Your great-great-grandmother cannot object to being in your family tree. Your cousin can.
That distinction does most of the work here, and it's the one people skip. Genealogy is treated as an activity involving the dead, and structurally it mostly is — but every tree has a living edge, and that edge is a document about real people who never agreed to be documented.
Nobody needs to be alarmed about this. It just needs deciding once, deliberately, rather than by default.
What the platforms actually do
All the major services have living-person protections, and they work broadly the same way: people marked as living are hidden from other users, and only you see them.
Two things about that are worth knowing.
The protection depends on the data being right. "Living" is usually inferred — no death date recorded, or a birth date recent enough that the person is presumably alive. An ancestor born in 1890 with no death date may be treated as living. A living person with a mistakenly entered death date stops being protected. The system is only as good as the field it's reading.
Privacy of the tree and privacy of the people are different settings. Some platforms let you make a tree public, private, or searchable-but-not-viewable, and those controls are separate from living-person suppression. People routinely set one and assume they've set both.
Worth doing once, today: open your tree's privacy settings and actually read them rather than assuming the defaults match what you'd have chosen.
The specific risk people underrate
Drag-and-drop GEDCOM viewers — the sites where you upload a file and see your tree instantly, no account needed.
They're convenient and there's nothing inherently wrong with them. But consider what's in the file you're uploading: full names, birth dates, birthplaces, mothers' maiden names, and current relationships, for people who are alive.
That combination is almost exactly the set of answers to the security questions banks have used for decades. It's also the raw material for the kind of social-engineering call that begins "hi, I'm calling about your mother's account."
For a file containing only long-dead ancestors, upload away. For a file with your living family in it, going to a service you haven't evaluated, the two seconds of convenience is not a good trade. Strip living people from the export first — most programs offer that as an export option — or don't upload it. More on GEDCOM viewing options generally.
The same logic applies to posting a screenshot of your tree in a Facebook group, which people do constantly without looking at what's in the bottom two rows.
What counts as sensitive here
Not everything about a living person is a problem. The things that are:
Full birth date. Year alone is fairly harmless. Day, month, and year together with a full name is an identity-verification key.
Mother's maiden name. Which is, unavoidably, the entire subject matter of a family tree. There is no way to build a tree without recording it — which is a good argument for being careful about who can see the living portion.
Current location. Genealogy records places of birth and residence, and for living people a current town is different in kind from a historical one.
Relationships people haven't made public. An adoption, a half-sibling, a first marriage nobody mentions, a biological parent discovered through DNA testing. Your tree may be the first place one of those is written down, and writing it down is not the same as it being yours to publish. More on that situation.
That last category is the one that causes actual family damage, and it has nothing to do with identity theft.
The etiquette question
Suppose a cousin doesn't want to be in your tree.
The practical answer is straightforward: take them out, or reduce them to a name with no details. Nothing in your research depends on their birth date, and the relationship costs more than the record is worth. You can keep whatever you need in your private files without publishing it.
The harder version is when someone objects to a fact rather than their own presence — a family circumstance they'd rather not see written down. There's no universal answer to that, but two principles hold up:
Documenting something privately and publishing it are different acts. You can record what the evidence says and still choose not to display it while the people involved are alive.
The living get a vote about themselves and don't get one about the dead. A relative can reasonably ask you to keep their own details private. They cannot reasonably require you to stop researching a shared great-grandparent because of what you might find.
A reasonable position
The deceased are the public record. Births, marriages, deaths, censuses, and land transactions have been public documents for a very long time. Researching them is not an invasion of anything.
The living are not. Default to the minimum: a name and a relationship is usually enough to hold the tree's structure together. Dates and places for living people belong in your private research, not in anything shared.
Strip living people before any file leaves your control. Exports, uploads, shared screenshots.
Ask before you publish someone. One message is cheap and it prevents nearly every version of this going badly.
Data-protection regimes in various countries impose actual obligations on how personal information about living people is handled, and they vary enough that nothing general is worth saying about them here. If you're publishing a family tree publicly at any scale, it's worth finding out what applies where you are.
Where a tree can be genuinely private
One structural point, and then the obvious disclosure.
A great deal of the privacy problem in genealogy comes from where trees live. A tree on a public platform is discoverable by design — that's frequently the feature you're paying for, since discoverability is how distant cousins find each other. A tree posted to a viewer site is on somebody's server under terms you clicked past.
A display that isn't a publishing surface doesn't have that shape. With Bright Branches, your tree sits in your own account, is transmitted over HTTPS, and is visible on your own television to the people in your own living room. It isn't indexed, isn't searchable by other users, and isn't a place where a stranger encounters your family. That's a narrower thing than a research platform, and narrower is the point.
It doesn't solve the underlying question — you still have to decide what belongs in the file at all. But it's worth knowing that "on a screen where my family can see it" and "on the internet" are not the same place, and a lot of people treat them as though they are.
Keep reading:
