AI and Privacy: What to Think About Before You Paste
The privacy question in family history is not really about AI. It is about whose material goes into your tool, and what it does to the tool.
The privacy question when it comes to AI in family history is not really about AI itself. It is about whose material you put into a tool built for one person and their own ancestors, and what happens when the answer is everyone's. The best way to explain it starts with a tool every family historian already knows, and it is not ChatGPT.
I knew a man at a genealogical society who paid for his own Ancestry subscription and let the whole society use it.
Anyone who came in to do research logged in under his account. There were a couple of hundred trees in there and none of them related to one another. Everyone who logged in could see everyone else's trees, and everyone could edit them.
His hints were worthless. The system that is supposed to look at your family and suggest records had two hundred unrelated families to work with, so it suggested nothing useful to anybody.
Was he doing anything wrong? He did not think so. He was solving a real problem for his fellow members. Nobody ever told him what it would cost him.
He was not unusual. He is the culture.
Shared logins are everywhere in family history. One person's newspaper archive covers the whole research group. One membership gets passed around a family. People build out other people's families inside their own accounts as a matter of routine, and speculative trees get thrown up to test a theory and left there forever.
None of it comes from carelessness. It comes from generosity, and from a field where the answer to "can you help me with this" has always been yes.
What these tools were actually built for
What does sharing Ancestry logins and tree ratings have to do with ChatGPT, Claude, and Gemini? Quite a lot, actually.
Ancestry was built for one person and their family tree. Maybe two trees. A spouse's line, an adoptive line. It was not built for one login serving two hundred people, and it does not stop you doing it on a personal account. It just quietly gets worse at the job you pay it for.
Claude, ChatGPT and Gemini were built the same way. One person. A set of reasonable purposes. Your work, your gardening hobby, your recipes for the week, your research questions, your way of writing. All of this is in the range of normal use. Everything good about AI tools comes from the assumption that the tool learns how you think and stops needing you to explain yourself.
Neither kind of tool was designed for someone serving dozens of people. Neither will warn you. Both get worse at it slowly enough that you will blame something else.
Why AI feels different when it isn't
You have been handing your ancestors to companies for years. Cloud storage. Transcription software. A subscription tree living on somebody else's server. An email to a cousin with a death certificate attached. Every one of those is a third party holding your material under terms you agreed to and probably did not read.
So why does pasting a census page into Claude feel like a different kind of act?
Because it answers. A search box does not reply, so nobody feels they have told it anything. You typed, it returned results, the transaction ended. A conversation is different. Something responded, and responding feels like receiving a confidence, and confidences feel like they carry obligations.
That is a feeling about the interface, not a fact about the data. If the underlying safety question is what is bothering you, whether AI is safe to use for genealogy research covers that ground directly.

The part you cannot see
Last spring I sat down to record a demo. I wanted a clean start with no history, no assumptions, nothing carried over, so a viewer could watch the process from zero the way they would experience it themselves.
I could not get one. Even after deleting memories, the answers kept arriving already shaped by work I had done before. I gave up and set up an entirely separate account for demos, and that is what I have used ever since.
Here is what that taught me, and it is the durable point in a field where the software changes every few weeks:
You cannot tell at a glance what an AI tool is drawing on when it answers you. Not what it remembers. Not what it inferred. Not what it is carrying from three months ago. The customization that makes the tool valuable is the same thing that makes it opaque, and there is no window into it at the time it is generating an answer. You can read what AI remembers about you and change some of it. You still cannot see the whole picture at the moment it answers.
Notice which fix worked, by the way. Not a fresh conversation. Not a separate project. A separate account.
Whose family is this?
You are the one in your family who knows how to do this. So you help. You look up a friend's grandfather. You sort out a cousin's brick wall. Somebody at church heard you are good at this and asks about their mother's side.
Your cousin asked you to find her grandmother. You fired up ChatGPT to get started on the research. She did not know her mother's address and her sister's birthday were going into a chat window on your laptop. She did not know the 1948 court record you found — the one nobody in that family talks about — went in with them.
She would probably have said yes. That is not the point. The point is that you decided for her, and uploaded documents to AI with her information on them.
That is the whole argument. Not that uploading is wicked. That you made a promise on someone else's behalf when you had no way of knowing what you were promising.
And here is the tell, if you are wondering whether this applies to you: if you are looking for someone to tell you it is fine to use AI to help someone without telling them you are using it, you already know it is not. Nobody goes hunting for permission about a thing they are comfortable with.
The answer is no, because you did not ask
That is it. That is the standard.
Not a form. Not a release. Ask. Not me, not a group of people online, not AI. Ask the person whose information it is.
If your aunt gave you the letters, and you want to transcribe them with AI, ask your aunt. She will almost certainly say yes, and now you have asked. When somebody hands you their family's material and you intend to run it through anything, tell them what you plan to do with it. One sentence. People are far more relaxed about this than the mood suggests, and asking turns something you were quietly wondering about (or possibly doing without them knowing about) into something you settled.
Two habits for working with AI cover the rest.
Strip the data about living people before you paste. Initials instead of names. Approximate years instead of exact birthdates. No addresses, no phone numbers. ChatGPT does not need your sister's date of birth to help you read a 1910 census.
Upload the record, not the tree. A full database export carries dozens to hundreds of living people who never agreed to anything. You need the page in front of you. The same principle applies to organizing genealogy research with AI generally: feed it what you are working on, not everything you own.
There is more on what deserves protecting and what does not in AI privacy for family historians.
And the second cost, which is yours
Every unrelated family you feed into your AI tool spends its attention on somebody else's ancestors. Not catastrophically. Not all at once. The tool that was learning your Quakers is also learning a stranger's Prussians, and the version of it that knows you best is the one you are diluting.
The man with two hundred trees did not wake up one morning with useless hints. It happened one favor at a time.
When helping other people is what you do
Some people reading this are not helping a cousin occasionally. They are working across a lot of families that have nothing to do with each other, almost every day of the week.
If that is you, you have outgrown a product built for one person and a handful of purposes. And it has an ordinary answer: you are operating as a business serving dozens to hundreds and businesses buy business subscriptions.
Nobody finds that arrangement mysterious. It is the right product for the situation, and the society in my story could have had one. They decided not to pay for it. That is a choice they made, and everyone who used that account got the worse version of the tool because of it.
What you are responsible for
You are responsible for what you hand over. That has always been true of every form you filled in, every folder you synced, every attachment you sent.
AI has not changed it. It has made it faster, which makes it easier to do a lot of it without noticing. And it made the tool answer you, which makes a transaction feel like a relationship.
It is a transaction. A very good one, when you are deliberate about what goes into it.
Use the right tool for the job. And keep your tool yours.
Common questions
Is it safe to upload old census records, wills and obituaries?
Generally yes. Public records about people who died a century ago are the lowest-risk material in genealogy, and the same documents are already indexed and searchable on public platforms.
Should I upload my whole family tree file?
Almost never. A full export includes living people who never agreed to anything, and the work in front of you usually needs one family's record rather than the whole database.
What if I am helping someone else with their research?
Tell them what you plan to do with their material and ask first. Then keep it out of the tool you use for your own family where you can, because unrelated material dilutes the customization you are paying for.
Can I see what an AI tool knows about me?
Partly. You can review and delete stored memories in most tools. What you cannot do is see, at the moment it answers, everything it is drawing on. That gap is why asking matters.
How do I know if I need a different kind of subscription?
Look at how many unrelated families are in your tool. If the answer is a lot, and it is that way most weeks, you have outgrown the product you are using.