The evidence desk
Start with the claim you need to verify
Each verdict separates what the sources support from what remains uncertain—and ends with a safer action you can take now.
01Moderate confidence
Messaging apps
A 2025 independent study found that WhatsApp image-mode transfers removed the tested EXIF fields, while sending the same images as documents preserved their metadata and file hashes. Treat that result as mode- and version-specific, not as a permanent WhatsApp privacy guarantee.
VerdictPhoto mode usually strips it; document mode can preserve it
02Moderate confidence
Social platforms
A 2025 independent study found that Instagram uploads were re-encoded and the tested critical EXIF fields were removed from the resulting image. That is useful evidence about the published copy, but it is not proof that Instagram collected no location, account, device, or upload metadata separately.
VerdictThe published image is typically re-encoded and stripped of critical EXIF
03High confidence
Email
Yes—when a photo is attached as a file, email normally transports the file data rather than sanitizing it. MIME specifies reversible transfer encodings, and a 2025 controlled study found identical hashes and complete tested EXIF retention for email attachments. Photo-app resize options can be an exception.
VerdictA normal file attachment usually preserves the original file data
04High confidence
Apple sharing
Yes. Apple’s current iPhone guide says sharing a photo includes associated metadata such as date, time, location, device, and captions. The share-sheet Options screen lets you turn Location off; enabling All Photos Data for AirDrop sends the original file with edit history and metadata.
VerdictYes, unless you turn Location off before sharing
05Moderate confidence
Cloud storage
Do not rely on Google Drive to remove embedded metadata. Google’s current help documents uploading, sharing, downloading, versions, and file conversion as separate actions; it does not describe link sharing as a metadata sanitizer. The conservative privacy assumption is that a downloaded uploaded file can retain its embedded metadata.
VerdictNo sanitization guarantee—treat uploaded file metadata as preserved
06High confidence
AI provenance
OpenAI, Google, Amazon, Microsoft, Adobe, and Meta document provenance signals for at least some generated media, but they do not all use the same mechanism. C2PA is an open metadata standard; SynthID and Amazon watermarks need compatible provider detection. Anthropic says Claude currently produces text and text-to-speech output and does not claim an equivalent deployed watermark.
VerdictWatermarking is growing, but detection remains signal- and provider-specific
07High confidence
AI regulation
The EU AI Act Article 50 marking and detection obligations apply from 2 August 2026, with separate disclosure duties for deepfakes and certain public-interest text. China’s explicit and implicit AI-content labelling measures have applied since 1 September 2025. The United States still lacks one equivalent general federal watermark mandate; provenance bills remain proposals unless enacted.
VerdictThe EU and China have operative marking duties; the US remains fragmented