Public family trees are a wonderful way to collaborate on genealogy, but they can unintentionally expose personal information about living people—names, birth dates, locations, relationships, and even photos. If you’ve ever uploaded a GEDCOM file to a public site or forum, you may have revealed more than you intended. This guide walks you through finding where your GEDCOM is published, removing or anonymizing living-person data, and republishing (or removing) your tree safely—without losing the value of your research.
What is a GEDCOM and why can it expose living people?
GEDCOM (GEnealogical Data COMmunications) is a standard file format (.ged) used by most family tree programs and genealogy websites. It stores facts like names, events (with dates and places), relationships, sources, and media links. By default, many desktop tools and sites mark living individuals as “living,” but they don’t always remove details on export or display. If a file is shared publicly—or imported into a site with different privacy defaults—those living details can become visible or discoverable via search engines and third-party aggregators.
Step 1: Make an inventory of where your GEDCOM exists
Before you clean or remove anything, list every place your tree or GEDCOM may be accessible:
- Genealogy platforms: Ancestry, FamilySearch, MyHeritage, Findmypast, Geni, WikiTree.
- Desktop software with online sync: RootsMagic, Family Tree Maker, Legacy Family Tree, Reunion.
- Public sharing sites and forums: RootsWeb, Genealogy.com archives, mailing lists, Google Groups, Dropbox/Google Drive public links, GitHub, personal blogs.
- Cousin or collaborator sites: family domains, shared drives, project pages.
Search your email and files for “GEDCOM,” “.ged,” and your tree name. Also run a web search for your surname plus “GEDCOM” and for living relatives’ names in quotes to spot public listings and cached copies.
Step 2: Lock down live trees before editing
Change privacy settings on each site first, so updates won’t leak mid-process:
- Set trees to Private (not searchable) if the platform allows it.
- Disable hints and matches based on living people where possible.
- Turn off media sharing or make albums private.
- Stop automatic sync from desktop software until you’ve sanitized your local file.
Step 3: Export a master GEDCOM and create a safe working copy
From your primary software or site, export your latest tree as a GEDCOM. Immediately make a duplicate and label it clearly (e.g., “FamilyTree_PUBLIC-REDACTED.ged”). Keep the original private; you’ll use the working copy for public sharing after redaction.
Step 4: Sanitize living-person details in desktop software
Most genealogy tools include features to suppress or remove living data. The goal: preserve deceased relatives’ information while anonymizing or excluding living individuals. Here’s how to do it in common tools and via a neutral “export for sharing” approach.
General redaction strategies
- Mark living status correctly: Ensure anyone without a death date and likely to be alive is marked “Living.”
- Choose an export option to “Exclude living people” or “Privatize living.” This often removes names, dates, places, and notes for living individuals or replaces them with placeholders.
- Replace sensitive fields: If excluding living people breaks relationships, consider replacing living names with “Living,” and strip dates, places, notes, and media for them.
- Exclude recent events: Some tools let you omit events after a cutoff year (e.g., last 100 years) as a broader safeguard.
RootsMagic (typical workflow)
- Tools to review living status: Verify “Living” flags in the People list.
- Go to File > Export.
- Select “Privacy options” and enable “Remove information about living people” and “Strip notes/sources for living.”
- Optionally set a cutoff to exclude events after a recent year.
- Export to a new GEDCOM and check output with a text editor or re-import to a test tree.
Family Tree Maker (typical workflow)
- Review “Living” designations from the People workspace.
- File > Export > GEDCOM.
- Choose “Privatize living individuals” and consider “Private facts” exclusions for notes and media.
- Export, then test on a blank tree to confirm living data is hidden.
Legacy Family Tree / Reunion / Others
- Look for export options labeled “Suppress Living,” “Anonymize Living,” or “Exclude Private Notes.”
- Use “Private” markers on facts you do not want exposed.
- Always test the redacted GEDCOM by re-importing into a separate, empty file.
Step 5: Sanitize living-person details on major genealogy sites
Desktop redaction protects future uploads, but you should also secure or remove existing online trees and GEDCOMs.
Ancestry
- Set tree to Private and also disable “Allow others to find this tree” to keep it unsearchable.
- Ancestry hides details of living people by default in public trees, but names, hints from attached records, and media titles can still suggest identities. Review profiles of living individuals and remove:
- Exact dates and places in facts; keep general regions if needed.
- Photos and documents that display dates, addresses, or school/work badges.
- Notes that mention living relatives’ personal information.
- If you previously exported or shared a GEDCOM from Ancestry, consider deleting the current tree and re-uploading a redacted version from your sanitized desktop file.
FamilySearch
- FamilySearch’s collaborative tree suppresses living details from public view, but verify that living profiles are marked “Living,” not “Deceased.” Correct any mistakes.
- Remove personally identifying details from memories, notes, and sources attached to living profiles.
- If you uploaded a separate GEDCOM to Genealogies (not the collaborative tree), review its privacy status. Remove it if it contains living details and replace with a sanitized upload if you want to share.
MyHeritage
- Set your site’s privacy to Private and hide living people from visitors and search engines.
- Check Smart Matches/Record Matches settings to limit sharing of living-person data with matches.
- Delete any existing online tree that was built from a non-redacted GEDCOM and re-upload a sanitized version.
