Move trust to the edge

Family histories hold exactly the kind of information a curious or compromised server should never be able to read. Encrypting it before it leaves the device makes that a property of the system.

The server can store and synchronise ciphertext without becoming another reader. That is a more useful promise than asking everyone to trust that an administrator will always make the right choice.

Constraints shape the interface

Once the service cannot inspect the records, convenient shortcuts disappear. Search, recovery, sharing, and key handling all need deliberate answers. The interface has to explain those consequences without turning cryptography into homework.

That constraint helps. Privacy decisions have to be made during design, long before anyone builds a settings screen.

Demo with a fictional family

For a public demo, a fictional tree is enough. It shows the relationships, the interaction and the visual style without using anybody’s real history.