What you reveal without meaning to

You’re publishing more than you post.

Ordinary digital acts carry riders you never chose to attach. A photo you upload can name the spot you stood in; a domain you register can list your home address. Two everyday cases — and how to close them.

Case one

The data hidden inside your files

A file is never just its contents. Photos and documents carry metadata — a hidden layer describing when, where, and how they were made — and most platforms don’t strip it for you.

A phone photo can embed the exact GPS coordinates where it was taken, the device that took it, and a timestamp. A document can carry the author’s name, the software used, and sometimes an edit history. Post it as-is and you’ve published all of that too.

WHAT YOU SEE HIDDEN IN THE FILE COORDINATES 40.4443° N, 79.9530° W DEVICE Apple iPhone CAPTURED 2026:03:14 15:22:07 CAMERA f/1.78 · 1/120 s · ISO 64 SOFTWARE Photos 1.0 · iOS
Illustrative. What a phone photo can carry beyond the image itself — the coordinates where it was taken, the device and its settings, and the moment it was shot. None of it is visible in the picture.

The location isn’t vague. The format stores the coordinates where you took the photo, next to the make and model of the device and its camera settings. Documents keep a different haul: Word, Excel, and PowerPoint files can hold the author’s and organization’s names, the software version, reviewer comments, the full record of tracked changes, and text that was deleted but never cleared. You can see all of it before anyone else does — a photo’s info panel shows where and on what it was taken, and Office’s Document Inspector lists everything a file is carrying.

Closing it is mostly a habit: strip the data before you share, on your own device, so nothing has to be uploaded to a stranger’s server to be cleaned. On an iPhone, the Share sheet’s Options let you drop the location from what you send, and the same screen removes it from a photo you’ve already saved. On a computer, ExifTool wipes an image in one line — exiftool -all= photo.jpg — and Office’s Document Inspector (File → Info → Check for Issues) pulls the author, comments, and change history out of a document before it leaves your machine. The cleaner fix is to stop the data being written at all: set the camera’s location permission to Never — on iPhone, under Settings → Privacy & Security → Location Services → Camera — and no coordinate is attached in the first place.

Case two

The address behind your domain

Register a domain and you’re legally required to give real contact details. Those details land in WHOIS — a lookup meant for subpoenas and abuse reports, not for anyone who’s curious about you.

Most registrars now offer WHOIS privacy that redacts your name and address from public view. Where that isn’t enough — for an activist or a source — shield registrars put their details on the record and take the legal exposure onto themselves, with real trade-offs for anyone who wants clear, official ownership of the name.

In progressStill being written: what WHOIS exposes, how registrar redaction works today, and the trade-offs of a shield registrar.

Get involved

It’s free, open to everyone at Pitt, and joining takes about a minute.

No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.