How to Share Photos Privately Online: Safety Checklist
A practical checklist for sharing photos without oversharing: strip location data, use unlisted links, set expiry and know how to delete what you shared.
By PictureToLink Team · · 8 min read
Facts checked against official sources on
On this page
To share photos privately online, remove the hidden location data first, check the picture itself for details you did not mean to show, send it by an unlisted link or a direct message rather than a public post, and set the link to expire if it is only needed for a while. Keep the delete link so you can take it down later. No method is completely private once someone else has the image, so the safest photo is the one you decide not to share.
What can a photo reveal when you share it?
A photo can reveal more than the moment it captures. Information gets out in four ways: hidden metadata such as GPS coordinates and device details, visible details in the frame, the link itself being forwarded or posted, and the service that stores the image, including who can browse it and how long it is kept.
Before working through the checklist, here is an example of each:
| What leaks | How | Example |
|---|---|---|
| Hidden metadata | GPS coordinates, date, time and device details stored inside the file | A photo of something you are selling carries your home's coordinates |
| Visible details | Things in the frame you did not notice | A house number, a school logo, a letter on the table, a screen in the background |
| The link itself | Links get forwarded, pasted in group chats or posted publicly | A link sent to one friend ends up in a forum thread |
| The service | Who stores the image, who can browse it and how long it is kept | An image posted to a public gallery is indexed and copied |
The checklist below deals with each one in the order you would meet them: before upload, during sharing and afterwards.
The checklist at a glance
- Remove location and other metadata.
- Look at the whole picture, including the background and reflections.
- Crop or cover anything sensitive properly (not with a light blur).
- Choose an unlisted link or a direct message, not a public post or gallery.
- Set an expiry time if the photo is only needed briefly.
- Save the delete link somewhere safe.
- Send the link only to the people who need it.
- Delete the image when it has done its job.
How do I remove location data before sharing a photo?
On iPhone, tap Share, then Options, and turn off Location before you send. On any device, run the photo through a metadata remover such as our free EXIF remover, or upload it to PictureToLink, which discards GPS coordinates, camera model and date taken from every upload. Then check the cleaned copy's info panel.
Most phone photos contain EXIF metadata, and many include the exact GPS position where they were taken. Apple's personal safety guide warns that people you share photos with "may be able to access the location metadata and learn where it was taken." Our explainer on what EXIF data is lists every field a typical photo contains.
Ways to remove it:
- On iPhone, while sharing: select the photos, tap Share, tap Options, then turn off Location. Apple's guide says "Location Not Included" then appears above the Options button.
- On iPhone, for future photos: go to Settings > Privacy & Security > Location Services > Camera and choose Never.
- In Google Photos: location sharing is a setting, not a given. Google's help page on photo locations explains that if your camera added a location and you share the photo on Google Photos, the photo shows that location. For shared albums there is a Share photo locations option, which Google says is turned off by default for new shared albums. Partner sharing is different: Google says that if you set it up, all photos you share have location details.
- On any device: run the photo through our free EXIF remover and share the clean copy.
- If you are sharing by link anyway: uploading to PictureToLink does this step for you. Every upload is re-encoded, and all embedded metadata (GPS coordinates, camera model, date taken) is discarded before the image is stored.
After removing it, check. Open the cleaned copy's info or properties panel and make sure no map or coordinates appear.
Check the background
Metadata removal does nothing about what is visible. Take ten seconds to look at the whole frame, then zoom in on the edges:
- House numbers, street signs and car number plates, including ones reflected in windows or seen through them.
- Documents and screens. Letters, parcels with address labels, open laptops and phone notifications in the background.
- School uniforms, badges and lanyards, which can identify a school or employer.
- Views from windows. A distinctive skyline or landmark narrows down a location quickly.
- Reflections in mirrors, glasses, glossy surfaces and eyes.
- Faces of other people, especially children, who have not agreed to be shared.
If something needs to go, crop it out or cover it with a solid block. A light blur or pixelation can sometimes be partly reversed or can still be readable, so for text such as names, addresses and account numbers, a solid box is safer. Our guide to redacting screenshots safely explains why.
Should I use an unlisted link or a public gallery?
For photos meant for a few people, use an unlisted link or a direct message, not a public post or gallery. Public posts can be found by anyone, often including search engines. An unlisted link can only be found by people who have it. But a link is not a password: anyone you send it to can forward it.
Where you put the photo matters as much as what is in it. There are three broad levels of exposure:
| Sharing method | Who can find it | Good for |
|---|---|---|
| Public post or public gallery | Anyone, often including search engines | Photos you are happy for the world to see |
| Unlisted link | Only people who have the link | Sending to a few people without an account on either side |
| Private album or direct message with sign-in | Only invited accounts | Family photos, ongoing private sharing |
An unlisted link is a practical middle ground. On PictureToLink, every image gets a random link that is not listed anywhere on the site, share pages ask search engines not to index them, and they carry no ads. But be clear about the limit: a link is not a password. Anyone you send it to can open it, and they can forward it to anyone else. We cover this in more depth in are image links private?
Practical rules for links:
- Send the link in a direct message or email, not in a public comment or group chat with people you do not know.
- Use one link per audience. If you need to send the same photo to two groups, upload it twice so you can delete one without affecting the other.
- Do not upload anything you would be harmed by if it became public: identity documents, bank details, intimate images or photos that reveal where children are. For those, use an end-to-end encrypted messaging app or do not share them at all.
Use expiry and delete links
Most photos only need to be available for a short time: a picture of a damaged parcel for a seller, a room photo for a landlord, a screenshot for tech support. Setting an expiry means you do not have to remember to clean up.
On PictureToLink:
- Before uploading on the homepage, open the options and set Auto-delete to 1 hour, 1 day, 7 days or 30 days.
- Upload the photo and copy the link you need.
- Copy the private delete link shown under the upload and keep it somewhere safe. It is also remembered under "Recent uploads" in the browser you used, but only on that device.
If you choose not to set an expiry, the image stays online while people keep viewing it and is removed after 12 months without a single view. Deleting it with the delete link is permanent, and every link to the image stops working.
Treat the delete link like a key. Anyone who has it can delete the image, so do not send it along with the share link.
Our guide to temporary image links helps you pick a sensible expiry for common situations.
Can I undo sharing a photo?
You can only partly undo sharing a photo. You can delete the image from the host, which stops every link to it working, remove it from shared albums and report re-posts. You cannot recall copies someone downloaded, saved or screenshotted, control links forwarded before you deleted it, or guarantee removal of copies on other sites.
Once a photo has been seen, some things are within your control and some are not.
What you can do:
- Delete the image from the host. Every link to it stops working, including the direct link, the share page and any embed codes.
- Remove it from shared albums or stop sharing an album in the service you used.
- Change your settings for next time, such as turning off camera location or switching off location sharing in shared albums.
- Report misuse. If someone has re-posted your photo somewhere else, use that site's reporting or takedown process. If it was uploaded to PictureToLink by someone else, use our report form via the FAQ.
What you cannot do:
- Recall copies. If someone downloaded, saved or screenshotted the photo, deleting the original does not affect their copy.
- Control forwarding. A link that was forwarded before you deleted the image may already have been opened.
- Guarantee instant removal everywhere. Copies on other sites, or in other people's apps, are outside the original host's control.
This is why the earlier steps matter most. Stripping location data, checking the background and choosing who gets the link are the parts you fully control.
Next step
Before your next upload, open the photo's info panel and check for a location. Then upload it on the PictureToLink homepage with an auto-delete time set, send the share page link only to the people who need it, and keep the delete link to yourself.
