
All three strip EXIF from the images they publish, and all three receive your original on upload. The visible difference is that Facebook writes its own IPTC tracking tag into the file it serves, which X does not — see what EXIF data Facebook stores. The practical advice is identical everywhere: clean the file before it leaves your device.