About
What is real in this demonstration, what is invented, and where it stops short of the site that would be built. Everything here is something you would otherwise have to find out for yourself, which is the reason it is on a page of its own rather than in a covering note.
01
What this is
A working demonstration of a private family archive, built for one client. The family in it is invented. There are 41 people across 7 generations, born between 1845 and 2022, who moved from the tin mines of west Cornwall to the gold country of northern California and then outward from there. Nobody in it is real. The names, the dates, the occupations, the places and all 101 accomplishments were written for this build.
The family was written to be awkward in the ways real families are awkward, because a tidy invented family proves nothing. There is a remarriage in it, a set of half sisters and brothers, one adoption, one divorce, and people whose birth year is only known to within a few years. Those are the cases that break amateur family tree software, so they are the cases worth showing you working.
Everything below is about the parts that are not invented.
02
The photographs
The photographs are real, and they are not photographs of these people. Each one is an archival portrait of a real person, taken by a real photographer, held by a real archive, and used here as a stand in for somebody who never existed. There are 13 of them and every one is credited, with a link to its record, in the catalogue at the end of this section.
No image in this build was generated. Not one face was made by a model, retouched into a resemblance, or aged to fit a date. Every one is a photograph of a person who sat for it.
Two licence positions were accepted when this set was assembled: public domain, and CC0, which is a dedication of a work to the public domain by the person who held the rights to it. Photographs offered under CC BY or CC BY-SA were rejected, even though both permit reuse, because an attribution licence attaches a standing condition to a family’s own archive and somebody has to keep satisfying it long after everyone who agreed to it has moved on. Of the 13 here, 9 are public domain and 4 are CC0.
Now the limitation, which is the part worth reading twice. Freely licensed portrait photography effectively stops around 1946. Almost everything before that date has fallen out of copyright or was made by a government photographer and released; almost nothing after it has. So the photographs in this archive are all of people born before about 1930, and they run out exactly where a real family’s own collection starts getting good. 11 of the 41 people here have a face. 30 do not.
That is a limit of what can be licensed, not a limit of the design. An empty mount is a designed state and not a missing record: it is the size a print would occupy, in a tone one step from the paper, with the person’s name below it at full strength. A relative with no photograph reads as present rather than as an error. On your own archive the pattern reverses: those mounts are where your photographs go, and it is the earliest generations that will stay empty, because that is the end a real family runs short at.
The 13 photographs, in full
01
Full-length carte de visite of a man identified only as Mr. Hawley, holding a top hat, studio of Silas Selleck, San Francisco, California, 1860s.
02
Cabinet card of a wedding party, 1870s or 1880s.
03
Sixth-plate daguerreotype of an unidentified woman, 1840s, in original frame.
04
Wedding party portrait, Swindon, Wiltshire, England, 1920s or 1930s, photographer Fred C. Palmer.
05
Carte de visite of a bearded man identified as Charles Kelly, studio of William Shew, San Francisco, California, 1860s.
06
Full-length carte de visite of a young man identified as William Graham, standing beside a balustrade, studio of William Shew, San Francisco, California, 1860s.
07
Studio portrait of a woman identified only as Mrs Wyly, photographer James Beck, Powerhouse Museum collection.
08
Curtis Stiner, a mountain farmer of East Tennessee, smiling in hat and glasses; part of a 1933 federal survey of families in the Norris Basin ahead of the Tennessee Valley Authority dam project, captioned with his own words that he wanted to stay on his land.
09
Cabinet card of a small child in a straw hat and belted tunic, holding a curtain, studio of Silas Selleck, Post Office Building, Sacramento, California, 19th century. Catalogued by the collection as an unidentified girl.
10
Mrs. Hilbert Bargo, a coal miner's wife, at the stove of the three-room rented house she and her husband shared; 1946 federal survey of coal miners' housing conditions.
11
Construction worker in cap and work shirt, smiling, on the Westmoreland subsistence homestead project, Westmoreland County, Pennsylvania, July 1935; photographed by Walker Evans for the Resettlement Administration.
12
Photograph by Lewis Hine of a teenage glassworks laborer waiting for the night shift outside the factory, Indiana, August 1908, U.S. National Archives.
13
Coal miner in cap lamp holding a pipe, dinner pail slung at his side, P V & K Coal Company, Clover Mine, Lejunior, Harlan County, Kentucky; from the 1946 federal survey of coal miners' housing conditions made when the U.S. government operated the mines.
03
The password
You asked for the site to be password protected, so this demonstration puts a door in front of it rather than describing one. That door is a designed screen, the same as every screen behind it, because a generic dialog in front of a site you are paying a designer for is the first thing that gives the game away.
What the demonstration actually does: it checks the passphrase in your browser. That keeps out a stranger who is handed the address. It does not keep out anyone who opens the developer tools and reads the page source. It is a curtain rather than a vault, and it is better to say so than to let you assume otherwise.
