Advertisement
Advertisement
Flip Caps

Text Tools

Text Case ConverterLetter & Character RemovalDuplicate Line RemoverDuplicate Word FinderEm Dash RemoverDash RemoverFind and Replace TextSentence CounterRemove Line BreaksRemove Text FormattingRemove UnderscoresReverse Text GeneratorAlphabetical OrderEmail ExtractorURL ExtractorUpside Down TextAdd Commas to NumbersRemove EmojisBold Text GeneratorItalic Text GeneratorSlug GeneratorLorem Ipsum GeneratorText RepeaterRemove AI Formatting

PDF Tools

Merge PDFSplit PDFCompress PDFExtract PDF PagesJPG to PDFPNG to PDFPDF to JPGPDF to PNGAdd WatermarkAdd Page NumbersHeader & FooterTable of ContentsRemove Blank PagesPassword Protect PDFPDF to DXFUnlock PDF

Unit Converters

CM to InchesMM to InchesMeters to FeetKM to MilesCM to FeetInches to FeetMeters to YardsInches to CMInches to MMFeet to MetersMiles to KMFeet to CMFeet to InchesYards to MetersKG to LBSGrams to OuncesPounds to OuncesLBS to KGOunces to GramsOunces to PoundsCelsius to FahrenheitFahrenheit to CelsiusLiters to GallonsmL to CupsGallons to LitersCups to mLMPH to KPHKPH to MPHAcres to Square FeetSquare Feet to AcresRadians to DegreesDegrees to RadiansHP to KWKW to HP

Image Tools

PNG to JPG ConverterJPG to PNG ConverterWebP to JPG ConverterWebP to PNG ConverterPNG to WebP ConverterJPG to WebP ConverterImage ResizerImage CompressorCrop ImageRotate ImageWatermark ImageMeme GeneratorPhoto EditorFavicon GeneratorAdd Logo to ImageRemove EXIF DataHEIC to JPG ConverterCircle CropBlur and Pixelate ImageJPG to DXF Converter

Calculators

Age CalculatorPercentage CalculatorDiscount CalculatorTip CalculatorCalculatorScientific CalculatorCompound Interest CalculatorLoan CalculatorMortgage CalculatorSavings Goal CalculatorBMI CalculatorCalorie CalculatorPregnancy Due Date CalculatorIdeal Weight CalculatorGPA CalculatorGrade CalculatorHours Worked CalculatorDate Difference CalculatorDays Until CalculatorRoman Numeral ConverterFraction CalculatorRatio CalculatorAverage CalculatorRetirement CalculatorDebt Payoff CalculatorBody Fat CalculatorOvulation CalculatorBlood Alcohol CalculatorFuel Cost CalculatorUnit Price CalculatorBudget Planner (50/30/20)Monthly Expense CalculatorPaycheck CalculatorTax Refund Estimator

Fun & Random

Spin the WheelDice RollerCoin FlipperRandom Quote GeneratorRandom Number GeneratorYes or No GeneratorKeyboard TesterDead Pixel TesterCamera Shutter Count CheckerRandom Team GeneratorChore WheelMagic 8-BallTyping Speed TestPros and Cons ListBaby Name GeneratorUsername GeneratorFantasy Name GeneratorBusiness Name GeneratorNew Year's Resolution Tracker

Word Games

Word UnscramblerJumble Solver

Games & Puzzles

Memory MatchTic-Tac-ToeHangman2048Word Search GeneratorSudokuDaily WordMinesweeperSliding PuzzleLights OutSimon SaysReaction Time TestDots and BoxesConnect FourMastermindSnakeTower of Hanoi

Design & Color

Color ConverterRandom Color GeneratorQR Code GeneratorColor Palette Generator

Time Tools

Alarm ClockOnline TimerStopwatchTime Zone ConverterSleep CalculatorHoliday Countdown

