Timestamp Photos vs Verifiable Photos: The Difference
A date stamp on a photo can be redrawn in any editor. See how verifiable photos link each image to a server record anyone can check, and when to use them.
A photo with the date, time and address printed in the corner is not automatically trustworthy evidence: that text can be recreated in any photo editor in a few minutes. A verifiable photo is different, because it is tied to a record on a server that the recipient can check independently. This article explains the difference, when a plain stamp is good enough, and when you need more.
How a plain timestamp photo works
Most timestamp camera apps do something simple: read the phone’s clock, read the GPS position, and draw text onto the pixels. The result is an ordinary JPG with an extra line of text.
That approach has real strengths:
- Easy to use, with many free options.
- Anyone looking at the image can read the details immediately.
- The information survives messaging apps, unlike EXIF metadata, which is often stripped when images are compressed.
But it has three fundamental weaknesses.
Time comes from the phone
If the app uses the system clock, the photographer only needs to open Settings, turn off automatic time and set a different one. A photo taken at 9:40 can carry a stamp saying 7:55. We cover this in trusted time vs phone time.
Location can be faked
Mock-location apps are widespread on Android. If the camera does not check for them, the coordinates on the photo only reflect what the phone was told to believe.
The stamp is just pixels
This is the biggest weakness. Anyone comfortable with an editor can erase the old text and draw new text in the same font and colour. The recipient has nothing to compare against; they can only choose to believe it or not.
What makes a photo verifiable
A verifiable photo also has a visible stamp, but the stamp is just the shop front. Behind it is a record on a server, created when the photo is uploaded, containing:
- A capture time from a trusted time source, independent of the phone clock.
- Location plus integrity flags (mock location, rooted device, clock drift and so on).
- A digital fingerprint of the file, typically a SHA-256 hash. Change a single pixel and the hash changes completely.
- A unique identifier, printed on the photo as text and as a QR code.
The recipient scans the QR or types the code, sees the original record, and compares the file they received with the original fingerprint. If anyone edited the photo, redrew the time or cropped it, the comparison will not match. The technical side is in detect edited photos with SHA-256.
Side-by-side comparison
| Aspect | Plain timestamp photo | Verifiable photo |
|---|---|---|
| Time source | Usually the phone clock | Server-synced time |
| Fake location detection | Usually none | Flags, re-checked by the server |
| Can the recipient check it? | No, they can only read the text | Yes, via code/QR and a verify page |
| Detects edits | No | Yes, through hash comparison |
| Needs a connection | No | To upload (capture can happen offline first) |
| Cost | Often free | Free tiers or team plans |
| Best for | Personal notes, low-risk internal photos | Client evidence, attendance, insurance, handovers |
When a plain stamp is enough
You do not always need verification. A plain timestamp is fine when:
- You are taking photos for yourself: when you planted the garden, how a home renovation is progressing.
- The viewer trusts the photographer and nobody has a conflict of interest.
- The cost of a wrong photo is low, such as an illustration in an internal newsletter.
When you should use verifiable photos
Consider verification when at least one of these applies:
- Money depends on the photo: attendance feeding payroll, milestone sign-offs that trigger payment, insurance claims.
- The recipient does not know the photographer: clients, property owners, partners, authorities.
- A dispute is plausible later: rental condition at move-in, proof of delivery, before-and-after repair photos.
- The team is large and spread out: managers cannot be on site to confirm every image.
Example: a cleaning contractor in Ho Chi Minh City sends end-of-shift photos to a building’s management office. If the office suspects a shift was skipped, it can scan the QR on the photo to see the real capture time and area instead of relying on the contractor’s explanation.
Common misconceptions
- “EXIF data is enough.” EXIF can be edited with free tools and is often removed by messaging apps.
- “A verifiable photo is absolute legal proof.” It is not. Verification makes integrity much easier to demonstrate, but how much weight evidence carries is for a court or authority to decide. See timestamped photos as evidence in Vietnam.
- “Verification means the app tracks me.” A verifiable photo only needs information from the moment of capture, not continuous location tracking.
How SnapID Mark makes photos verifiable
SnapID Mark follows the verifiable-photo model:
- The time on each photo is synced with the server; offline, a monotonic clock keeps it correct, and changing the phone clock has no effect.
- Every photo carries a SNP-XXXX-XX code and QR code. Anyone can check it at
snapidmark.com/v/CODEwithout an account. The verify page shows capture time, a rounded area for privacy, the workspace name and integrity flags. - Recipients can drop the file onto the page to compare its SHA-256 hash, computed in their own browser with no upload.
- The server re-checks every photo for mock location, rooted or jailbroken devices, clock drift, outside-geofence capture, uploads more than 15 minutes late and invalid app builds.
To be clear, SnapID Mark does not provide legally certified timestamps from an accredited authority or digital-signature certificates. Try checking a sample photo in the verify demo and read more about security.
FAQ
Can I turn an old photo into a verifiable one?
No. The verification record has to be created at capture time; adding one later proves nothing about when the photo was taken.
If a messaging app compresses the photo, will the hash still match?
No, because the file has changed. The recipient can still scan the QR to see the original record; for a hash comparison, send the original file as a document.
Does the verify page reveal an exact address?
On SnapID Mark, the public page only shows a rounded area, never exact coordinates.
Are plain timestamp photos useless?
Not at all. They are still handy for personal and low-risk internal use. See how to add date, time and location to photos.
Want every photo you send to be checkable? Download SnapID Mark and take your first verifiable photo.