An illustration of a typical result. No real file, name or location is used.
Before — what you would be sending
project-handover.zipZIP
Environment file.env — API keys and database passwords
Private key or credential filekeys/id_rsa
Exact location51.503364, -0.119543 — in photos/office.jpg
After cleaning
project-handover-clean.zipZIP
Environment fileremoved
Private key or credential fileremoved
Exact locationremoved
Archives are reported, not rewritten. Remove the files you did not mean to include, then zip again.
The file names are the disclosure
Most advice about metadata concerns what is buried inside a document. An archive is different: the list of paths is itself the problem. Sending a project folder to a client or a contractor routinely includes an environment file full of API keys, a .git directory holding every version ever committed, or a database dump nobody remembered was there.
What turns up again and again
Environment files with live credentials. Private keys, which grant whatever access they were issued for to whoever holds them. SQL dumps containing records that were deleted from the running system months ago. Editor backups sitting beside the real file with an older version inside. Log files quietly holding usernames and tokens.
The small ones nobody notices
A .DS_Store lists every file that was in that folder when macOS last looked, including files you removed before zipping. Thumbs.db on Windows holds small copies of images that were in the folder, sometimes ones since deleted. Neither is dangerous on its own, and both tell a recipient more than you meant to.
Photographs inside the archive keep their own metadata
Zipping a folder does not strip anything. Every photograph inside still carries its GPS coordinates, its camera serial number and its owner name. This page opens the archive, reads the files inside it, and reports what it finds in each one.
In practice
Seeing hidden files before you compress
Hidden files are hidden by convention — a leading dot on macOS and Linux, an attribute flag on Windows — and every file browser can show them. On macOS press Command, Shift and full stop in Finder. On Windows, the View tab has a Hidden items checkbox. On Linux, Control and H in most file managers. Turn it on once and look at a folder you have zipped before; the contents are usually a surprise.
Zipping a clean copy instead
The safer routine is not to compress your working folder at all. Create a new folder, copy in only the files the recipient needs, and zip that. It takes a minute, it removes every category of leftover in one step, and it also forces you to look at what you are actually sending, which catches things no tool would flag.
Why the .git directory is the worst case
Removing a password from a file and committing the fix does not remove it from the repository. The earlier version is preserved in the history, retrievable with one command by anyone who has the directory. A .git folder inside a ZIP is therefore not a small untidiness; it can be the complete history of a private project, including every credential that has ever been committed and later corrected.
Common questions
Does zipping a file remove its metadata?
No. A zip is a container. Everything inside keeps exactly the metadata it had, including GPS coordinates in photographs.
Why is a .env file dangerous to share?
It typically holds API keys, database passwords and access tokens in plain text. Anyone who opens the archive has them.
What is a .DS_Store file?
A record macOS keeps of a folder's contents and layout. It lists file names that were in the folder, which can include ones you deleted before sharing.