Media Tools

GIF EditorMOV to MP4 ConverterAudio ToolsVideo to MP3Replace Audio in VideoTrim AudioMP4 to WebM ConverterWebM to MP4 ConverterMKV to MP4 ConverterAVI to MP4 ConverterMOV to GIF ConverterMP4 to GIF ConverterVideo TrimmerMute VideoRotate VideoVideo CompressorVideo ResizerExtract Video FrameCrop VideoWatermark VideoMerge VideosSplit VideoVideo Speed ChangerReverse VideoAudio ConverterOGG to MP3Audio CompressorMerge AudioAudio Speed ChangerAudio Volume Booster

Developer Tools

Password GeneratorBase64 Encoder/DecoderNumber to WordsScreen Resolution CheckerAspect Ratio CalculatorVanishing Note - Self-Destructing NotesScript SplitterPrint Pad
← Blog|Productivity

How to Share Files Safely Online Without Leaking Data

21 min read
Advertisement

You take a photo of something you are selling and post it in a local group. You send a proposal to a prospective client. You email a spreadsheet to a colleague. Each of these feels like sending exactly one thing: the picture, the proposal, the numbers. In reality each file carries a quantity of additional information you never chose to include, and some of it is information you would refuse to send if anyone asked you for it directly.

Complete guide to sharing files safely online covering hidden metadata, watermarks, passwords and secure delivery methods

This is not a guide about paranoia, and it is not about locking everything down until sharing becomes impractical. It is about the routine, boring gap between what you think you are sending and what you are actually sending, and about closing that gap with a few habits that take under a minute each. We will cover what files reveal, how to strip it, when watermarking is worth the effort, how access control actually works, which delivery method suits which sensitivity level, and a checklist you can run before anything leaves your machine.

What Your Files Reveal About You

Every file is two things at once: the content you can see, and the metadata describing it. Metadata exists for good reasons. It lets your photo library sort by date, lets a camera remember its settings, lets a document track who edited what. It becomes a problem only when a file leaves the context it was created in, which is precisely what sharing does.

Hidden metadata in photos and documents including GPS coordinates, device details, author names and edit history

Photos

Photographs carry EXIF data, written automatically by the camera or phone at the moment of capture. A typical smartphone photo contains:

  • GPS coordinates accurate to within a few metres, if location services were enabled.
  • Date and time of capture, to the second.
  • Device make and model, and often the operating system version.
  • Camera settings: aperture, shutter speed, ISO, focal length, flash.
  • Orientation, lens information, and on some devices the serial number of the camera body.
  • Editing history if the image passed through certain software, sometimes including the name of the software licence holder.

The coordinates are the part that matters. A photo of a bicycle taken in a driveway carries the driveway's location. A picture of a child in a garden carries the garden's location. A photograph of an item for sale, taken indoors, geolocates a home containing something worth stealing. None of that is visible in the picture, and all of it travels inside the file.

Timestamps matter more than people expect too. A sequence of photos with times and locations describes a pattern of movement, and patterns are more revealing than any single point. Someone reviewing a year of a person's posted images can often infer where they live, where they work, when they leave, and when the house is empty.

Documents

Office documents and PDFs are frequently worse than photos, because the hidden content is often text that was deliberately removed.

  • Author and last modified by, usually a real name, sometimes an internal username.
  • Organisation name from the software licence.
  • File path of where it was saved, which can expose an internal folder structure or a client name.
  • Total editing time, which occasionally tells a client something you would rather it did not.
  • Tracked changes and comments, including ones you thought were resolved.
  • Earlier versions retained inside the file by some applications.
  • Hidden rows, columns and sheets in spreadsheets, which are hidden from view and entirely present in the data.
  • Text under redaction rectangles in PDFs, when someone drew a black box over text rather than removing the text itself.

That last one is a genuinely famous category of failure. A black rectangle placed over a paragraph in a PDF is a graphic sitting on top of text. The text is still there, still selectable, and copies out perfectly into any text editor. Real redaction means deleting the content and flattening the page, not covering it.

The Practical Risk

It is worth being proportionate here. Nobody is examining the EXIF data of your holiday snap. The realistic risks are narrower and more mundane:

Marketplace listings. Photos of items for sale, taken at home, with coordinates attached, shared publicly with strangers who now know both what you own and where it is.

Anonymity that is not. Anyone posting under a pseudonym who uploads original photos is one metadata check away from being located.

