How GEDCOM Viewer treats your file
8 October 2026
The short version. GEDCOM Viewer is one web page that runs entirely in your browser. Your GEDCOM file is read by your browser, on your computer, and is never sent anywhere. After it loads, the page makes no network requests of its own. It keeps no copy of your file and uses no analytics, no cookies and no code from anyone else.
Your file
- Opening. Open GEDCOM, or dropping a file on the page, has your browser read the file from your disk into the page's memory. Nothing is uploaded. The button says Open because that is all it does.
- Saving. Save writes to your own disk, through the permission Chrome asks you for. The folder you grant is held in the page's memory for that visit and forgotten when the tab closes. Save a copy, in a browser without that permission, downloads the copy as any download.
- Closing. When the tab closes, the file is gone from the page. Nothing of it is kept.
What stays in your browser
Between visits the page remembers only its settings, in your browser's own storage on your computer: the theme, Indent and its width, Bold surnames, the widths of the side frames and whether each is hidden, the Tags list's order, whether the change stamps are ticked, and whether the file's facts show. Never a file's name, its contents or where it is. Clearing this site's data in your browser removes all of it.
No network
The page carries its own content-security policy, which tells your browser to refuse every connection, image, font and script except the page's own files; the browser enforces it, and you can read it in the page's source. The page's five files hold no code that fetches, posts or opens a connection, and the project's tests check that on every change.
What the host sees
The page is served by GitHub Pages. Like every web host, GitHub sees the address and request details of each visitor, and says that it logs visitors' IP addresses; GitHub's privacy statement governs that. That is the whole of what leaves your computer: the request for the page and its files. The file you open is never part of it.
The code is public
Everything the page runs is in the open, at github.com/bunahu/gedcom-viewer. What is served at gedcom-viewer.net is published from that repository, version by tagged version. The page's files can also be downloaded and opened from your own disk, with no web at all.
Reporting a problem
The page sends no error reports. Report a problem, in Settings, writes a report of counts and codes: the file's size, lines, encoding, record counts and check findings by code and line number, the program that exported it, the browser, and the first characters of the file's hash. Never a line of the file, its name or its folder. You read it, change or cut anything, add what happened in your own words, and Copy puts it on your clipboard, to paste into a new issue in the repository. Nothing leaves the page on its own, and the original is kept nowhere. The report's last line is a checksum of the lines above it, so a report changed after it was built reads as changed, which is all it says about editing. Write nothing you would not want public.
Changes
Changes to this page are made in the repository, where each one is dated and visible.