Geni, WikiTree, and collaborative trees
- These platforms typically privatize living individuals, but settings and community norms differ.
- Audit living profiles for stray data in biographies, notes, or photo captions.
- If a manager or collaborator controls a branch, request removal or redaction of living details on pages you do not control.
Step 6: Remove old public GEDCOMs and cached copies
Even after you sanitize current trees, older files may remain indexed or mirrored elsewhere.
- Delete old GEDCOM uploads on forums, cloud drives with public links, and personal sites. Replace with the redacted version only if necessary.
- For search-engine indexing, remove or restrict the page where the file lives, then request removal through search engines’ content removal tools once the source is gone or blocked.
- For third-party archives or pages you do not control, email the site owner or webmaster. Clearly state the file URL and that it exposes personal information of living individuals; request deletion or deindexing.
Step 7: Verify your sanitized GEDCOM before republishing
Before you share again, test your redacted file:
- Open the GEDCOM in a plain text editor and search for names of living relatives. You should only see placeholders like “Living” or no entries at all.
- Look for lingering tags such as BIRT, BAPM, RESI, OCCU for living individuals. Ensure dates and places are removed.
- Import the file into a blank tree in your software and preview public-facing reports to see what will display.
Safe ways to share family data without exposing living people
- Share deceased-only branches: Export a GEDCOM that includes only ancestors and deceased collateral lines.
- Use placeholders: Keep relationship structure but replace living names with “Living” and strip facts, places, and notes.
- Publish narrative reports for deceased individuals only: Share PDFs or webpages that omit living generations.
- Use private collaboration spaces: Private tree sharing invitations, shared drives with access controls, or encrypted archives sent directly to trusted relatives.
What about photos, documents, and stories?
Media often leaks the very details you intend to hide. Review and, if necessary, remove or edit:
- Scanned records: School records, yearbooks, employment documents, and IDs that reveal dates, locations, or institutions tied to living people.
- Photo captions and filenames: Replace full names with initials or “Living,” and remove location metadata.
- EXIF metadata: Strip embedded GPS and timestamp data from images before uploading.
Coordinating with collaborators and relatives
Privacy protection is a team sport. Reach out to co-researchers and family members who might have copies of your tree or overlapping branches online:
- Share your redaction standards and why they matter (identity theft, harassment, doxxing risks).
- Ask them to remove or sanitize their versions and avoid re-sharing older files.
- Create a brief “sharing policy” document so everyone follows the same privacy rules going forward.
Ongoing monitoring and risk reduction
Even after you lock down your tree, your family’s personal data can surface through record hints, obituaries, school announcements, data broker sites, and breaches. Set a schedule to:
- Quarterly: Search for your surname with terms like “GEDCOM,” “family tree,” and the names of living relatives to catch new exposures.
- Annually: Re-export and re-check your public GEDCOM to ensure living people remain anonymized after new research updates.
- After major life events: Weddings, births, and relocations can quickly appear in online sources—update your tree’s privacy as needed.
If you’re concerned about broader identity exposure—from addresses and phone numbers to financial activity—consider adding credit and identity monitoring as another layer of protection. It won’t remove tree data, but it can alert you to suspicious activity that sometimes follows personal-information leaks. A practical option many readers use is SmartCredit for privacy, credit monitoring, and identity protection.
Frequently asked questions
Do I have to delete living people entirely?
No. Many researchers keep living individuals as placeholders using “Living” for the name and removing all facts, notes, and media. This preserves relationships for research without exposing details.
Can I rely on a platform’s default “hide living” feature?
It helps, but it’s not foolproof. Notes, media captions, and external exports can still reveal information. Always review what a stranger would see and sanitize your GEDCOM before sharing.
How do I handle uncertain death dates?
If you are unsure whether someone is deceased, treat them as living. You can revise later with a confirmed source.
What if someone else posted my family’s living details?
Contact the tree owner politely, explain the privacy issue, and request removal/redaction. If needed, contact the hosting site’s support with URLs and specifics. As a last resort, request search engine removal after the source is taken down or blocked.
A simple checklist you can follow today
- List everywhere your GEDCOM or tree is online.
- Make all trees private and pause syncing.
- Export a fresh GEDCOM and duplicate it as your redacted working copy.
- Use your software’s “Exclude/Privatize Living” options; strip dates, places, notes, and media for living individuals.
- Delete old public GEDCOMs; replace only with the sanitized version if needed.
- Audit media captions, filenames, and EXIF metadata for hidden identifiers.
- Coordinate with collaborators to remove or update their copies.
- Set reminders to re-check search results and re-verify privacy each quarter.
Conclusion
Protecting living relatives’ privacy in public family trees is achievable with a clear process: inventory where your files live, sanitize living-person details at the source, remove outdated public copies, and republish only what’s safe to share. Combined with periodic monitoring and simple collaboration rules, you can keep your family history useful to researchers while minimizing exposure of sensitive personal information. Taking these steps today helps prevent data brokers, scammers, and casual browsers from piecing together details about the living people you care about most.
Good to Know
Even if your tree is “private,” a previously shared GEDCOM or cached copy on another site can still expose living relatives. Always track where you uploaded files and request deletion at each site, not just your primary platform.