masto.ai
- The documents do not say whether your data trains AI.
- The policy rules out using your data for targeted ads.
- Data is shared only with the providers who run the service.
- Staff may review your content; the policy does not describe an opt-out.
A Mastodon server: public posts and profile are public; operators can read DMs; IPs kept up to a year.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account details, posts, follows, profile pictures, IP address, and browser info.
Read the exact line
Privacy policy
“If you register on this server, you may be asked to enter a username, an e-mail address and a password.”
Training
They use it to run Mastodon, send emails, and help with moderation like spotting ban evasion.
Read the exact line
Privacy policy
“To aid moderation of the community, for example comparing your IP address with other known ones to determine ban evasion or other violations.”
Sharing
Public posts go to the whole network; staff and other servers may see private messages.
Read the exact line
Privacy policy
“Please keep in mind that the operators of the server and any receiving server may view such messages, and that recipients may screenshot, copy or otherwise re-share them.”
Kept
Login IPs up to 12 months; request logs up to 90 days; you can delete your account.
Read the exact line
Privacy policy
“Retain the IP addresses associated with registered users no more than 12 months.”
Controls
You can download an archive, delete your account, and revoke login sessions in settings.
Read the exact line
Privacy policy
“You can request and download an archive of your content, including your posts, media attachments, profile picture, and header image.”
Fine print
Minimum age 13 in the US or 16 in the EU; no terms here on lawsuits, refunds, or account bans.
Read the exact line
Privacy policy
“If this server is in the USA: Our site, products and services are all directed to people who are at least 13 years old.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Download an archive of your posts and media
Request an archive as described in the privacy policy (posts, media, profile picture, header image)
Irreversibly delete your account
Account deletion, described as available at any time
Review and revoke logged-in sessions
Settings, where logged-in sessions are available for review and revocation
Turn on two-factor authentication
Account security settings (two-factor authentication)
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
People who run this server or other servers can read your direct and followers-only posts. Recipients can copy them.
Read the exact line
Privacy policy
“Please keep in mind that the operators of the server and any receiving server may view such messages, and that recipients may screenshot, copy or otherwise re-share them.”
For example, a private message to a friend could still be read by a server admin or saved as a screenshot.
Your profile is public. Anyone can see your name, bio, and pictures.
Read the exact line
Privacy policy
“The username, display name, biography, profile picture and header image are always listed publicly.”
For example, a photo you set as your avatar is visible to people who never follow you.
Other Mastodon servers can copy your public posts and keep them even if you later change something here.
Read the exact line
Privacy policy
“Your public content may be downloaded by other servers in the network.”
For example, a public post can live on another server after you delete it here if that server does not honor the delete.
They warn you not to put secrets in posts because they cannot fully lock them down.
Read the exact line
Privacy policy
“Do not share any sensitive information over Mastodon.”
For example, they say not to send a password, health detail, or home address in a Mastodon message.
They keep the last IP you logged in from for as long as a year.
Read the exact line
Privacy policy
“The latest IP address used is stored for up to 12 months.”
For example, a café Wi-Fi address from last winter could still be on file.
They say they do not sell your personal info, except to trusted helpers and when the law requires it.
Read the exact line
Privacy policy
“We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information.”
For example, they would not list your email for sale, but a hosting company might still process it.
You can wipe your account for good. They do not say how fast copies on other servers disappear.
Read the exact line
Privacy policy
“You may irreversibly delete your account at any time.”
For example, you can delete the account, but a follower’s server might still have old posts.
Passwords are stored in a hashed form, and you can turn on two-factor login.
Read the exact line
Privacy policy
“your password is hashed using a strong one-way algorithm. You may enable two-factor authentication to further secure access to your account.”
For example, even if someone copies the database, they should not get your raw password.
They say kids under 13 in the US (or 16 in the EU) should not use it. They do not describe checking your age.
Read the exact line
Privacy policy
“If you are under the age of 13, per the requirements of () do not use this site.”
For example, a 12-year-old could still type a birthday and sign up if nobody checks.
Words to know
Legal words from the lines above, in plain English.
- human review
- Company staff or contractors may read your messages or content, usually to check for rule breaking. For example, a flagged private chat with an AI can be read by a person at the company.
- sensitive personal information
- Data that could hurt you if exposed, like health, religion, sexuality, race, exact location or bank details. For example, telling a chatbot about a medical condition creates sensitive data that some laws protect more strictly.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- COPPA
- A US law that limits what apps can collect from children under 13 without a parent's permission. For example, an app must get a parent's OK before it collects a 10-year-old's email address.
How we got here · grade C · score 42/100 · 13 of 15 policy answers backed by a verified quote · 6 not stated
What does the app collect beyond what it needs to work?
They collect account info, posts, media, follows, plus IP addresses, browser name, and server logs.
Does it record your voice, face or body, and what happens to that?
Not stated in the documents.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Server operators and receiving servers may view direct and followers-only posts. No opt-out is described.
Are you profiled or tracked for advertising?
They mention cookies for preferences, not ads or third-party ad trackers.
Do they sell or share your data, and can you opt out?
They say they do not sell personal info, but share with trusted helpers, other servers for federation, and when required by law.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
You can request an archive and irreversibly delete your account. IPs are kept up to 12 months; logs up to 90 days. They do not say how fast deleted content is gone everywhere.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe SSL, hashed passwords, and optional two-factor authentication. No audit or leak history is mentioned.
Is there a real age gate, and are teens protected?
They say 16+ in the EU/EEA and 13+ in the USA and tell underage people not to use the site. No age check is described.
Will they tell you when the rules change, and is the policy specific?
The policy is dated October 6, 2022, but it does not say they will warn you before changes.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
No paid plans, subscriptions, or refunds are described.
The privacy policy is 1,177 words at a fairly hard level (Flesch reading ease 54.7).