Professional embarrassment. A proposal sent to a client with a previous client's name in the file path, or with tracked changes showing the price you originally intended to quote.

Personal safety. For people managing a stalking or harassment situation, location metadata is not an abstract concern. It is the specific mechanism by which addresses get found.

The reason to build the habit is that you cannot reliably predict which of your files falls into these categories, and the cost of stripping metadata routinely is close to zero.

Stripping Metadata Before You Send

The fix is simple and fast. What matters is doing it consistently rather than only when you remember to be careful.

Removing EXIF metadata and GPS location data from photos before sharing them online

Photos

Removing EXIF data does not alter the image itself in any visible way. The pixels are untouched; only the descriptive block travelling alongside them is deleted. A stripped photo looks identical and behaves identically, minus the coordinates.

An EXIF data remover handles this in the browser, which matters more than it sounds. Uploading a photo to a server in order to remove its location data has an obvious circularity to it: you have just sent the file, coordinates and all, to somebody else's computer. Processing locally means the image never leaves your machine, and the version you send afterwards is genuinely clean.

Because the same concern applies to every photo in a batch rather than one at a time, doing this for a whole set at once is the practical approach. A marketplace listing with nine photos needs all nine stripped, and stripping eight is the same as stripping none.

A Note on Screenshots

Screenshots do not carry GPS data, but they carry something arguably worse: whatever was visible on your screen. Notification banners, other browser tabs, a taskbar showing which applications are running, an email preview in the corner, the name of the network you are connected to, a partially visible document behind the window you meant to capture.

Before sharing a screenshot, look at the entire image rather than the part you care about. Crop tightly to the region that matters. If something sensitive is inside the region, cover it with a solid filled shape and re-export the image as a flattened file, so the covering is baked into the pixels rather than sitting as a removable layer.

Documents

For documents, work through this sequence before sending:

  1. Accept or reject all tracked changes, then confirm tracking is off.
  2. Delete every comment, including resolved ones, which some applications retain.
  3. Unhide hidden rows, columns and worksheets, check what is in them, then delete rather than re-hide anything that should not travel.
  4. Clear the document properties, which most office applications expose through an inspect or remove personal information function.
  5. Export to PDF, which discards a great deal of application specific baggage.
  6. Open the PDF and try to select text under any redaction. If it selects, the redaction is cosmetic and the document is not safe to send.

If a PDF contains pages that should not be shared at all, remove them rather than trusting the recipient to skip them. A PDF splitter lets you extract only the pages that should travel, which is both safer and more considerate than sending a forty page document and asking someone to look at pages nine to twelve.

Where a document has been assembled from several sources, exporting and reassembling it cleanly also strips a lot of inherited metadata along the way. A PDF merger produces a single new file from your chosen pages, which is a tidier artefact than a chain of forwarded attachments.

Strip GPS coordinates, device details and timestamps from your photos before they leave your computer.

Try the EXIF Data Remover

Watermarking Work You Share

Metadata removal is about what you do not want to send. Watermarking is about what happens to a file after it arrives.

Watermarking images and documents to deter unauthorised reuse and identify the source of shared files

Be clear about what a watermark does and does not achieve. It does not make a file impossible to steal. Anyone determined enough can crop, clone out, or reconstruct. What it does is change the economics of casual reuse: it makes copying inconvenient, makes the source identifiable wherever the file travels, and signals that the owner is paying attention. For the overwhelming majority of real world reuse, which is opportunistic rather than determined, that is sufficient.

When It Is Worth Doing

  • Client proofs. Photographers and designers sending previews before payment. The watermark is what makes the unpaid version unusable.
  • Portfolio images published where anyone can right click and save.
  • Draft documents circulating internally, marked DRAFT or NOT FOR DISTRIBUTION so a version cannot be mistaken for final six months later.
  • Confidential material sent to multiple parties, where a per recipient watermark tells you exactly which copy leaked if one does.
  • Stock and licensed material where attribution needs to survive the file being passed on.

Doing It Well

A bad watermark is either invisible or ruins the image. Both fail.

