Living Persons and Third-Party Information
Why this policy exists. Genealogy software is unusual: most of the information it holds is about people who are not its users. Your tree contains relatives, in-laws, DNA matches and research subjects, many of them living, none of whom signed up or were asked. Most products in this category say nothing about that. This policy sets out what we expect of you, what a person described in a tree can ask of us, and what we will and will not do.
1. The Basic Principle
You control what goes into your tree. We do not review it, verify it, or decide what belongs there. That is deliberate: your research is private and we do not want to be reading it.
The consequence is that responsibility for the information sits with you. If you record something about a living person that you should not have recorded, or publish something that should have stayed private, that is your decision and its consequences are yours. Section 19 of the Terms of Service makes that allocation explicit.
What we contribute is tooling: settings that exclude living people from anything you publish, on by default, and a way for someone who has been named to reach us.
2. If You Are a User
When you record information about someone else, you are telling us that you may lawfully do so. Concretely, we ask you to:
- Record what you need, not everything you can. A living cousin's name and approximate year of birth serves most research purposes. Their street address, telephone number, employer, and medical history usually do not.
- Be accurate, and mark uncertainty as uncertainty. Genealogy runs on inference. Write "probably" when it is probable. An unqualified assertion about a living person's parentage, paternity, or conduct can be defamatory when it turns out to be wrong.
- Respect an explicit objection. If a relative has told you they do not want to be in your tree, honour that. It costs you a node.
- Take particular care with anything a person might not have chosen to disclose — adoption, illegitimacy, a change of name or gender, an estrangement, a criminal matter, an addiction, a cause of death. These are the entries that cause real harm when they surface unexpectedly.
- Keep your credentials safe. Most exposure of family data comes from an account being accessed, not from a platform breach.
3. Before You Publish Anything
Adding information to your private tree and publishing it are different acts with different consequences. Publishing includes generating a share link, exporting a GEDCOM file and sending it to someone, and uploading a file to another service.
Our defaults protect living people. New share links exclude them, and GEDCOM exports mask them, unless you switch that off. If you switch it off, you are making a decision about other people's privacy, and you should be able to justify it.
Please understand the limits of those defaults. Whether someone counts as living is inferred from what you entered. If a birth date is missing or approximate, we err toward treating the person as living and protecting them — but we can only work from what is in the record. Review a share link before you send it. Open it yourself, in a signed-out browser, and look at who appears.
Share links are quiet but not secret. The address is unguessable, so it will not be stumbled upon. But anyone you send it to can forward it, and if you post it somewhere public it can be found and indexed. Revoke a link when it has served its purpose.
Photographs need a separate thought. Once an image has appeared in a published tree, its direct address may continue to work even after you revoke the link. If it matters that a particular photograph stops being reachable, delete the photograph itself.
4. Particularly Sensitive Information
DNA matches. A match is another person, usually living, who tested for their own reasons. Their name, the amount of DNA you share, and the relationship it implies is information about them, and it can reveal things they did not intend to reveal — a misattributed parentage, an unknown sibling, a closed adoption. Treat match data as confidential. Do not publish it, and think carefully before telling a third party what it implies. In several US states this category is separately regulated.
Race and ethnicity. Historical records frequently record race, and our document transcription feature will carry that across when it appears in the document, which means it can be recorded without you having typed it. Review what transcription produces before saving it, and clear that field if you do not want it held.
Religion. Baptism, christening, confirmation and burial records imported from a GEDCOM file indicate religious affiliation, which is sensitive in many jurisdictions and in many families.
Health. There is no health field in AncestorOS. Please do not put diagnoses, conditions, or causes of death for living people into notes. This is not a medical records system and it has none of the protections one would need.
5. Deceased People
Data protection law generally does not apply to the dead, and recording a deceased ancestor's details is the ordinary business of genealogy. Two cautions remain.
First, information about the dead is frequently also information about the living. A cause of death, a paternity finding, or a criminal record identifies a deceased person and implies something about their surviving children.
Second, a recently deceased person has a surviving family. Publishing details of a death that occurred a few months ago is different from publishing a death from 1890, whatever the law says.
6. Children
Living children appear in most family trees. They cannot consent, and they will one day be adults who may feel differently about what was recorded.
If you record a child who is not your own, consider whether their parent would agree. Keep the record minimal — a name and a birth year is usually enough. Do not publish a child's details in a share link or an export. A parent or guardian may contact us under Section 7.
7. If You Are Named in Someone's Tree
If you have discovered that information about you is held in an AncestorOS account, you can contact us at privacy@ancestoros.com. You do not need an account and there is no charge.
Bring us as much of the following as you have: your name and any variants; the share link or page where you saw the information, if there was one; what specifically concerns you; and whether you know who holds the tree. A screenshot helps.
We will acknowledge within 5 business days and aim to resolve within 30 days. If a matter is complex we will tell you what is taking time rather than going quiet.
8. What We Will and Will Not Do
We would rather set expectations honestly than promise something we cannot deliver.
We will:
- Disable a published share link, which stops the public page working immediately.
- Remove specific content where it is unlawful, where it presents a risk of harm, or where we are legally required to.
- Pass your request to the account holder, who is contractually obliged to consider it in good faith and to cooperate.
- Tell you what we did.
- Act promptly, without waiting for the account holder, where there is a credible risk to someone's safety — including where a tree is being used to locate a person who does not want to be found.
- Suspend or terminate an account being used to harass, stalk, or endanger someone.
We generally will not:
- Delete or alter the private research files of an account holder because a third party asked us to. We are not able to adjudicate competing claims within a family about who is entitled to record what, and doing so would require us to read private records in order to decide.
- Tell you who holds a tree, or give you their contact details, without their consent or a lawful order. That person also has privacy rights.
- Confirm or deny whether a particular individual appears in any particular account, where doing so would itself disclose someone's private information.
- Undo a copy someone else already made. If a tree was exported or downloaded before we acted, that copy is beyond our reach.
If you believe the law requires more of us than this, write to legal@ancestoros.com setting out the basis, and we will consider it properly.
9. How to Make a Request
Step 1. Email privacy@ancestoros.com with the details in Section 7.
Step 2. We may ask for enough information to confirm you are who you say you are, and that the record is about you. We ask for the minimum needed and we do not keep verification material longer than the request.
Step 3. We assess it. Where it concerns a published link or a safety risk we act first and discuss afterwards. Where it concerns private research we contact the account holder.
Step 4. We tell you the outcome and, where we have declined, why.
If you are the account holder and we forward you a request: you agreed under Section 8.3 of the Terms of Service to cooperate promptly and in good faith. In practice this usually means removing a detail, marking a person private, or revoking a link. Please respond within 14 days. If you do not, we may act on the request ourselves.
10. Family Disputes
Some requests are not really privacy requests. They are family disagreements — about an adoption, a paternity, an estrangement, a will — that arrive at our door because we happen to host the file.
We are not able to resolve those, and it would not be appropriate for us to try. We are a software company with no way to establish who is right about a family's history. Where a request turns on a contested factual claim rather than a legal one, we will normally decline to intervene beyond disabling anything published, and we will say so plainly rather than leaving you waiting.
A court order directed to us is a different matter and we will comply with one.
11. Contact
Commoner Apps LLC
506 Soapberry Ave.
Princeton, Texas 75407
United States
Requests about information held about you: privacy@ancestoros.com
Legal notices: legal@ancestoros.com
Safety concerns: privacy@ancestoros.com, with "URGENT" in the subject line
See also the Privacy Policy and the Terms of Service.