family tree privacy and security

Family Tree Privacy and Security & Protect Living People

Learn how family tree privacy and security controls protect living people, manage collaborators, support exports and explain deletion and retention.

Family Tree Privacy and Security: Control Who Sees Your Information

Family trees can contain exact dates, private relationships, photographs, addresses, documents and research notes. Those details deserve clear controls. This page explains how family tree privacy and security should work across new trees, invitations, public sharing, exports, account access and deletion.

This overview complements the legal Privacy Policy. It does not replace it. The legal policy should identify the data controller, information collected, purposes, retention, user rights, subprocessors and contact method.

Verification required: Replace every bracketed security, retention and support field with a confirmed statement reviewed by the product and legal teams. Do not claim encryption, certifications or deletion timing unless implemented and documented.

Private by Default

A newly created tree should not appear in public search results or become visible to other users automatically. The owner must deliberately invite someone or change the sharing setting before access is granted.

Private does not mean risk-free. Invited viewers may still copy information or download shared files. Remove unnecessary sensitive details before sharing, even with relatives.

Recommended Access Levels

Access level What the person can do Owner action
Owner Manage people, settings, invitations, exports and deletion Protect the account and maintain independent backups
Editor Add or change people, relationships and sources Invite trusted contributors and review important changes
Viewer Read the parts of the tree shared with them Hide fields and profiles they do not need
Public view Open a deliberately published version Remove sensitive data and prevent indexing of living-person pages

Protect Living People

Profiles for living people should receive stronger defaults than historical profiles. Shared views can hide exact dates, addresses, contact details, private notes and documents. The product should not rely only on age estimates to determine whether a person is living.

  • Do not publish full birth dates of living people.
  • Avoid home addresses, telephone numbers and personal email addresses.
  • Do not upload identification, financial or medical documents.
  • Ask permission before sharing personal photographs.
  • Keep adoption, parentage and family-conflict notes private unless appropriate consent exists.
  • Create a separate shareable tree when the research version contains sensitive details.

Invitations and Collaboration

Invite people individually rather than posting an editable link. Give each collaborator the least access needed, review the invitation list regularly and revoke access when participation ends.

If an invited relative’s email account is compromised, the family-tree account may also be exposed. Encourage collaborators to use unique passwords and multi-factor authentication when available.

Security Controls to Confirm Before Publishing

Control Publish only after verifying Required replacement
Connection security All authenticated and data-transfer pages use HTTPS [CONFIRMED HTTPS/TLS STATEMENT]
Password storage Passwords are hashed using the implemented method [CONFIRMED PASSWORD-STORAGE STATEMENT]
Data at rest The actual database and file-storage protections [CONFIRMED AT-REST PROTECTION]
Backups Frequency, access controls and recovery testing [CONFIRMED BACKUP SUMMARY]
Multi-factor authentication Enrollment and recovery behavior [AVAILABLE / NOT AVAILABLE]
Incident response User-notification process and support route [CONFIRMED INCIDENT CONTACT]

Exports Need Separate Protection

A downloaded GEDCOM, PDF, image or media archive is no longer protected by account permissions. Store exports in a secure location, avoid public links and delete unnecessary copies from shared devices.

Before sending a GEDCOM file, check whether it contains hidden notes or exact living-person dates. Share a limited branch when the recipient does not need the full tree.

Data Retention, Export and Deletion

Users should be able to understand how long account and tree data remains after deletion, whether backups retain copies temporarily and how to request assistance. Insert the verified retention period here: [PRIMARY DATA RETENTION] and [BACKUP RETENTION].

Before deleting an account, download a GEDCOM copy and separate media archive if you may need the research later. Deletion should not be presented as an alternative to providing portable exports.

Children and School Projects

Do not encourage children to publish full names, exact birth dates, schools, locations or family circumstances. School templates should support initials, first names only or fictional sample data. The legal Privacy Policy must address the age requirements that apply to the service.

What You Can Do to Improve Security

  1. Use a unique password: Do not reuse the password from email, banking or other genealogy accounts.
  2. Enable multi-factor authentication: Use it when the verified account settings provide the option.
  3. Review invitations: Remove old collaborators and confirm current permission levels.
  4. Limit sensitive fields: Do not collect private information merely because a field exists.
  5. Back up securely: Store GEDCOM and media copies in an encrypted location with controlled access.
  6. Report unusual activity: Use [VERIFIED SECURITY CONTACT OR SUPPORT FORM] and include the time, account and observed behavior.

Frequently Asked Questions

Is my family tree public by default?

No. New trees should be private until the owner deliberately invites someone or publishes a limited view.

Can search engines index my tree?

Private trees should not be crawlable. Public pages involving living people should remain noindex unless a verified policy and consent process supports another choice.

Who can see information about living relatives?

Only the owner and people granted appropriate access should see protected fields. Verify the exact visibility rules in the live product.

Can an invited relative download information?

They may be able to copy visible information even when downloads are restricted. Share only what they need.

What happens when I revoke access?

The person should lose future account access, but copies already downloaded or recorded cannot be recalled.

Can I export and delete my data?

The product should provide portable exports and an account or tree deletion route. Insert the verified path and retention timing before publication.

Does the website sell family-tree information?

Insert the exact verified policy. Do not make a ‘we never sell data’ promise unless the Privacy Policy, advertising model and vendor arrangements support it.

How do I report a security problem?

Contact [VERIFIED SECURITY EMAIL OR FORM]. Do not post private tree information in a public forum.

Use Privacy as Part of the Research Process

Strong family tree privacy and security begins with collecting only what is useful, protecting living people, limiting collaborators and keeping downloaded copies safe. Review access whenever the tree changes or a new relative joins the project.

REVIEW MY TREE PRIVACY SETTINGS
Scroll to Top