Place it where cropping hurts. A mark tucked in a corner is removed with one crop. A mark positioned across a meaningful part of the image cannot be removed without damaging what makes the image worth taking.

Use partial opacity. Somewhere between thirty and fifty percent is usually right: legible, but not obscuring the work you are trying to show.

Consider a repeating pattern for high value material. A diagonal tiled mark across the whole frame is far harder to remove than a single logo.

Keep it consistent. The same mark, the same position, the same opacity across everything you publish, so it reads as a signature rather than an afterthought.

An image watermarking tool applies text or a logo across a whole batch at once with shared settings, which matters because watermarking is only useful if every image in a set carries it. One unmarked file in a gallery of forty is the one that ends up circulating.

For documents, the same principle applies with different placement. A diagonal DRAFT or CONFIDENTIAL across each page of a PDF is standard practice, and unlike a footer it survives someone screenshotting a single page.

Sizing Before You Publish

One quiet form of protection is simply not publishing the full resolution original. A portfolio image displayed at 1200 pixels wide does not need to be an 8000 pixel file, and providing the large version gives away something you might otherwise sell. Publishing at display size is both a performance improvement and a limit on what a copied file is worth, and running images through an image compressor before publishing achieves both at once.

Passwords and Access Control

For genuinely sensitive material, stripping and watermarking are not enough. You need to control who can open the file at all.

Password protecting documents and using access controlled links with expiry dates for sensitive file sharing

Two Kinds of PDF Password

This distinction is important and widely misunderstood.

An open password encrypts the document. Without it, the file cannot be read at all. On a modern PDF with strong encryption and a strong password, this is real protection.

A permissions password allows anyone to open the document but supposedly prevents printing, copying or editing. This is not security. It is a request that the viewing software chooses to honour, and plenty of software does not. Treat permission restrictions as a politeness marker, never as a control.

A PDF password tool applies an open password, which is the one worth using. If a document genuinely needs protecting, protect it properly rather than relying on a restriction that any competent tool ignores.

The Password Itself

Encryption is only as good as what protects it. A document locked with the recipient's surname is not locked. Use a long, random, unique password generated rather than invented, because human invented passwords cluster in predictable patterns that cracking software exploits first. A password generator produces something genuinely unpredictable in a second, and length matters more than complexity: a long passphrase beats a short string of symbols.

Then, and this is the part people skip: never send the password in the same channel as the file. A password in the same email as the attachment protects against nothing at all, because anyone who obtains the email has both. Send the file by email and the password by text message, or by phone, or through a separate messaging app. The point of the second channel is that compromising one does not yield both.

Sharing a Secret Without Leaving a Trail

Passwords, keys, access codes and credentials sent through email or chat persist. They sit in the sender's outbox, the recipient's inbox, both mail servers, any backup of either, and any device where the app is signed in. That persistence is the actual risk, and it grows over time rather than shrinking.

A self destructing note solves this cleanly. You put the secret on a page, share the link, and once the recipient opens it the content is destroyed, so there is no lasting copy in anyone's message history. A vanishing note tool is well suited to exactly this: sending the password for a protected document, or a temporary access code, without it living forever in a mailbox.

Links Beat Attachments for Anything Sensitive

An attachment is a copy. Once it has been delivered you have no further control: it can be forwarded, saved, backed up and archived without your knowledge, and it cannot be recalled.

A link to a file you host is a pointer. If the service supports it you can restrict access to named recipients, set an expiry date, disable downloading, require a password, and revoke access entirely at any point. You can often see who opened it and when.

For anything confidential, a link with access control is the better mechanism, and the difference is not marginal. The single most useful capability is revocation, because deals fall through, staff leave, and documents that were appropriate to share in March are not appropriate in September.

QR Codes for Physical Handoff

When a link needs to move from a screen to a person standing in front of you, or onto printed material, a QR code is the practical bridge. Conference handouts, printed proofs, packaging inserts and event signage all benefit from pointing at a controlled link rather than a long URL nobody will type. A QR code generator turns any link into one, and because the underlying link keeps its access controls, the code inherits them.