The reason is narrow and technical. This demonstration is exported as a folder of finished files with no server behind it, which is what makes it cheap to host and leaves almost nothing in it that can fail, and a password with no server to check it can only be checked in the browser. The built site does not have that constraint.
Four ways of doing this were compared before choosing. The host’s own password screen, or the browser’s built in one, costs almost nothing and puts an unstyled, platform branded box in front of your family. Accounts for each relative, with an email sign in or a link sent to an inbox, are the strongest and the least kind to a reader in their seventies, who will open the link on the wrong device or find it in a spam folder. The right answer sits between them: the same designed screen you have already seen, with the check moved to the edge of the network, setting a signed cookie. Pages are then never sent to a browser that has not passed, a search engine never sees the content at all, and changing the passphrase signs everybody out at once.
Accounts per relative stay worth having later, if you ever want one person to see the archive and another not to. It is not proportionate to one family site today, and it can be added without changing anything you can see.
04
Living relatives
Of the 41 people here, 16 are living. 13 of those 16 have not agreed to appear in full, so their pages carry their name and their place in the family and nothing else: no dates, no photograph, no occupation, no biography, and none of their accomplishments. 3 have agreed, and they appear like anybody else. The rule is stated on the page itself where it applies, rather than applied quietly, because a family needs to know it exists in order to ask for it to be changed.
Put concretely: that rule withholds 30 of the 101 accomplishments in this archive. The number matters because of how the mistake would look if it were made. A screen that reads a person’s accomplishments straight off the record renders perfectly, looks finished, passes every automated check, and publishes all 30 of them. So no screen in this build reads them straight off the record. Every screen asks one shared function whether it is entitled to what it is about to show, and the figures in these two paragraphs were produced by calling that same function rather than by being typed into the copy.
This is a second, finer layer stacked on top of the site password, not a replacement for it. The password decides who reaches the archive at all. This decides what the archive is willing to say about someone who is still alive to mind.
It is also the settled convention rather than something invented here. Geneanet hides living individuals from a published tree by default, and its own guidance is to get a person’s agreement before showing them at all, since anything on a public profile becomes searchable. GEDmatch shows a placeholder wherever a person is flagged as living. Family Tree Maker lets an owner mark single facts private rather than a whole person. All of them treat site access and living person redaction as two separate controls that stack, which is how they are treated here. On your own archive the setting is per person, and it stays at no until somebody says yes.
05
How it is built
Every page is written out in advance, once, and served as a finished file. There is no database behind it, no program running on a server waiting to be asked, no content system to log in to, and nothing that needs patching on a Tuesday because somebody found a hole in it. The whole site is one folder of files. It can be moved to a different host by copying that folder, and a folder of plain files is about the safest thing there is to leave sitting somewhere for twenty years.
Dates keep their own precision. Nicholas Vingoe has a birth year recorded as about 1845, so the page says about 1845 and nothing more than that. It does not quietly become the first of January, which is what a system that insists on a complete date does to a record that does not have one. 5 of the dates here are recorded as approximate or as a bare year, and they are shown that way. An uncertain fact is still a fact. An invented certainty is not.
One more thing under the surface, because it is the reason the chart draws correctly. A family is not a tree. Two parents converge on a child, people marry more than once, and a line that forks in only one direction cannot say so. So a child here is attached to a marriage rather than to two people, which is what lets a half sister from a second marriage, a step parent and an adoption each draw as the thing they actually are instead of collapsing into one undifferentiated pair of parents.
06
What is not built
A short and honest list. Each of these is something you would otherwise find out after the invoice.
There is no way to add or edit a person from inside the site. The family is authored in one data file and the site is rebuilt when that file changes. Turning that into something you could use yourself needs three pieces that are not here: somewhere to keep the family that can be written to while the site is running, a form behind the same door for adding a person and attaching a photograph, and an upload that resizes a scan and strips the camera information off it before it is published. The data is already shaped for all three, so it can be added later without anything you can see being redrawn. It is the single most likely thing to be wanted once the family starts using this.
There is no map. 24 places are recorded, including the name a place went by at the time, which is the part a family actually remembers. None of them carries a coordinate, so every one of them would have to be looked up and checked before a map could be drawn honestly rather than approximately.
There is no way to take the data out. A family archive nobody can export is a family archive somebody retypes in fifteen years. GEDCOM, the interchange file every other genealogy tool reads and writes, is well documented, and producing one from this data is contained work. It is the thing worth adding straight after the editor.
Everyone with the passphrase sees the same archive. There is one shared passphrase, so there is no way to let one relative in and keep another out, and no way to give somebody a view that hides more than the living person rule already hides. That is the upgrade described at the end of the password, and it is worth doing only if you ever actually want it.
If it helps to see where the rest of this goes, the archive itself is the tree and the index of everyone.
