How Living People Are Kept Private on a Public Family Tree
What gets hidden, how platforms decide who counts as living, and where the protection still has holes.
Every major genealogy service hides living relatives from public view. Ancestry, FamilySearch, MyHeritage, Findmypast, Geni, and WikiTree all do it, and none of them let an ordinary user switch the protection off for the general public. If you have been worried that publishing a family tree means publishing your children's birthdays, that is not how any of these platforms work. The differences between them are real, but they are differences of degree, not a question of whether the protection exists.
What follows is how the mechanism generally works, what each platform actually hides, and the specific places where living-person privacy still breaks down.
How a platform decides you are still alive
No genealogy service knows whether a person in your tree is alive. It infers it. Nearly all of them use the same shape of rule: if there is no death date recorded, and the person was born recently enough that they could plausibly still be living, treat them as living and hide their details.
The threshold varies. Ancestry documents assuming a person is living unless there is death information or a birth date more than 100 years ago. FamilySearch and Findmypast both use 110 years. Family Roots Center uses 110 years as well, with two additional conditions: a recorded burial place also counts as evidence of death, and a person explicitly marked deceased is treated as deceased.
The important detail in all of these systems is what happens when the data is missing. A person with no birth date at all is treated as living, not deceased. That is deliberate. When a platform knows nothing about someone, the safe assumption is the one that hides more, and every serious implementation defaults that direction.
What each platform hides
This is where they genuinely diverge. All of them suppress identity; they disagree about whether the person's existence, position, and surname remain visible.
- FamilySearch is the strongest approach in the field. Living people are not redacted from the shared tree — they never enter it. They live in a private space only the person who entered them can see, and the record becomes public only when a death date is added. Partitioning is stronger than redaction. One documented gap: photos and stories attached to a living person can still be publicly viewable and must be restricted separately.
- Ancestryhides living people's information from other users while the node itself stays visible in the tree. Trees are public by default. A tree owner can grant specific invitees permission to see living people, and Ancestry states plainly that the owner is responsible for getting those relatives' consent.
- MyHeritage states that names, birth dates, and other details of living people are always hidden, including from paying subscribers — but surnames remain visible. It is one of the few services where an anonymous visitor with no account can browse a family site at all.
- Findmypast does not share information about living people through its tree search. However, when generating a share link, the owner can choose to include people marked as living. That is a user-configurable path to exposing living relatives, which most of the others do not offer.
- Geni automatically forces profiles marked living to private, and that cannot be changed back. Living profiles are excluded from search-engine indexing. Visibility does extend fairly wide within the site — managers, family groups, and users within a fourth-cousin range.
- WikiTreehas the most granular system, with seven privacy levels, and it is enforced as a rule rather than a preference: profiles of living non-members must be Unlisted, and Public and Open are not available options for living people. On partially-private profiles, dates display only as a decade, such as "1970s".
How it works at Family Roots Center
A public tree here is served by a single database function rather than by querying the member records directly. That function decides, per person, whether to return their real record or a redacted stand-in, and it is the only path a public visitor has.
A redacted person comes back as "Living" carrying only what is needed to draw the tree: an internal id, the links to their parents, and gender. Name is replaced. Surname is null. Birth and death dates, places, map coordinates, biography, occupation, education, religion, ethnicity, photographs, and contact details are all absent from the response — not blanked out on screen, but never included in the data at all. Relationships that touch a living person lose their dates and names. Locations and life milestones belonging to living people are dropped rather than emptied.
The reason this is worth stating precisely: the anonymous credential the public site uses has no read access to the underlying member records. There is no unredacted version of the response for a public visitor to request, because there is no query available to that credential that returns one. The redaction is not a filter applied to a result set. It is the only result set that exists for that caller.
There is no setting to turn this off, which is a genuine tradeoff rather than a pure benefit. You cannot use a public link to show your living relatives to your own sister. Sharing living people with family requires inviting them into the tree as an authenticated member.
What is actually different here
Not the 110-year rule, which is the industry convention. Not the existence of redaction, which is table stakes. Two narrower things:
First, a public tree at Family Roots Center is readable with no account at all. Ancestry, FamilySearch, and Findmypast largely sidestep the hardest version of this problem by requiring a login before anyone sees a tree. Serving genuinely anonymous traffic while still withholding living people is a stricter requirement than serving it to a signed-in member base.
Second, the surname is removed too. MyHeritage, the other major service that allows anonymous browsing, keeps last names visible for living people. A surname plus a position in a published tree is often enough to identify someone.
Where living-person privacy still breaks, everywhere
Be skeptical of any platform, including this one, that presents this protection as absolute. The honest limits:
It is a heuristic, not knowledge. A living person whose record has a mistyped death date is classified as deceased and their details are published. A sloppy import that marks people deceased in bulk produces the same result. The inference is adequate for deciding what to render; it is not a guarantee about a specific individual.
Deceased records expose living people.A parent's maiden name, birth date, and birthplace are precisely the security questions used to verify their living children. Publishing a fully documented deceased generation has consequences for the generation after it, and no living-person filter addresses that.
Structure itself is information. Redaction that keeps the node visible still reveals that a particular deceased couple had four children, and roughly when. It is much less than a name and a birthday, and it is not nothing.
Copies escape. On collaborative platforms, once another user has copied material into their own tree, correcting or deleting yours does not retract theirs.
What to actually do
Before you make any tree public, on any platform: check what an anonymous visitor sees by opening the public link in a private browsing window while signed out. That is the only reliable test, and it takes a minute. Confirm that photos and stories attached to living people are covered, because attachments are handled separately from vital records on several services and are a common gap. And ask living relatives before publishing details about them, which every platform's terms make your responsibility rather than theirs.
One further note on how this site handles it: Family Roots Center does not emit schema.org Person markup for anyone in a family tree, living or deceased. Marking a tree viewable by link is not treated as consent to syndicate relatives into search indexes and training corpora, which is a different and much less reversible thing than being visible on a web page.
You can inspect the public-tree behavior on the demo tree without signing up or creating an account. Every Family Roots Center tree is private until you deliberately publish it, and living relatives are redacted before the data leaves the database whether you are on the free plan or a paid one.
Try it free