One caution worth stating: a QR code is opaque to the person scanning it. Nobody can see where it leads before opening it. That is exactly why they are used in scams, and it is a good reason to be sceptical of codes you did not generate yourself, particularly stickers placed over existing ones in public places.

Choosing How to Send Something

Different material warrants different handling. Matching the method to the sensitivity avoids both under protecting the important things and over complicating the trivial ones.

Comparing email attachments, cloud links and file transfer services for sending files of different sensitivity

Email Attachments

Convenient, universal, and the least controllable option available. Email is stored on multiple servers, backed up, retained under policies you have no visibility of, and forwarded freely. Size limits sit around twenty to twenty five megabytes for most providers, and corporate filters are stricter.

Appropriate for: low sensitivity files where a copy existing indefinitely is fine.

Not appropriate for: anything confidential, anything you might need to withdraw, anything containing personal data about a third party.

Cloud Links

The default for most professional sharing, and rightly so. Access control, expiry, revocation and download logs are all available depending on the service.

The failure mode is configuration. A link set to anyone with the link can view is effectively public, because links get forwarded and pasted into chats and tickets. If the material is sensitive, restrict it to named accounts rather than relying on the obscurity of a long URL. Search engines have indexed publicly shared cloud links before, and will again.

File Transfer Services

Useful for large files going to someone outside your organisation. Read the retention policy before using one: some delete after a set period, some do not, and some free tiers are funded in ways worth understanding before you upload a client's material.

Messaging Apps

Convenient and often end to end encrypted in transit, which is genuinely valuable. The weak point is the endpoints: the file lands in a chat history on a device that may be shared, unlocked, or backed up to a cloud account with weaker protection than the app itself.

Browser Based Processing

Worth calling out as a category because it changes the calculation. When a tool processes your file locally in the browser rather than uploading it, no copy is created anywhere. There is no server holding your document, no retention policy to read, no breach that could expose it, and no upload wait. For preparing sensitive files, stripping metadata, watermarking, compressing, splitting, this is the safest way to handle them, because the safest file is the one that never travelled in the first place.

Printed and Physical Copies

It is easy to focus entirely on digital channels and forget that the most common uncontrolled copy of a sensitive document is a printed one. A printed page has no access control, no expiry and no audit trail. It sits in an output tray in a shared office, gets carried to a meeting, and ends up in a bag or a recycling bin.

Where a physical copy is genuinely needed, print only the pages required rather than the whole document, collect it immediately rather than leaving it in a shared tray, number the copies if they are being distributed at a meeting, and collect them at the end. Shredding rather than recycling is not theatre for anything containing personal or financial data. And remember that most office printers retain a spooled copy of recent jobs on internal storage, which is a detail that surprises people when devices are resold or returned at the end of a lease.

A Note on Encoding

People occasionally reach for base64 encoding, thinking it obscures content. It does not. Base64 is an encoding, not encryption, designed to carry binary data through text only channels such as email bodies and configuration files. Anyone can decode it instantly with a base64 encoder and decoder. It is a genuinely useful format for embedding a small image in a stylesheet or moving data through a text field, and it provides exactly zero confidentiality. Never treat encoded content as protected content.

Files You Receive, Not Just Files You Send

Almost every guide on this subject treats sharing as a one way activity. In practice you receive far more files than you send, and the incoming direction carries a different set of risks that are worth handling with the same routine.

Attachments From People You Know

The most effective malicious attachments do not come from strangers. They come from a real colleague whose account was compromised, or from an address that differs from a real one by a single character. The message is plausible because it is built from a real conversation, and the file arrives with a name like invoice or contract or the exact document you were waiting for.

Two habits catch most of this. First, check whether the extension matches what you expected: a document that arrives as an executable, a script, or an archive containing one, is worth a phone call before opening. Second, be suspicious of urgency, because urgency is the mechanism that stops people checking. A request to open something immediately, pay something immediately, or bypass a normal process is the single most reliable warning sign there is.

Documents You Are Asked to Fill In and Return

When you complete a form and send it back, you are creating a new file with your data in it, and everything in this guide applies to that file. Before returning it, check what else is in the document beyond the fields you completed. Forms circulated widely sometimes arrive with a previous respondent's information still in them, and sending it onward makes you the person who disclosed it.

