metadata privacy email metadata why metadata matters is metadata personal data surveillance encryption

Metadata privacy: what the envelope reveals about you

Adrian Maverick · · 10 min read

Picture a sealed envelope going through the post. Nobody opens it. But the outside still says who sent it, who it is for, the postmark, and the date. Do that once and it means nothing. Do it for every letter you send for a year and someone holding all the envelopes knows your doctor, your lawyer, your bank, and roughly when you sleep. They never read a word.

Metadata privacy is about protecting the information around your communications rather than the content: who you contacted, when, how often, from where, and on what device. It matters because metadata is collected far more widely than content, is often left unencrypted, and in bulk can reveal your health, relationships, and routines.

What is metadata, in plain terms?

Metadata is data about your data. The Electronic Frontier Foundation compares it to an envelope: the letter is the content, and everything written on the outside is metadata.

You create it constantly:

  • Calls and texts: the numbers involved, time, duration, and which cell tower handled them.
  • Email: sender, recipients, date, the servers the message passed through, often the subject line, and sometimes your IP address.
  • Photos: EXIF data such as the date, camera model, and often GPS coordinates.
  • Documents: author name, organization, and edit history.
  • Browsing: which sites you connect to and when, visible to your internet provider even when pages use HTTPS.

Content vs metadata in a single email

The content (the letter) The metadata (the envelope)
The words you typed Your address and every recipient's address
Attachments The exact date and time sent
The subject line, on most services
Every mail server that handled the message
Your mail app and version, on some services
The IP address you sent from, on some services
The size of the message

End-to-end encryption hides the left column from everyone but the recipient. The right column is what mail servers use to deliver the message, so it has to stay readable to them.

Read your own email metadata in 2 minutes

This is the quickest way to make metadata concrete. Pick an email you sent to yourself or one you received from a friend.

  1. Open the full headers. In Gmail, open the message, click the three dots, and choose "Show original." In Outlook on the web, open the three dots, then View, then "View message source." In Apple Mail on a Mac, choose View, then Message, then All Headers.
  2. Find the Received: lines. Read them bottom to top. Each one is a server that handled the message, with a timestamp. That is the route your mail took.
  3. Look for an IP address in the lowest Received: line or in a header like X-Originating-IP. Some services stamp the address of the device you sent from. Others, including Gmail on the web, leave it out. Now you know which kind yours is.
  4. Check Date, Message-ID, and X-Mailer or User-Agent. The Message-ID often names the sending service. The mailer line can reveal the app and version you used.

Everything on that screen traveled with the message and was visible to the servers along the way. None of it was the body.

Why is metadata important for privacy?

Any single piece of metadata is boring. The risk is volume. Collect enough envelopes and patterns appear that content rarely shows so cleanly. The EFF gives examples like these:

  • You called a suicide prevention hotline from a bridge.
  • You got an email from an HIV testing service, then called your doctor, then visited an HIV support group website, all in the same hour.
  • You called a gynecologist, spoke for half an hour, then called an abortion clinic later that day.

Nobody read a message. The pattern told the story.

The Stanford MetaPhone study

In 2016, Stanford computer scientists Jonathan Mayer, Patrick Mutchler, and John Mitchell published a study in the Proceedings of the National Academy of Sciences. Their app collected only call and text metadata from 823 volunteers: more than 250,000 calls and more than 1.2 million texts, with no content at all.

Combining that with public business listings, they inferred sensitive facts. One participant called a chronic-care pharmacy, several neurology practices, and a hotline for a drug used only to treat multiple sclerosis. Another called a gun dealer that specializes in AR rifles; the researchers confirmed that person owned one. Neither fact had been disclosed.

What the people running surveillance say

As David Cole reported in The New York Review of Books in May 2014, former NSA general counsel Stewart Baker said: "Metadata absolutely tells you everything about somebody's life. If you have enough metadata, you don't really need content." At a debate that year, former NSA and CIA director Michael Hayden called that "absolutely correct" and added: "We kill people based on metadata."

How much location metadata adds up to

In Carpenter v. United States (2018), prosecutors had obtained 12,898 location points for one man's phone, covering 127 days, an average of 101 points a day, from his wireless carriers' records. The Supreme Court held that getting those records was a Fourth Amendment search. That was metadata the carriers kept as a normal part of running a network.

Is metadata personal data?

In the EU, often yes. The GDPR lists "online identifiers" such as IP addresses among the things that can make data personal, and the Court of Justice ruled in Breyer (2016) that even a dynamic IP address can be personal data in a website operator's hands. In the US, protection is patchier: Carpenter covers historical cell-site location records, but a lot of other metadata is still collected with far less friction than content.

Why encryption does not hide metadata

People hear "end-to-end encrypted" and assume they are invisible. Encryption scrambles the letter. The network still needs the envelope to deliver it: a mail server must know where to route your email, and a phone network must know which tower you are on.

Some tools work hard to shrink the envelope. Signal, for example, uses a feature called sealed sender to hide who sent a message from its own servers, and says it can produce only an account's registration date and last connection date in response to legal requests. That is the exception, and it is worth knowing about if the relationship itself is the secret. We compared the tradeoffs in Signal vs encrypted email.

How to protect your metadata

You cannot get to zero. Delivery needs some envelope. You can shrink it a lot.

  1. Hide your IP address. Your IP maps to your rough location and ties sessions together. A VPN or Tor breaks that link for the sites and services you use. Secria VPN runs RAM-only servers with no activity logs. (Your internet provider is one of the largest metadata collectors of all; here is what your ISP can see.)
  2. Strip metadata from files before sharing. On Windows, right-click a file, choose Properties, then Details, then "Remove Properties and Personal Information." On iPhone, tap Options on the share sheet and turn off Location before sending a photo. For documents, use your editor's document inspector.
  3. Use messaging built to minimize metadata for conversations where who you talk to is sensitive.
  4. Stop trackers from creating new metadata about you. Tracking pixels in email report when you opened a message, from where, and on what device. Block remote images, or use a provider that strips pixels for you.
  5. Choose providers whose business is not your profile. Every provider handles your envelope. What matters is whether it turns that into an ad profile.

Where Secria fits

Secria Mail is built around point five. Stored mail sits under zero-access encryption, sealed with keys we never hold, and our business model does not rely on advertising or data collection. Tracking pixels are removed automatically, and senders never get your IP address. That removes one of the biggest sources of fresh metadata created about you every day. Encryption is hybrid post-quantum (ML-KEM-1024 with X25519) on every plan, including the free one.

Frequently asked questions

Does a VPN hide my metadata?

Partly. A VPN hides your real IP address and rough location from the sites and services you connect to, and hides which sites you visit from your internet provider. It does not hide who you email or when. Treat it as one layer.

What is the difference between data and metadata?

Data is the content: the words of a message, the pixels of a photo. Metadata describes it: who sent it, when, where, how big, and on what device.

Can metadata identify you?

Yes, especially in combination. An IP address, a set of contacts, and a daily pattern of times and places are often enough to single out one person, as the MetaPhone study showed.

How do I remove metadata from a photo?

On iPhone, tap Options in the share sheet and turn off Location before sending. On Android and desktop, use the photo app's option to remove location or a metadata-removal tool. Many social networks strip EXIF data when you upload, but messaging apps and email usually send the original file.

Stop asking only whether a message is encrypted. Ask who can see the envelope, and what they do with it.

Sources

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.