Short answer: sometimes, and more often than people expect. The picture is only part of what you share. The file around it can say where you were, when, which phone you used, and on some devices, who you are.
What can travel with a photo
Where you were. Location, often to within a few metres, plus altitude and the direction you were facing. Many phones have this switched off by default now; plenty don't.
When you were there. The date and time, and your time zone.
Which device, exactly. The make and model, and on many dedicated cameras the body and lens serial numbers. A serial number links every photo you've ever shared from that camera, and back to you if it was registered, repaired or sold.
Who you are. An owner or artist name set in a camera's menu. Some editing and tagging software also writes an author name into the file.
What you did to it. The software that edited it, sometimes a history of saves, and a small preview image that can still show the uncropped original after you've cropped something out.
Extra data some phones add. Some phones append their own record to the end of the file. On Samsung phones, for example, it includes the country of your SIM card.
What could someone do with it?
With location and time, a stranger can learn where you live, work or park. With a serial number, they can connect an anonymous account to a named one. With a date and a device, they can check a story you've told. Most of the time none of this happens. The point is to know what you're sharing.
Check your own photos
Upload a photo to snapWONDERS. It's free, needs no account, and works over Tor and I2P if you'd rather not check on the open web. The Privacy section lists what the file reveals, and you choose how long the report link stays active (anyone with the link can open it, so keep it to yourself).
A worked example: two phones, one scene
We photographed the same building in Melbourne about a minute apart: once with an Android phone (the file copied straight off the phone) and once with an iPhone (the photo sent to us by email).

Neither photo recorded where it was taken (the Android phone had location switched off). They still gave plenty away:

- The Android photo carried a small record after the picture, written by the phone, holding the country of the SIM card's mobile network and the capture time (which gives away the time zone). Tools that "remove metadata" often miss it, because it isn't stored where metadata usually is.
- The iPhone photo named the exact phone and lens it was taken with, even after being emailed.

Both are genuine (Authenticity A). The difference is what they expose.
Neither of these is dramatic on its own. Put together across the photos someone shares over time, they narrow down who, when and where, which is how a photo gets tracked back to a person.
Then remove it
See how to remove location and metadata from a photo. Removing hidden details doesn't make a photo anonymous, though: house numbers, school uniforms, street signs and the view from a window give away just as much.
Why this works
Kenneth Springer goes deeper in What your phone photos reveal about you and Your camera's fingerprint survives EXIF stripping.


