What image metadata can reveal
Digital photos and exported artwork often carry information beyond visible pixels. EXIF commonly describes a camera, lens, exposure, capture time, orientation, and GPS coordinates. IPTC fields can identify a creator, credit, copyright notice, caption, or editorial location. XMP can contain editing software, workflow history, rights information, and application-specific values.
jpeg.id highlights useful fields and keeps the complete normalized metadata report bounded for safety. Metadata is rendered as inert text; values cannot become links, markup, or executable content.
Metadata is a declaration, not proof
EXIF, IPTC, and XMP fields can be edited, copied, removed, or generated by software. A camera model field does not cryptographically prove that a particular camera captured the pixels. A location field does not prove where the depicted event happened. A software field may describe only the latest application that saved the file.
jpeg.id displays editable metadata alongside—but never as—verified C2PA evidence. Missing metadata remains unknown rather than becoming a real/fake conclusion.
To understand cryptographically bound claims, use the Content Credentials checker and read how C2PA differs from ordinary metadata.
Check metadata before sharing a photo
Location and identity fields may be sensitive. Before publishing an original photo, inspect it for precise GPS coordinates, capture times, creator names, copyright values, device details, and editing history. Social platforms may strip some metadata, but behavior differs and can change; inspect the exact file you intend to distribute.
-
01
Select the final file. jpeg.id detects its real format.
-
02
Review declared metadata. Pay special attention to GPS and identity fields.
-
03
Export only when needed. Reports can themselves contain sensitive values.
Why this viewer stays local
Uploading a file to inspect its privacy exposure can create a second privacy exposure. jpeg.id parses supported image bytes in a disposable browser worker and transmits no filename, hash, manifest, or extracted metadata. There are no accounts, analytics, remote fonts, or runtime content delivery networks.