Send a relative a link in one tap — and know exactly what it shows, who can open it, and how to take it back. Here is the whole idea, one layer at a time.
Each layer stands on its own. Read the first, stop whenever you have enough, or open the next to go deeper.
Press Share, press Create & copy link, and paste it into WhatsApp. That's the whole job. Your relative opens it, signs in with Google, and can look around the tree — pan, zoom, search, export — but change nothing.
What they don't get is everyone's full name, the living people's birth dates, or a single one of your private notes. Salasilah strips those out before the page ever leaves the server — you don't have to remember to.
Simple mode always makes the first one. Switch to Advanced and the form asks a single question first — "what should this person be able to do?" — then shows only the settings that matter for that answer.
They can pan, zoom, search and export — but not edit. This is what Simple mode creates, every time.
They fill in their branch in their own copy; you watch progress from your dashboard and merge it back when you're ready. Nothing they do touches your tree until you approve it.
A copy that doesn't report back — it becomes theirs. Needs a Google account.
Not a link — a per-person grant that puts your tree on their dashboard, read-only, including living people and private notes. Trusted people only.
The dashboard shares a tree. The tree editor shares a view. That's the only difference between the two Share buttons — open it from inside a tree and the form grows one extra control at the top:
Everyone. The default, so the one-tap path stays one tap.
Exactly the people on your screen right now — the ones you've framed with the generation and display controls.
One person's ancestors and descendants, plus their direct spouses. Good for handing a cousin "your side" without the rest of the family.
Each option shows a headcount, so you can see how many people you're about to send before you send them.
Every shared link is minimised on the server before it's sent. Not hidden with styling — genuinely never transmitted. Here's the same person, as you see them and as your recipient sees them:
| Detail | On a shared link |
|---|---|
| Full name | Reduced to one given name |
| …including the deceased | Also reduced |
| A living person's birth date | Year only |
| A deceased person's dates | Kept in full |
| Private notes, bio, salutation | Never sent |
| Your email address | Never sent |
Why redact the deceased too? Two reasons. A tree where some names are full and others are clipped reads as broken. And more importantly, a patronymic name gives away the father — "Ahmad bin Hassan" tells you Hassan's name, and Hassan may well still be living. Dropping the patronymic closes that back door.
A link on its own is a secret address — hard to guess, but anyone holding it can walk in. Advanced mode lets you add a lock on top:
| Protection | What the recipient needs | Best for |
|---|---|---|
| Passcode only | A 4-digit code you send separately | Older relatives with no Google account |
| Google sign-in | Any Google account | The default — nothing extra to communicate |
| Both | Sign-in and the code | Anything sensitive |
With Google sign-in you can go further and list allowed emails — then only those specific people can open it, even if the link is forwarded around the family group chat.
Links expire in 7 days by default. Set your own number of days, or 0 for a link that never expires. A short expiry is the cheapest safety net there is.
Name a link — "Cousins, read only" — so that in six months you still know what you handed out and to whom.
Every link you've made is listed under Existing links in Advanced mode. Revoke one and it stops working immediately, for everyone holding it.
This layer is opinion, not mechanics — the thinking behind the choices above.
A family tree is other people's data, not just yours
You built the tree, but you don't own the facts in it. Every living person in it has a stake in where their name and birth date end up — and most of them will never see this app, never consent to anything, and never know a link was made. That asymmetry is the reason redaction is automatic rather than a checkbox.
The safe thing must also be the easy thing
A privacy control that costs an extra tap gets skipped, and one that costs five gets resented. So the protection isn't a setting at all — it's the floor. Simple mode has exactly one button precisely so that the fastest way to share is also the most careful one.
Strip it at the server, not in the browser
Hiding a name with styling isn't hiding it — it's still sitting in the page, one right-click away. The only redaction worth trusting is the kind where the data never left the server. That's why a scoped share genuinely doesn't send the other people, and why the Faraid calculation stays on the server too.
Trust should be granted deliberately, not by accident
There is a way to show someone everything — live access — because sometimes your sibling genuinely should see the whole thing. But it's a separate, per-person, amber-marked decision that you make by typing their email, not something you can slide into by leaving a checkbox ticked. Full trust should feel like a deliberate act.
Everything you hand out, you can take back
Links expire on their own, can be revoked on demand, and are listed where you can find them again. Sharing shouldn't feel irreversible — if it did, the careful answer would always be "don't share", and a family tree nobody sees isn't worth building.