GenAgent Trust Hub
Menu

Musician.social (Mastodon Instance)

CTier CMedium risk · 45/100
  • The documents do not say whether your data trains AI.
  • The policy rules out using your data for targeted ads.
  • Data is shared only with the providers who run the service.
  • Staff may review your content; the policy does not describe an opt-out.

A Mastodon music server that posts publicly, keeps IPs up to a year, and lets operators read DMs.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy · October 6, 2022 ↗Terms not found6 min read · fairly hard18 lines verified word for word

Collected

What is collected

Account details, posts and media, plus your IP address and browser name.

Read the exact line

Privacy policy

“When you log in, we record the IP address you log in from, as well as the name of your browser application.”

Training

How it is used

They use it to run the site, send email notices, and help with moderation.

Read the exact line

Privacy policy

“To aid moderation of the community, for example comparing your IP address with other known ones to determine ban evasion or other violations.”

Sharing

Who may see it

Public posts go to other servers; staff and other servers may also see DMs.

Read the exact line

Privacy policy

“Please keep in mind that the operators of the server and any receiving server may view such messages, and that recipients may screenshot, copy or otherwise re-share them.”

Kept

How long it is kept

Logs up to 90 days, login IPs up to 12 months; you can delete your account.

Read the exact line

Privacy policy

“Retain the IP addresses associated with registered users no more than 12 months.”

Controls

Your controls

You can download an archive, delete your account, and revoke login sessions.

Read the exact line

Privacy policy

“You can request and download an archive of your content, including your posts, media attachments, profile picture, and header image.”

Fine print

The fine print

No terms of service here; age is 13 in the US and 16 in the EU, self-declared.

Read the exact line

Privacy policy

“If this server is in the USA: Our site, products and services are all directed to people who are at least 13 years old.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Download an archive of your posts and media

    Privacy policy: request and download an archive of your content

  2. Irreversibly delete your account

    Privacy policy: you may irreversibly delete your account at any time

  3. Review and revoke logged-in sessions

    Settings: all logged in sessions are available for review and revocation

  4. Turn on two-factor authentication

    Account settings as described in the privacy policy

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · How it is used

Even private or followers-only posts can be read by this server’s staff and by other servers.

Read the exact line

Privacy policy

“Please keep in mind that the operators of the server and any receiving server may view such messages, and that recipients may screenshot, copy or otherwise re-share them.”

For example, a DM about a gig deal could be seen by an admin or copied on another server.

2 · What is collected

Your profile is public. Anyone can see your name, bio, and pictures.

Read the exact line

Privacy policy

“The username, display name, biography, profile picture and header image are always listed publicly.”

For example, a photo you set as your avatar is visible to the whole internet.

3 · How it is used

Public posts are copied to other Mastodon servers and may stay there.

Read the exact line

Privacy policy

“Your posts are delivered to your followers, in some cases it means they are delivered to different servers and copies are stored there.”

For example, deleting a post here may not erase copies already saved elsewhere.

4 · How long it is kept

They keep the last IP you logged in from for as long as a year.

Read the exact line

Privacy policy

“The latest IP address used is stored for up to 12 months.”

For example, a login from a café Wi‑Fi could be stored for 12 months.

5 · How it is used

They warn you not to put secrets in posts or DMs because they are not fully private.

Read the exact line

Privacy policy

“Do not share any sensitive information over Mastodon.”

For example, do not send a password or medical detail in a direct message.

6 · How it is used

They say they do not sell your personal info, except to helpers who run the site or if the law requires it.

Read the exact line

Privacy policy

“We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information.”

For example, they would not sell your email list to an advertiser.

7 · How long it is kept

You can wipe your account for good whenever you want.

Read the exact line

Privacy policy

“You may irreversibly delete your account at any time.”

For example, you can delete the account after a tour and it should not come back.

8 · How long it is kept

Logins go over encrypted HTTPS and passwords are stored hashed, not in plain text.

Read the exact line

Privacy policy

“Among other things, your browser session, as well as the traffic between your applications and the API, are secured with SSL, and your password is hashed using a strong one-way algorithm.”

For example, someone who steals a database dump should not see your real password.

9 · The fine print

Kids under 13 in the US are told not to use it, but they only ask you to follow that rule yourself.

Read the exact line

Privacy policy

“If you are under the age of 13, per the requirements of () do not use this site.”

For example, a 12-year-old could still sign up if they type an older age.

Words to know

Legal words from the lines above, in plain English.

human review
Company staff or contractors may read your messages or content, usually to check for rule breaking. For example, a flagged private chat with an AI can be read by a person at the company.
sensitive personal information
Data that could hurt you if exposed, like health, religion, sexuality, race, exact location or bank details. For example, telling a chatbot about a medical condition creates sensitive data that some laws protect more strictly.
sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
COPPA
A US law that limits what apps can collect from children under 13 without a parent's permission. For example, an app must get a parent's OK before it collects a 10-year-old's email address.
How we got here · grade C · score 45/100 · 13 of 15 policy answers backed by a verified quote · 6 not stated
  • What does the app collect beyond what it needs to work?

    They collect account and profile info, posts and media, plus IP addresses, browser name, and server logs.

  • Does it record your voice, face or body, and what happens to that?

    Not stated in the documents.

  • Are your chats and uploads used to train AI models, and is that off by default?

    Not stated in the documents.

  • Can employees or contractors read your conversations, and when?

    Server operators and receiving servers may view direct and followers-only posts. There is no opt-out described.

  • Are you profiled or tracked for advertising?

    Cookies are used to save preferences. The policy does not describe ads or third-party ad tracking.

  • Do they sell or share your data, and can you opt out?

    They say they do not sell personal information, but share with trusted helpers and federate public posts to other servers.

  • What rights do they take over what you type and what the AI makes?

    Not stated in the documents.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    You can delete your account at any time. Server logs are kept no more than 90 days; login IPs up to 12 months.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    Not stated in the documents.

  • Do they commit to basic security, and have they leaked data?

    They describe SSL, hashed passwords, and optional two-factor authentication. No audit or leak history is mentioned.

  • Is there a real age gate, and are teens protected?

    They say 16+ in the EU/EEA and 13+ in the USA. There is no described age check beyond that warning.

  • Will they tell you when the rules change, and is the policy specific?

    The policy is dated October 6, 2022, but it does not say they will warn you before changing it.

  • Can they close your account without warning, and can you get your data out first?

    Not stated in the documents.

  • If something goes wrong, who pays?

    Not stated in the documents.

  • Do subscriptions renew on their own, and can you get a refund?

    The documents do not describe paid plans, subscriptions, or refunds.

The privacy policy is 1,177 words at a fairly hard level (Flesch reading ease 53.4).

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton