Kinonicle

GEDCOM privacy and import protocol

Move the family tree.
Keep the context.

A GEDCOM is a useful transfer file, but a successful upload does not prove that every source, photograph, relationship or nuance arrived intact. This checklist makes the handover reviewable.

Start here

A transfer file is not automatically a complete archive.

Keep the original export, its associated media and a record of what the receiving application actually supports.

01

Understand what the file is

GEDCOM is an open format for exchanging genealogical information between applications. A conventional file uses the .ged extension and contains structured plain text: a header, genealogical records and a trailer.

Different applications export different GEDCOM versions and subsets. FamilySearch GEDCOM 7 uses UTF-8 and also defines GEDZIP, a ZIP package that can carry a GEDCOM dataset with referenced media. A standalone .ged file should not be assumed to contain the photographs it mentions.

The format helps portability; it does not remove the need to understand what the sending and receiving applications preserve.

02

Before importing

  1. 1

    Export a fresh copy

    Create the file directly from the application that currently holds the working tree. Record the application and export date.

  2. 2

    Keep the source untouched

    Retain one unchanged copy before opening, editing or converting anything. Keep it somewhere other than the steward’s main device.

  3. 3

    Review living-person information

    Assume the file may contain names, dates, notes and relationships for living relatives. Remove information that is unnecessary or not approved for the intended family space.

  4. 4

    Keep media beside the export

    A .ged file may refer to photographs or documents without containing their bytes. Preserve the media folder and original filenames separately.

  5. 5

    Use a private transfer route

    Do not send the file through ordinary email, a public link, a public validator or an AI chat. Use only the service’s intended private upload.

03

What Kinonicle’s current beta importer verifies

Kinonicle checks that the file is non-empty and no larger than 16 MB, contains individual records, stays within the current 20,000-person and 60,000-relationship limits, and has no duplicate person identifiers, self-links or family links to missing people. A missing header or trailer is reported as a warning.

Before changing the private family space, Kinonicle calculates a SHA-256 checksum, records person and relationship counts, and stores the verified original under a private opaque object key. The import replaces the current family record, so a steward review and current export are required before using it on an established space.

Currently mappedCurrent beta scope
PeopleIndividual records, names, male/female/unknown sex values
Life factsBirth year and place, death year
ContextInline person notes, including continued lines
RelationshipsSpouses and parent-child links from family records

Do not assume these are mapped yet

  • Full day-and-month precision beyond the displayed year
  • All event, attribute, source, repository and citation structures
  • Media objects, media files and GEDZIP packages
  • Shared-note records, extension tags and every application-specific field
  • Adoptive, step, guardian or other custom relationship semantics

The original source remains the reference for unsupported information. Kinonicle should not be treated as having preserved a field merely because the overall import succeeded.

04

After importing

Compare the import report with the source counts, then ask the steward to inspect three familiar paths:

  1. A parent-to-child path across at least three generations.
  2. A spouse and sibling group where the ordering is well known.
  3. A relationship-finder path between two known relatives.

Check names and scripts, approximate and exact dates, places, notes, unknown living status and any disputed branch. Do not repair a missing relationship by assumption and do not merge two people solely because their names match.

Use the relationship guide

05

Treat the file like a private family document

A GEDCOM can be opened in a text editor. File obscurity is not encryption. Keep temporary copies to a minimum, avoid public conversion or validation websites, and do not paste family data into a general AI service.

Inside Kinonicle, the family space—not robots.txt—is the privacy boundary. Authentication, family membership and tenant isolation protect the record; search exclusion is an additional public-surface control.

Read Kinonicle’s current security approach

06

Questions and sources

Is a GEDCOM a complete backup of my family archive?

Not necessarily. A GEDCOM can contain people, relationships, events, notes and sources, but photographs and other media may remain as separate files. Keep the original export and its media together.

Can I email a GEDCOM file?

A GEDCOM is readable text and may contain information about living people. Use an intended private transfer route rather than ordinary email or a public file-sharing link.

Does a successful import prove the family history is correct?

No. Validation can confirm structure, counts and links, but a family steward still needs to compare familiar branches, sources and sensitive details.

Primary sources

FamilySearch GEDCOM 7 specification — format, records, UTF-8 and GEDZIP.

FamilySearch GEDCOM tools and guidance — portability and private backup uses.

Kinonicle implementation reviewed: current beta parser, validation rules, private source storage, export path and synthetic migration tests as at 3 August 2026.