Covering a face, a plate, or a document in the picture changes what a human sees. It does not rewrite the EXIF block that many cameras and phones attach to the file. That block can include a timestamp, a device model, and — if location was enabled — coordinates precise enough to mark a house, a clinic, or a trailhead. People finish a careful pixel pass and feel done. The header was never in scope. Anyone who saves the image can read the tags without undoing a single blur.
This is a two-step privacy workflow: (1) cover the pixels that identify people or secrets in the scene, (2) strip metadata from the copy you will actually send. HideShot is step one. MetadataWipe is step two. Blurring a location that is visible in the frame (a sign, a skyline, a house number) is still a pixel job — see blur a location in a photo. Coordinates in the header are not in the frame. They need a strip, not a bigger box.
Guide
A JPEG or HEIC is not only a grid of colors. Typical camera files carry an APP1 segment (EXIF) and sometimes XMP or IPTC. Those structures store capture time, GPS, camera make and model, orientation, and vendor MakerNotes. Image editors that paint on a canvas are changing samples. Unless the export path is written to omit those segments, the tags ride along. PNG exports from some tools write fewer camera tags than the original JPEG — that is an accident of format, not a privacy policy. Other export paths copy EXIF into the new file. You cannot see the difference by looking at the picture.
Social posting still needs a pixel pass for faces, plates, and documents in the frame; redact a photo for social media is that sharing-oriented cover. Stay on this page for the missing half: why that cover is silent about the header, and how to complete the second step without mixing the two jobs.
Pixels and tags are different layers
Pixel redaction answers: can a person looking at the image read the secret? Metadata answers: can a person inspecting the file learn when and where the camera was, and which device wrote the file, without reading the scene? A black box over a face does not clear GPSLatitude. A strip of EXIF does not cover a face. Doing only one is how a “careful” post still maps a home, or how a “cleaned” header still shows a license plate in 4K.
GPS is the loud field. If Location Services was on for the Camera app, the JPEG can carry a pin of the room you stood in. Blurring the mailbox in the picture does not move that pin. Timestamps are quieter and still useful to someone reconstructing a timeline — DateTimeOriginal is independent of whether you covered a clock on the wall. Device tags (Make, Model, sometimes serial-like MakerNotes) fingerprint a handset across posts. None of these are rendered as letters in the photograph. Inspectors show them as fields. Free desktop “Get Info” / Properties panes show a subset. Dedicated EXIF viewers show more.
What visual redaction does not touch
HideShot loads the image onto a canvas, lets you mark regions, and writes a new raster. That is the right tool for on-image content: faces, plates, account numbers, screens. The canvas does not parse GPS IFD tags to decide whether you are “done.” If the download is a PNG, some camera EXIF may drop simply because PNG is a different container — do not bet on that. If the path you use later (email, a desktop convert-back-to-JPEG, a phone share sheet) re-wraps the image, tags can reappear from a sidecar or from the original you still hold. The reliable sequence is: finish pixels, then run a strip on the file that will leave the device, then verify the stripped copy in a metadata panel.
Thumbnail databases and cloud originals are extra copies, not extra tags inside the redacted PNG. iCloud Photos and Google Photos may still hold the geotagged master after you saved a covered PNG locally. The local PNG can be pixel-clean and header-clean after a strip, while the cloud object is neither. That is a cloud-order problem; the sibling site covers backup restoration in more depth. The point here is simpler: blurring in HideShot never logged into your photo library to rewrite the master.
The two-step order that actually matches the threats
- Cover the scene in HideShot on this page (or your usual HideShot tool page). Download the marked PNG. Zoom-check the pixels as you would for any redaction.
- Strip tags on the copy you will send. Open MetadataWipe, drop that PNG or a JPEG export of it, confirm GPS and camera fields were present if you expect them, strip, and re-open the cleaned download so the panel is empty.
- Send only the cleaned, marked file. Do not attach the camera-roll original because the thumbnail looks identical at 32 pixels.
- If the location is also in the pixels (street sign, house number, identifiable skyline), that is still a HideShot region — blur a location in a photo — in addition to stripping GPS. Two channels, two covers.
Reversing the order is possible but clumsier: if you strip first and then redact, some editors write a new Software tag or a new timestamp into the redacted export. Strip last on the file that will travel, or strip again after the pixel export if you care about those leftover processing tags.
False comfort from a “private-looking” picture
The face is a mosaic, so the photo feels anonymous. The pin in EXIF is still a home. Anonymity in the pixels is not anonymity in the header.
You covered every sign in a street photo. Good pixel work. Plot the GPS anyway, or strip it. The map does not need the sign.
You exported PNG and assumed PNG cannot hold metadata. PNG can hold tEXt, eXIf, and XMP chunks. Some cannot; some do. Inspect the file you will send.
You stripped last month’s photo and reused a blur from an old edit on a new original. New original, new header. Each generation is a new pair of jobs.
You posted the marked PNG and kept the geotagged JPEG in a public shared album as a “backup.” The album is the leak. The PNG being clean does not un-publish the JPEG.