Privacy Policy
By Where Is This Place
The short version
Three of our four tools never send your photo anywhere — they run inside your browser. The fourth, the photo location finder, checks metadata locally first and, only if no GPS exists, sends a single resized, metadata-free copy of the image to a visual geolocation provider. We do not store your images, we do not keep results, and we do not sell data, because we barely collect any.
The rest of this page explains exactly what is processed where, which third parties are involved, and what choices you have. It reflects what the code actually does.
What stays on your device
The Photo Metadata Viewer, the Photo Date Finder and the Remove Photo Metadata tool parse your file entirely within the browser tab using client-side JavaScript. No image, no filename, no EXIF field and no coordinates are transmitted to us or to any third party at any point. You can verify this claim yourself in your browser's developer tools: the network tab stays silent while the tools run.
Downloads created by the metadata remover (the clean copy) are generated in memory and saved directly by your browser. They are never routed through a server.
What the location finder sends, and when
When you upload a photo to the location finder, the EXIF and GPS check happens locally. If valid GPS coordinates exist, the result is displayed and nothing is sent anywhere.
If no usable GPS exists, the browser produces a sanitized analysis copy: orientation-corrected, long edge resized to at most 2048 pixels, re-encoded as JPEG from the canvas (which carries no metadata by construction). Only that copy is sent, via our server which acts as a proxy, to the configured visual geolocation provider (GeoSeer by default; the provider is named in our About page). The optional text clue you type is forwarded alongside it.
The server proxy does not write the image to disk and does not log its content; the buffer is discarded when the provider responds. The provider processes the image under its own privacy terms — we chose providers that do not retain submitted images for training, but their policies govern their systems, and you should read them if this matters to you.
Server logs and analytics
Like nearly every website, our hosting provider records standard request logs (IP address, timestamp, URL, user agent) for security and abuse prevention. These logs contain no image data, no EXIF fields and no GPS coordinates, and we never log your clue text or its contents.
If analytics are enabled, they record aggregate events only — for example, that an analysis started or finished — never coordinates, filenames or metadata values. We do not run advertising trackers on tool pages.
Cookies
The tools work without accounts and without tracking cookies. Functional storage we may use: your language and theme preference, and an anti-abuse token (Cloudflare Turnstile) on the AI analysis. Turnstile runs without storing personal data and without showing captchas to most users.
We do not set advertising or cross-site tracking cookies, and there is nothing to opt out of because there is nothing tracking you across sites.
Third-party services
Visual geolocation: GeoSeer (or, if configured, Picarta) — receives only the sanitized analysis copy described above. Map tiles and reverse geocoding: Geoapify and OpenStreetMap-based styles — these are loaded only after a result exists and you choose to view a map; loading tiles reveals your IP to those tile servers, as any map on any website does. Abuse prevention: Cloudflare Turnstile.
Each provider processes data under its own privacy policy, linked from their sites. We name them here because a privacy policy that hides its processors is not a privacy policy.
Your rights and choices
Because the local tools transmit nothing, there is nothing for us to delete from them. For the AI path, no image or result is retained after the response, so there is no deletion backlog either — but you may always email support@whereisthisplace.world to ask what was logged about a request, to request log-based data removal where law applies (including GDPR and CCPA frameworks), or to object to processing.
You control the biggest switch yourself: if you do not want any image transmitted, use only the three local tools, or stop before pressing 'Find This Place' when the finder reports that no GPS exists — that is the exact moment transmission would occur.
Changes to this policy
If the geolocation provider or the data flow ever changes, this page changes with it before the new flow ships. The page always states the plain-language truth of what runs where; dated revisions appear in the page footer metadata.
Data we never collect
For clarity, this is the list of things no tool on this site collects: your photos (except the single sanitized analysis copy described above, which is not stored), your GPS coordinates, EXIF field contents, file names, capture dates, your contacts, your location history, or advertising identifiers tied to tool usage. If a claim on this list ever needs to change, the change will appear here before it ships.
Children
The site is not directed at children under 13 (or 16 in the EEA) and collects no age information. If you believe a child has contacted us, we will delete any such correspondence.
International transfers and law
Our hosting and third-party providers may process data in several countries; transfers rely on the providers' standard contractual mechanisms. Where mandatory privacy law in your jurisdiction grants access, correction, deletion or objection rights over personal data we hold (essentially request logs), email support@whereisthisplace.world and we will act within the statutory windows.