How Cloud Services Handle Your Photo Metadata (and What They Keep After You Delete the Original)
Published 28 August 2026 · 6 min read
Upload a photo to iCloud, Google Photos, or Dropbox and the EXIF data riding inside that file enters a pipeline you can't see. The camera model, lens, shutter speed, GPS coordinates, even the software version that took the shot, all of it travels with the image bytes into someone else's data centre. What happens next depends on the service, and none of them are particularly forthcoming about the details.
The question worth asking isn't whether these services strip metadata. Most of them do, eventually, for the copy that gets served back to you or shared with others. The question is what they keep on their servers, for how long, and who can see it.
iCloud Photos: Apple keeps the original file
Apple's iCloud Photos sync uploads the full original photo file, EXIF included. There's no stripping at upload. The photo on Apple's servers is the same file that came off your phone, metadata and all. When you view the photo through the Photos app, Apple reads that metadata to display location, date, and camera information. The data isn't hidden or removed, it's actively used.
Apple's privacy documentation states that iCloud data is encrypted on their servers, and that end-to-end encryption applies to certain data categories. Photos fall under the standard iCloud data protection tier, which means Apple holds the encryption keys and can access the content if compelled by legal process. The EXIF block inside your photo is part of the file content, so it receives the same protection level as the photo itself. That protection is against external access, not against Apple's own systems.
When you delete a photo from iCloud Photos, Apple says the file is removed from their servers within 30 days, and from backups after the next backup cycle. Until that window closes, the original file with full metadata sits in the Recently Deleted album and on Apple's infrastructure. If you shared the photo through a public iCloud link before deleting it, anyone with that link can still access the original file until the link expires, which can be up to 30 days.
Google Photos: metadata survives compression
Google Photos offers two storage tiers: Original quality and Storage saver. Original quality keeps the file as uploaded, EXIF intact. Storage saver recompresses the image, but the compression pipeline preserves most EXIF fields. Camera make, model, date, and GPS coordinates survive the recompression in practice. You can verify this yourself: download a Storage saver photo from Google Photos and run it through our EXIF checker. The GPS block is still there.
Google uses photo metadata for more than display. EXIF data feeds into Google's search and organisation features. When Google Photos groups your images by location, it's reading the GPS coordinates from EXIF. When it creates a "memories" slideshow around a specific date, it's reading the EXIF timestamp. The metadata isn't passive information sitting in a file, it's actively indexed and used to build features that keep you inside the product.
Google's data retention policy for deleted photos states that removal from Google's systems takes up to 60 days. During that window, the photo, with all its metadata, exists on Google's infrastructure. Google's transparency reports show they receive tens of thousands of legal requests for user data annually and produce data in response to a significant majority of them. Photo metadata, including location data, is part of what can be produced.
Dropbox: file storage, not photo management
Dropbox treats photos as files, which means it doesn't process, recompress, or strip anything. The file you upload is the file stored on Dropbox's servers, byte for byte. If your photo has GPS coordinates, camera serial numbers, and software version strings in the EXIF block, all of that's sitting in your Dropbox folder on Amazon S3 infrastructure, exactly as it left your phone.
This is the simplest model to understand, and the most honest: Dropbox is file storage, and file storage preserves files. The trade-off is that Dropbox offers none of the photo-specific privacy mechanisms Apple and Google have built. There's no option to strip location data from photos in your Dropbox. There's no EXIF-aware sharing mechanism. If you share a Dropbox link to a photo, the recipient downloads the original file with full metadata.
Dropbox retains deleted files for 30 days on standard plans and up to 180 days on Extended Version History. During that period, the file with all its metadata is recoverable. Shared links remain active until you revoke them, and anyone who downloaded the file through a link has a permanent copy of the original.
What sharing actually exposes
The sharing mechanisms across all three services have a common blind spot: they were designed before EXIF awareness became a consumer concern, and they default to sharing the original file or a derivative that preserves metadata.
iCloud shared links serve the original file. Google Photos shared links serve a compressed derivative that retains EXIF in practice. Dropbox shared links serve the original file. In all three cases, a person who receives your shared link can extract the GPS coordinates of where the photo was taken, the camera that took it, and the date and time down to the second.
The fix is the same across all platforms: strip the metadata before you upload, not after. Once the file is on someone else's server, you're relying on their deletion mechanism and their retention policy, neither of which you control. You can drag any photo onto the tool on our homepage to see exactly which fields are present before you share it. The check runs locally in your browser, nothing is uploaded, and it shows you every EXIF field the file carries, GPS included.
What deletion doesn't do
Deleting a photo from cloud storage removes it from your view, but the removal isn't instantaneous on any of the three platforms. Apple gives itself 30 days. Google gives itself 60. Dropbox gives itself 30 or 180 depending on your plan. During those windows, the file, with all its metadata, exists on infrastructure you can't access but others can request through legal process.
More importantly, deletion from your account doesn't delete copies that left your account. A photo shared by link, a photo downloaded by someone else, a photo that passed through a backup cycle before you deleted it, all of those copies persist with full metadata. Cloud deletion is account-level deletion, not file-level erasure.
The practical approach is simple. Before uploading anything sensitive, strip the metadata. The tool on our homepage does this in your browser, no upload required. Once the file is clean, upload the stripped version. The cloud service will store a file that has no GPS, no serial number, and no location data to index, display, or produce in response to a legal request. You can't retroactively clean a file that's already on Apple's, Google's, or Dropbox's servers. You can only clean it before it gets there.
Related: What Telegram, Signal and WhatsApp Actually Do With Photo Metadata · What Your Camera Serial Number Says About You