Remove Photo Metadata for Journalism and Source Protection
EXIF removal is a necessary step in protecting a source. It is nowhere near a sufficient one, and this page is explicit about the difference.
100% Local — Works Offline, Nothing Transmitted
Strip metadata from your photos now
Drop your .heic files into the converter. They are decoded and re-encoded on your own device, and the result carries no EXIF block — no GPS, no timestamps, no device details.
Open the converter Converting re-encodes pixels only. The EXIF block does not survive.Zero uploads
The decoder runs in your browser via WebAssembly. Your files never touch a server, so there is nothing to retain, leak or subpoena.
Works offline
Load the page, disconnect, and it still converts. Nothing is transmitted at any point in the process.
Coordinates removed
GPS latitude, longitude and altitude are dropped along with the rest of the EXIF block.
What this tool does, precisely
It decodes the image and re-encodes the pixels, producing a file with no EXIF block: no coordinates, no timestamps, no device or lens identifiers. Because the decoder runs in your browser, the original never leaves the machine — you can verify that by disconnecting from the network and converting anyway.
For a newsroom handling images from a source, that is a genuine improvement over any tool that requires an upload.
What it does not do — read this before relying on it
Metadata is one channel among several. The visible content of a photograph identifies places and people; the transmission path leaks IP addresses and timing; a document photographed on a screen can carry printer tracking dots or watermarks; and if a file has been shared before, earlier copies still exist with their metadata intact.
Sensor pattern noise is a further consideration in adversarial contexts: images from the same camera can in principle be linked to each other, and re-encoding does not reliably defeat that. If a source's safety depends on this, use a purpose-built workflow — SecureDrop, Tails, or your organisation's security desk — and treat metadata stripping as one step inside it rather than the protection itself.
One layer, not a shield
Metadata removal protects the file. It does not protect the connection, the account, the visible content of the photograph, or copies already sent. For high-risk work, use SecureDrop or Tails and take advice from a security desk before transmitting anything.
Frequently asked questions
Is removing EXIF enough to protect a source?
No, and it is important to be clear about that. Stripping metadata removes one identifying channel. It does nothing about the visible content of the image, the transmission path, prior copies of the file, or account and device identifiers captured by whatever platform receives it.
Where a person's safety is at stake, use an established source-protection workflow such as SecureDrop and consult your organisation's security lead. This tool is one component, not a solution.
Can I use this offline?
Yes. The decoder loads with the page; once it has, conversion works with the network disconnected. That is a reasonable way to satisfy yourself that nothing is being transmitted.
How does converting remove metadata?
HEIC stores EXIF in a metadata box inside its container; a JPEG stores it in an APP1 segment at the head of the file. PixHeic decodes your photo to raw pixels and re-encodes them, and nothing writes a new EXIF block — so GPS coordinates, capture timestamps and camera details are simply absent from the result rather than blanked out.
What information is left in the converted file?
The pixels, their dimensions, and the JPEG encoder's own markers. No location, no date, no device or lens identifiers, no serial number. What the picture shows is untouched, which is the part people underestimate — a street sign or a recognisable window frame carries location information no metadata tool can remove.