The same applies to spreadsheets. A workbook shared for one purpose frequently contains other sheets, and hidden sheets are hidden from view rather than from the file.

Anything You Are Going to Republish

If you receive an image and intend to post it, the metadata inside it belongs to whoever took it, and it may include their location, their device and their name. Publishing someone else's coordinates is worse than publishing your own, because they did not choose it and may not know it happened. Strip incoming images before republishing, exactly as you would your own.

Sharing Inside a Team

Individual habits are the smaller half of this. Most real disclosures happen through shared systems, where access accumulates quietly over years and nobody is responsible for reviewing it.

Permissions Drift

Every shared folder starts with a sensible set of permissions and ends with a wider one. Someone needs access for a project, gets it, and keeps it after the project ends. A folder is opened up temporarily for a contractor and never closed. A link is created for one meeting and pasted into a document that circulates for years. Nobody makes a bad decision; the state simply drifts, and after two years the finance folder is readable by half the organisation.

The fix is a scheduled review rather than better individual judgement. Quarterly, someone opens each shared location and asks who has access and whether they still need it. It is dull, it takes an hour, and it is the single highest value security activity most small organisations can do.

Offboarding

When someone leaves, revoking their account is the obvious step and usually happens. What frequently does not happen is revoking the things attached to them personally: links they created that still work, files shared to a personal address, documents in a personal cloud account, and access granted to their personal device rather than their account. Build a written offboarding list and work through it, because reconstructing it from memory reliably misses something.

The Naming Problem

Filenames travel further than the files themselves. They appear in email subject lines, notification previews, chat messages, backup indexes and search results, in contexts where the file itself is not visible. A file called Redundancy List March.xlsx has disclosed something before anyone opens it.

Use neutral, descriptive names for sensitive material, and adopt a consistent convention so files are still findable. Our guide on consistent file naming conventions covers the mechanics, and the privacy benefit is a genuine side effect of doing it well.

Shared Credentials

Teams share logins for tools that do not support multiple users, and the credential ends up in a document, a chat message, or a shared note that outlives everyone who needed it. Where the tool supports individual accounts, use them. Where it genuinely does not, keep the credential in a dedicated password manager rather than in a document, rotate it when anyone with access leaves, and never let it sit in a message history.

If Something Does Get Out

Mistakes happen to careful people. What separates a small incident from a large one is usually the first hour.

Act on what you can still control. If it was a link, revoke it immediately, before working out how bad the situation is. Revocation is reversible; delay is not. If it was an attachment, recall is unlikely to work but attempt it anyway, and follow with a direct message to the recipient asking them to delete it.

Establish what was actually in the file. Not what you think was in it. Open the copy you still have and check, including metadata, hidden content and anything beneath a redaction. The scope of the problem determines everything that follows, and guessing at it leads to either overreaction or, more commonly, under reaction.

Tell someone quickly. If the material involved other people's personal data, or belonged to an employer or client, there may be a legal obligation with a short clock on it, and those obligations generally start from the moment of discovery rather than the moment of disclosure. Concealing a small disclosure is what turns it into a serious one.

Change what the file exposed. If credentials were in it, rotate them now rather than after the investigation. If it was a document password, that document should be treated as open.

Fix the process, not the person. Nearly every disclosure traces back to a missing step rather than a careless individual: no pre send check, a default that was too permissive, a review that never happened. Adding the step is what stops it recurring. Blaming the sender does not, and it makes the next person slower to report.

The Pre Send Checklist

Everything above condenses into a routine that takes under a minute once it becomes habit.

