The person worrying about their IP address usually has a photo on their phone with their street visible through a window behind them. That is the whole problem with how people think about burner identity opsec: the loud risks get the attention and the quiet ones do the damage. Below is what an IP actually reveals, what a VPN actually does, what your photo background now gives away, and the six things worth doing in the order they actually reduce risk. Last checked September 2026.
Your IP address is worth less than you have been told
MaxMind, one of the main geolocation data providers, publishes its own accuracy figures: roughly 63% at city level in the United States and 38% in Finland. A 2026 Virginia Tech measurement study found median real-world error of about 3 to 16 km on fixed broadband, and 179 to 207 km on mobile. Mobile users on IPv4 are usually sitting behind carrier-grade NAT, sharing one address with a large number of other people.
What an IP reliably gives an operator: your country, your ISP, a rough region, whether you are coming from a known VPN range, and a reasonably stable handle for enforcing a ban. What it does not give: your name, your address, or your street. The gap between those two lists is where most of the internet's IP anxiety lives.
What a VPN changes, and what it leaves untouched
A VPN changes your IP and your DNS path. That is the honest description of it. It does not touch your User-Agent, your canvas fingerprint, your screen resolution, your system timezone, your language headers, your cookies or your logged-in sessions. The timezone one is worth sitting with: a system clock set to one country while your exit server is in another is itself a distinguishing signal, not a disguise. WebRTC can leak your local IP if you have not shut it down.
So a VPN is a fine tool for the narrow job it does. It is not anonymity, and "I have a VPN" is not a threat model.
The background of the photo is now the bigger leak
This is the fact that should change what you do. Multimodal models beat non-expert humans at geolocating a photograph, by up to 21 times lower average error. The DoxBench paper (ICLR 2026) found a leading model reaching street-level accuracy, within one mile, in 60% of cases. That is from the picture itself, with no metadata involved.
Most platforms strip EXIF on upload. Nothing strips the background. Reflections in glass, car windows, mirrors and even eyes. Signage. Shadow direction giving up time of day. The layout of a front yard. A view out a window. All of it survives every metadata tool you will ever run, and it is now readable at a scale that was not true a few years ago. Check what is behind you before you check what is in the file.
One related leak almost nobody knows about: some messaging apps preserve original file metadata when a photo is sent as a file or document rather than through the normal photo picker. If you are stripping metadata carefully and then attaching the image as a document, you may be undoing the work. Our page on censoring nudes covers the metadata side properly, including removing it on iPhone and Android without uploading anything.
Handles, emails and phone numbers
A reused username is a one-step identity graph. Free tools check a single handle across hundreds of sites in seconds, and anyone can run one. They cannot tell coincidence from identity, which is exactly the defence: genuinely separate handles read as unrelated strangers, because there is nothing to correlate. One handle, used nowhere else, ever. Not a variation of your usual one.
For email, alias services are the right tool. SimpleLogin, addy.io, Firefox Relay, DuckDuckGo Email Protection and Apple's Hide My Email all give you an address that forwards without exposing your real one, and that you can burn independently.
Public SMS receive sites are the wrong tool for anything you care about. The inboxes are public, so anyone with the link reads your verification codes. The numbers are shared and recycled, which correlates with a much higher rate of account takeover. And because they are reused constantly, services flag them, so codes arrive late or never. The better move is not finding a cleverer disposable number, it is choosing services that never ask for one.
Ranked by how much risk each one actually removes
The ordering is the point here. Most guides list these as an undifferentiated pile.
1. Keep your face and identifying marks out of the frame. Face search is the single technique that links a photo to a different photo of you, which is the mechanism that turns one image into an identity. Nothing else on this list closes a gap that big. If you want to see how that works from the other side, we walk through it in reverse image searching yourself.
2. A unique handle, used nowhere else, ever. Cheap, permanent, and it defeats the most commonly run attack there is.
3. Control the background. This now outranks metadata, for the reasons above.
4. A separate email alias, and never reuse a photo that exists on another account. A profile picture that appears on one other account collapses the separation instantly.
5. Strip metadata, and do not send photos as documents. Worth doing. Not the first thing to do.
6. A VPN. Well down the list, and useful mainly for the narrow job it genuinely does.
Overrated, misunderstood, or simply wrong
Incognito mode hides your history from your own device. It does not hide your IP, does not encrypt anything, does not stop fingerprinting, and does not stop server-side analytics. "A VPN makes you anonymous" is the most repeated wrong sentence in this space. EXIF panic in isolation, with no thought given to what is visible in the picture, solves a shrinking part of the problem. "Encrypted app equals safe" confuses the pipe with the threat: encryption protects the message in transit, and the person reading it at the other end is who you actually needed to worry about, which is what sexting safety is about. "Burner account equals anonymous" is only true if the handle, the photo, the email and the writing habits are all new too.
What we hold, plainly
We can say this because we are not selling you a VPN subscription. Our chat service stores a nickname, an IP address, and an email only if you choose to register one. We do not ask for or store a phone number, a real name, an address or a date of birth. The privacy policy spells it out and does not hedge.
What is an IP worth to us? Ban enforcement. That is the honest answer. It is a stable-ish handle that makes it harder for someone who was removed to walk straight back in. It is not identification, and given the accuracy numbers at the top of this page, it could not be. Everything else follows from that: anonymous chat with no account, anonymous sexting with a nickname that connects to nothing, and anonymous nudes if that is where things go, with the one rule that never bends. Share what's yours to share. Posting a partner's, an ex's, or anyone else's photos without their consent is ban-worthy, every time.