Ancello Back to articles
How to Protect Privacy When Sharing a Family Tree Online
8 July 2026 Ancello

How to Protect Privacy When Sharing a Family Tree Online

Share useful family history without exposing living people, private documents, sensitive stories, DNA information, or hidden file metadata.

The safest way to share a family tree is to publish the smallest useful set of information, keep living people private by default, remove sensitive media and metadata, and review the exported result as a stranger would see it. Platform privacy controls help, but the researcher remains responsible for what is uploaded, linked, or described.

Separate research from publication

Your private workspace can contain evidence, hypotheses, contact details, correspondence, DNA notes, and restricted recordings. A public or extended-family tree should be a deliberate export, not an unrestricted window into that workspace.

Create sharing tiers such as private research team, invited family, and public deceased-person tree. Decide which fields and assets belong in each.

Protect living people by default

Do not publish a living person’s full birth date, exact birthplace, address, phone, email, private photographs, identity documents, education, employer, medical information, or relationship details without informed permission.

Even a name marked “Living” can be identifiable through parents, spouse, children, photographs, and narrative text. Review the whole context, not only the person card.

FamilySearch states that living-person records are kept in a user’s private space and are not visible to other users, but behaviour differs among services. Read current settings and test them with a separate viewer where possible.

Ask consent for stories and media

Explain where the material will appear, who can access it, whether it can be downloaded, and how long it will remain. Give people a real choice and a way to withdraw future sharing.

Extra care is needed for adoption, parentage, fertility, health, criminal allegations, abuse, financial hardship, immigration status, sexual orientation, religion, and family conflict. The fact that information is known within a family does not make global publication appropriate.

Understand rights and ownership

Owning a print does not necessarily give you copyright. A relative who sends a photograph may not own the photographer’s rights. Archive downloads can have reuse conditions. Private letters involve both the physical owner and the writer’s content.

Record creator, owner, source, rights status, permission, and restrictions with each asset. When uncertain, link to the archive catalogue or share a description instead of republishing the image.

Clean files before uploading

Images, documents, and audio can expose more than the visible content:

  • EXIF location and device data;
  • filenames containing names or addresses;
  • hidden PDF text or previous revisions;
  • document author and organisation metadata;
  • faces or certificates in the background;
  • spoken names elsewhere in a recording.

Make a separate sharing copy, remove unnecessary metadata, crop unrelated private material, and listen or read through the complete file.

Review tree exports

GEDCOM and report exports may include notes, sources, addresses, living people, private flags, and media paths. Export to a new test file, open it in a clean account or separate app, and inspect:

  • living people and their relatives;
  • notes and source text;
  • events after a privacy cutoff;
  • attached media;
  • DNA and medical fields;
  • submitter contact details;
  • private facts that lost their flag.

Do not assume privacy markings transfer consistently between apps.

Use access controls deliberately

Prefer named invitations over public links for family-only material. Give edit access only to people who need it. Use unique passwords and multi-factor authentication, review collaborators periodically, and remove access when a project ends.

Remember that a viewer can take screenshots or download files. Access control reduces exposure; it cannot guarantee confidentiality after sharing.

Avoid exposing home and cemetery risk

Do not map a living person’s exact home. Be cautious with photographs of valuable objects, keys, documents, or location metadata. Cemetery information about deceased relatives is generally less sensitive, but recent memorials can reveal living family names and current locations.

Write a family sharing policy

A short policy can state:

  • living people remain private unless they opt in;
  • sensitive facts require explicit approval;
  • every media item needs source and permission notes;
  • public exports exclude private notes and raw DNA data;
  • corrections and takedown requests have a named contact;
  • collaborators do not re-share outside the agreed group.

Review it when new people join or the publication format changes.

Respond to a privacy problem

If private information is exposed, remove public access first. Identify copies and links, notify affected people, request removal from collaborators or platforms, rotate compromised credentials, and document what happened. Search-engine removal requests may be needed after the source page is corrected.

Do not preserve a public page merely because it took time to create. Privacy comes before presentation.

A pre-publication check

View the tree while signed out. Search for living surnames, dates in the last 100 years, addresses, emails, phone numbers, private keywords, and attached documents. Inspect page source or downloads if the service offers them. Ask a relative unfamiliar with the project to look for unintended clues.

A useful shared tree need not contain everything you know. Good privacy is selective: enough evidence and story to serve the audience, with sensitive detail kept in the protected research archive.

Sources and current platform guidance