Pre send privacy checklist for verifying recipients, stripping metadata and choosing the right sharing method

Before Anything Leaves Your Machine

  1. Open the file and look at all of it. Not the part you are thinking about. All of it. Every page, every tab, every image in the set.
  2. Check the properties. Author, organisation, file path, edit history.
  3. Strip photo metadata, every image, not just the ones that seem sensitive.
  4. Resolve tracked changes and comments, including resolved ones.
  5. Check for hidden content: hidden rows, hidden sheets, cropped areas of images that still contain the cropped data, text under redactions.
  6. Confirm redactions are real by trying to select the text beneath them.
  7. Watermark if the material is a proof, a draft or something you do not want reused.
  8. Remove pages that do not need to travel.
  9. Rename the file professionally. Filenames are metadata too, and internal codenames, client names and version labels such as final_v9_actually_final all say something about you.
  10. Choose the method by sensitivity, not by convenience.
  11. Verify the recipient. Autocomplete picking the wrong contact is the most common data disclosure there is, and it happens to careful people constantly.
  12. Send credentials separately if the file is protected.

After Sending

Set a reminder to review shared links periodically. Access granted for a specific purpose should not outlive the purpose. Every few months, review what is still shared and revoke anything finished. Old links from concluded projects accumulate silently and are the most common way material ends up available long after anyone intended.

Sensible Defaults

Rather than deciding case by case every time, adopt defaults and only deviate deliberately:

  • Strip metadata from every photo before sharing, without assessing whether it matters.
  • Never post an original camera file publicly; post a resized export.
  • Watermark anything unpaid or unpublished.
  • Use links rather than attachments for anything work related.
  • Set an expiry on every shared link that has an expiry option.
  • Prefer tools that process locally when handling anything sensitive.
  • Never send a password in the same channel as the file it opens.

Defaults work because they remove judgement from moments when judgement is scarce. The disclosure that causes trouble is almost never the file you thought carefully about. It is the one you sent in a hurry, on a phone, between meetings, without pausing.

Frequently Asked Questions

What is EXIF data and why does it matter?

EXIF is metadata your camera or phone writes into every photo: date and time, device model, exposure settings, and on most phones the exact GPS coordinates of the shot. Those coordinates are precise enough to identify a home, a school or a workplace, and they travel inside the file whenever you send the original.

Does social media remove metadata from photos?

Major platforms generally strip EXIF during upload processing, but do not rely on it. Direct messages, cloud links, email attachments, forums and transfer services frequently pass originals through untouched, and platform behaviour changes without notice. Strip it yourself and the question never arises.

Does a watermark actually stop image theft?

It does not make theft impossible. It makes casual reuse inconvenient and traceable, deters opportunistic copying, and identifies the source wherever the file travels. For proofs, drafts and portfolio work that is usually enough.

Is a password protected PDF secure?

A strong open password on a modern PDF provides real encryption. Permission passwords that only restrict printing or copying are trivially bypassed. Use a long unique password and send it through a different channel from the file.

What is the safest way to send a large confidential file?

A link from a service supporting access control, so you can restrict it to named recipients, set an expiry and revoke it later. Attachments cannot be recalled once delivered.

Should I worry about metadata in documents as well as photos?

Yes, often more. Documents retain author names, organisations, file paths, editing time, previous versions, tracked changes and comments. The hidden content is frequently text someone deliberately deleted, which makes disclosure more embarrassing than a stray coordinate.

Is browser based file processing actually safer?

When processing happens locally, the file is never transmitted, so there is no server copy, no retention policy and no breach exposure. For preparing sensitive files this is meaningfully safer than any upload based service, however well run.

How do I redact a PDF properly?

Drawing a black box over text does not remove it; the text remains selectable underneath. Proper redaction deletes the content and flattens the page. Always verify by trying to select the text beneath the redaction before you send the file.

The Short Version

Files carry more than their contents. Photos carry coordinates, timestamps and device details. Documents carry authors, file paths, edit history and text that was supposedly deleted. None of it is visible, and all of it travels.

The routine that fixes it is short: look at the whole file, strip the metadata, resolve tracked changes, verify that redactions actually removed something, watermark anything you do not want reused, remove pages that should not travel, rename the file sensibly, and match the delivery method to how sensitive the material really is. Send passwords through a different channel than the files they open, and prefer links you can revoke over attachments you cannot.

None of this requires becoming suspicious of everything. It requires closing the gap between what you think you are sending and what you are actually sending, once, deliberately, until it becomes the thing you do without thinking about it.

For related reading, see our guides on creating strong passwords and watermarking and protecting your images.

Advertisement

← Back to all articles
Advertisement