Earlier quoted context omitted.
Worst offender is google photos on iOS - you can’t even open the app without giving it all photos access. Selected photos doesn’t count. Even just to view photos already saved in the cloud.
Discussed recently on ATP[1] - this is a huge security hole. If you give access to all photos, apparently the app can search through the EXIF data to extract locations and timestamps, and build up a very accurate timeline of your whereabouts. 1: https://atp.fm/542
As an app developer I don’t want users to send me location metadata with their photos, but there’s no easy way to communicate this to non-technical users.