GenAgent Trust Hub
Menu

Hostux.social (Mastodon Instance)

BTier BLow risk · 50/100
  • The documents do not say whether your data trains AI.
  • The policy rules out using your data for targeted ads.
  • Data is shared only with the providers who run the service.
  • Staff may review your content; the policy does not describe an opt-out.

A Mastodon server that posts publicly, keeps IPs up to a year, and lets operators read DMs.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy · October 6, 2022 ↗Terms not found6 min read · fairly hard25 lines verified word for word

Collected

What is collected

Account details, posts, profile pictures, browser info, and IP addresses.

Read the exact line

Privacy policy

“If you register on this server, you may be asked to enter a username, an e-mail address and a password.”

Training

How it is used

They use it to run Mastodon, send emails, and help with moderation like spotting ban evasion.

Read the exact line

Privacy policy

“To aid moderation of the community, for example comparing your IP address with other known ones to determine ban evasion or other violations.”

Sharing

Who may see it

Public posts go to the whole network; they say they do not sell data but share with helpers and other servers.

Read the exact line

Privacy policy

“We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information.”

Kept

How long it is kept

Login IPs can be kept up to 12 months; request logs up to 90 days; you can delete your account.

Read the exact line

Privacy policy

“Retain the IP addresses associated with registered users no more than 12 months.”

Controls

Your controls

You can download an archive, delete your account, review logins, and approve followers.

Read the exact line

Privacy policy

“You can request and download an archive of your content, including your posts, media attachments, profile picture, and header image.”

Fine print

The fine print

Age 16 in the EU or 13 in the USA, self-declared; no terms on suing, refunds, or account bans.

Read the exact line

Privacy policy

“Our site, products and services are all directed to people who are at least 16 years old.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Download an archive of your posts and media

    Privacy policy: You can request and download an archive of your content

  2. Irreversibly delete your account

    Privacy policy: You may irreversibly delete your account at any time

  3. Review and revoke logged-in sessions

    Settings: All the logged in sessions are available for your review and revocation

  4. Approve new followers manually

    Settings: toggle an option to approve and reject new followers manually

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · How it is used

People who run this server, and other servers, can read your private and followers-only posts.

Read the exact line

Privacy policy

“Please keep in mind that the operators of the server and any receiving server may view such messages, and that recipients may screenshot, copy or otherwise re-share them.”

For example, a direct message you think is private could be read by the admin.

2 · How it is used

They warn you not to put secrets in posts because they are not truly private.

Read the exact line

Privacy policy

“Do not share any sensitive information over Mastodon.”

For example, do not send a password or medical detail in a DM.

3 · What is collected

Your profile is public to anyone, not just people you follow.

Read the exact line

Privacy policy

“The username, display name, biography, profile picture and header image are always listed publicly.”

For example, a photo you set as your avatar can be seen without logging in.

4 · How it is used

Other Mastodon servers keep copies of your public posts.

Read the exact line

Privacy policy

“Your posts are delivered to your followers, in some cases it means they are delivered to different servers and copies are stored there.”

For example, deleting a post here may not remove every copy on another server.

5 · How long it is kept

They keep the last IP you logged in from for as long as a year.

Read the exact line

Privacy policy

“The latest IP address used is stored for up to 12 months.”

For example, they could still have last year’s home IP after you move.

6 · How it is used

They say they do not sell your personal data, except to trusted helpers and when the law requires it.

Read the exact line

Privacy policy

“We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information.”

For example, they would not list your email for sale to marketers.

7 · How long it is kept

You can wipe your account for good whenever you want.

Read the exact line

Privacy policy

“You may irreversibly delete your account at any time.”

For example, you can delete the account from settings and it should not come back.

8 · How long it is kept

Passwords are stored hashed, and you can turn on two-factor login.

Read the exact line

Privacy policy

“your password is hashed using a strong one-way algorithm. You may enable two-factor authentication to further secure access to your account.”

For example, even if someone steals the database they should not see your real password.

9 · The fine print

They ask people under 16 in the EU not to use the site, but it is just a statement, not a hard ID check.

Read the exact line

Privacy policy

“If you are under the age of 16, per the requirements of the () do not use this site.”

For example, a 15-year-old could still sign up by saying they are older.

Words to know

Legal words from the lines above, in plain English.

human review
Company staff or contractors may read your messages or content, usually to check for rule breaking. For example, a flagged private chat with an AI can be read by a person at the company.
sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
sensitive personal information
Data that could hurt you if exposed, like health, religion, sexuality, race, exact location or bank details. For example, telling a chatbot about a medical condition creates sensitive data that some laws protect more strictly.
GDPR
Europe's privacy law, which requires a legal reason for using your data and gives you strong rights over it. For example, an EU user can demand to know why the app keeps their location history.
How we got here · grade B · score 50/100 · 13 of 15 policy answers backed by a verified quote · 5 not stated
  • What does the app collect beyond what it needs to work?

    They collect account info, posts, profile media, cookies, browser name, and IP addresses, not only what you type.

  • Does it record your voice, face or body, and what happens to that?

    The policy does not say they record voice, face scans, or body data as biometrics. You can upload a public profile picture.

  • Are your chats and uploads used to train AI models, and is that off by default?

    Not stated in the documents.

  • Can employees or contractors read your conversations, and when?

    Server operators and receiving servers may view direct and followers-only messages. No opt-out is described.

  • Are you profiled or tracked for advertising?

    They use cookies to remember preferences. The policy does not describe ads or third-party ad trackers.

  • Do they sell or share your data, and can you opt out?

    They say they do not sell personal information, but share with trusted parties who help run the site, and they federate posts to other servers.

  • What rights do they take over what you type and what the AI makes?

    Not stated in the documents.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    You can delete your account and download an archive. Request logs are kept no more than 90 days; user IPs up to 12 months.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    Not stated in the documents.

  • Do they commit to basic security, and have they leaked data?

    They describe SSL, hashed passwords, and optional two-factor authentication. No independent audit is named.

  • Is there a real age gate, and are teens protected?

    They say the site is for people 16+ in the EU and 13+ in the USA, with no age-check method described.

  • Will they tell you when the rules change, and is the policy specific?

    The policy is dated October 6, 2022. It does not say they will warn you before changing it.

  • Can they close your account without warning, and can you get your data out first?

    Not stated in the documents.

  • If something goes wrong, who pays?

    Not stated in the documents.

  • Do subscriptions renew on their own, and can you get a refund?

    The privacy policy does not describe paid plans, auto-renewal, or refunds.

The privacy policy is 1,196 words at a fairly hard level (Flesch reading ease 54.4).

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton