GPS in Photos: How Precise Is It, Really?

“Photos contain your location” is true but too vague to act on. The useful question is how precisely, and the answer is more specific than most people expect.

How the coordinates are stored

EXIF does not store a decimal number. It stores latitude and longitude the old way — degrees, minutes and seconds — as three rational values, each a pair of integers. A separate one-character field records the hemisphere: N or S for latitude, E or W for longitude.

To turn that into something you can put in a map, you convert:

decimal = degrees + (minutes / 60) + (seconds / 3600)

A test file we use during development encodes a position that comes back as 31.52040° N, 74.35870° E. That is the exact value our parser reconstructs from the degrees, minutes and seconds in the file, every build — a deliberate check, because a parser that merely runs is not a parser that is correct.

What each decimal place is worth

Latitude is the easy one, because a degree of latitude is very nearly the same distance everywhere: about 111 kilometres.

Decimal placesResolves toIn practice
1~11 kmA city
2~1.1 kmA district
3~110 mA street
4~11 mA building
5~1.1 mA room, or which side of the door you stood on
6~11 cmBeyond what consumer GPS can actually deliver

Longitude is narrower, and it narrows as you move away from the equator — a degree of longitude spans about 111 km at the equator but roughly 95 km at 31° north, where that test file was recorded.

Five decimal places, which is typical of what a phone writes, describes a spot about a metre across. It does not tell someone your neighbourhood. It tells them where you were standing.

A caveat worth stating plainly: stored precision is not accuracy. A phone that writes five decimal places is describing the position its receiver believed it held. Indoors, in dense city streets, or with a poor sky view, the true error can be tens of metres regardless of how many digits the file records. The number is precise; it is not always right.

The fields that come with it

Coordinates rarely travel alone.

  • GPSAltitude — height above sea level, with a reference byte for above or below. This is what distinguishes a ground floor from a fourteenth, and it is why “somewhere in that tower block” is often more specific than it sounds.
  • GPSTimeStamp and GPSDateStamp — recorded in UTC, separate from the camera’s own clock, which is usually local. The difference between the two reveals the time zone you were in, which occasionally contradicts a stated location.
  • GPSImgDirection — the compass bearing the lens was pointing, with a reference for true or magnetic north. Combined with the position, this describes not only where you stood but what you were facing.
  • GPSDestBearing, GPSSpeed, GPSHPositioningError — written by some devices. The last is the phone’s own estimate of how wrong it might be, which is the closest thing you get to an honesty field.

These live in a sub-directory of the EXIF structure rather than in the main block, which has a practical consequence: a tool that does not follow sub-directory pointers will report a photo as having no GPS data when it plainly does. That is not hypothetical — it is a bug we shipped and caught, and it only surfaced because the test fixture had a known answer to check against.

One photo is not the risk

A single photograph with coordinates tells someone where one thing happened once. That is usually unremarkable.

The risk is in the set.

Photographs accumulate. Take a few hundred over a few months and the coordinates alone describe a life: the place that appears at night and on weekends is home, the place that appears on weekday mornings is work, the places between them describe a route and a schedule. Add the timestamps and you have not only where but when, reliably enough to predict.

No individual photograph in that set feels revealing. Each one is a picture of a meal, a pet, a document, a thing you were selling. The pattern is the disclosure, and it emerges from files nobody thought twice about.

This is why “I have nothing to hide in this photo” answers the wrong question. The photo is not the unit of exposure. The archive is.

Where it matters most

Marketplace listings. Photographs of an item for sale, taken at home, published to strangers who have every reason to look closely. This is the single most common route by which home addresses leak, and it is entirely avoidable.

Anything posted anonymously. Coordinates in one image tie an anonymous account to a physical place. Combined with a camera serial number, which links every photograph a body has taken, the anonymity is thinner than it looks.

Photographs of children. School gates, front doors, regular routes. The aggregation problem again, with worse consequences.

Images sent during a dispute. Insurance claims, legal matters, anything contested. Coordinates and timestamps get examined by people whose job is to find inconsistencies.

What to do

Check first, decide second. Open a photograph in our EXIF viewer and see what is actually there — many devices do not write GPS at all, and many people have the setting off without knowing it.

If coordinates are present and the photograph is going anywhere public, strip them. It takes seconds, it happens in your browser, and it does not touch a single pixel of the image.

If you would rather solve it upstream, turn off location access for the camera app entirely. You lose the ability to organise photographs by place, which is a genuine loss — that feature exists because it is useful. The middle path is to leave it on for your own archive and strip on the way out.

How coordinates get in when you thought location was off

People are frequently surprised to find GPS data in files they believed were clean. There are four common routes.

The setting is per-app and was granted once. Camera location permission is often granted during setup and never revisited. Checking it is worth a minute.

A second app re-added it. Some editing and gallery applications write location back into an exported file from their own database, even when the source had none. Export a photo from a library that knows where it was taken and the coordinates can reappear.

The photo came from somebody else. Images received in a message, downloaded, or shared from a colleague carry whatever their device wrote. If you then publish one, you are publishing their location, not yours — which is a consideration people almost never extend to files they did not create.

It is in a sidecar or a duplicate. Editing workflows sometimes keep the original alongside an edited version. Strip the export, publish the original by mistake, and nothing was achieved.

The practical answer to all four is the same: check the file you are actually about to send, not the one you think you are sending.

Turning it off, and what it costs

If you would rather not deal with this per file, revoke location access for the camera app. Both major mobile platforms allow it, and the change takes effect immediately for new photographs.

What you lose is real. Photo libraries organised by place, maps of a trip, automatic albums grouped by location — all of that stops working, and for anyone with a large archive that is a genuine feature to give up.

The middle path most people end up preferring is to leave tagging on for the private archive and strip at the point of sharing. That keeps the organisational benefit and removes the exposure, at the cost of one deliberate step before anything goes public.

Either is defensible. Doing neither, and assuming the platform will handle it, is the option that reliably fails.


Read the coordinates in your own photos, and remove them, with the EXIF viewer and remover.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top