privacy

Ancestry Apps Know More Than Your Family Tree

Genealogy apps ask for far more than your family history. Here's what happens to the photos, stories, and personal data you upload — and who else can see them.

When people sign up for an ancestry app, privacy is rarely the first thing on their mind. You’re hunting for great-grandparents, building out a family tree, maybe scanning old photos of relatives who passed decades ago. The data implications tend to come later — if they come at all.

They should come first.

What You’re Actually Uploading

Genealogy platforms collect several distinct categories of personal data that most users don’t fully account for at signup:

Family photographs — particularly scanned historical images — are uploaded and stored on the platform’s servers. These often contain identifiable faces, location context embedded in digitized documents, and information about living relatives who appear alongside deceased ancestors.

Family tree data — names, birthdates, marriage dates, addresses, occupations, and cause-of-death records — is structured personal information about dozens or hundreds of individuals, including living people who never created an account and never consented to being included.

Document scans — birth certificates, death certificates, immigration records, wills, census records — contain government-issued personal identifiers. Many of these documents include information about living family members.

Written stories and notes — biographical narratives about family members, including details about medical histories, family disputes, financial circumstances, and personal relationships.

Active genealogy users can spend years building a profile that represents one of the most detailed private records of a family that exists anywhere.

Who Can See Your Tree?

The answer varies significantly by platform and by the privacy settings you’ve configured — and most users never change the defaults.

On Ancestry, family trees are public by default. Other Ancestry members can view your tree, see your uploaded photos, and read notes you’ve written about living and deceased relatives. The platform applies automatic protections — living people are typically hidden from public view — but these protections depend on the platform correctly identifying someone as living based on available data, which is not always reliable.

MyHeritage offers similar public-by-default settings, with the additional feature that it runs facial recognition across uploaded photos to suggest family connections between different users’ trees. Your photographs are analyzed by AI systems and compared against a database of images from other MyHeritage users — without specific notification that this happens at the time of upload.

FamilySearch, operated by the Church of Jesus Christ of Latter-day Saints, maintains a large free platform built around collective contribution to a global family tree. Records you submit to FamilySearch become part of that shared record — photos, documents, and biographical data you add are contributed to a permanent, openly searchable database.

The DNA-Photo Intersection

Some genealogy platforms combine photo storage with DNA testing — Ancestry being the most prominent example. This creates a specific data vulnerability that doesn’t exist on photo-only platforms.

A facial photo uploaded to your public family tree can be cross-referenced with DNA match data to draw inferences about biological relationships. A photo of a relative sitting next to someone identified in your tree as a “half-sibling” could, combined with DNA data, surface information about non-paternity events, adoptions, or donor conception that the individuals pictured have never disclosed.

This is not a theoretical risk. Genealogy research communities have documented cases where the combination of photo evidence, DNA matching, and tree data has surfaced family secrets that multiple generations had kept private.

When you upload a family photo to a genealogy platform, you may be participating in the disclosure of information about living people who have not consented to that disclosure.

Research Partners and Law Enforcement

Ancestry’s privacy policy states that it does not share genetic information with third-party marketers or insurers without explicit consent. But it does describe a research partner program through which anonymized genetic data can be shared with partners for health and ancestry research — and those partners can include for-profit companies.

Law enforcement access is a separate and significant concern. In 2018, investigative genealogy — using consumer DNA databases to identify criminal suspects — became a mainstream investigative technique. Since then, law enforcement agencies have issued subpoenas to genealogy companies seeking access to user data, and several platforms have received such requests.

Ancestry states that it evaluates law enforcement requests on a case-by-case basis, requires valid legal process, and notifies users when permitted by law. The key phrase there is “when permitted by law.” Courts can issue gag orders alongside subpoenas, which means you may never know if your data was accessed.

What Happens When the Company Changes Hands

Genealogy companies have been acquired, merged, and restructured throughout their history. When the company holding your family tree and photo archive changes ownership, the privacy policy in place at the time you signed up is no longer the operative policy.

Ancestry was acquired by Blackstone Group in 2020 for $4.7 billion. MyHeritage has changed ownership multiple times. The data you uploaded — including photos of relatives who trusted you with their images — is subject to the data practices of whoever currently owns the platform.

Protecting Yourself Without Giving Up Research

You don’t have to abandon genealogy platforms entirely to reduce your exposure.

Audit your privacy settings. Most platforms allow you to make trees private, hide living individuals, and restrict who can see photos. These settings are usually buried several menus deep, but they exist.

Upload lower-resolution versions of family photos. High-resolution scans enable more accurate facial recognition. A scan at half resolution still conveys genealogical information while reducing its usefulness for biometric systems.

Keep your most sensitive documents local. Birth certificates, medical records, and documents revealing sensitive family information can be referenced for your own research without being uploaded to a shared platform.

Separate your DNA from your tree. You don’t need to link your DNA test to a public family tree. Keeping them separate limits what inferences can be drawn from the combination.

Store your photo archive independently. A private photo storage service keeps your family photographs accessible without contributing them to a shared genealogy database. daftei stores files with AES-256 encryption at rest, and your content is never used to train third-party AI or sold to data partners.


Your family history is worth preserving. Whether it belongs on a public platform is a different question — one worth asking before you upload the first image.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts