Mastodon vs Bluesky
Side-by-side comparison of the Terms of Service and Privacy Policy of Mastodon and Bluesky.
The policy emphasizes minimal monetization, short log retention, and user controls like archive download and account deletion. The main caveat is the inherent exposure of federated messaging and the public nature of much of the platform.
Mastodon.social’s legal posture is relatively privacy-conscious compared with many social platforms: it says it does not sell personal information, limits server log retention, allows content export, and lets users delete accounts. At the same time, because it is a federated social network, posts may be copied to other servers, and direct or followers-only messages can still be viewed by server operators and recipients.
Points of interest
-
negative ●●●●○ privacyPrivate posts can spread
Followers-only and direct posts may be stored on other servers, and the policy warns that server operators or recipients may view, screenshot, copy, or reshare them. In practice, these messages are not treated as truly private.
-
negative ●●●●○ privacyLogs keep IPs up to a year
The service records your login IP address and says the latest IP address used may be stored for up to 12 months. That is a meaningful amount of identity-linked metadata retention.
-
positive ●●●●○ privacyNo data selling
The policy says Mastodon does not sell or trade your personal information. That reduces the risk of ad-tech style sharing or monetization of your data.
-
positive ●●●●○ privacyExport your content
You can request and download an archive of your content, including posts, media, and profile images. This makes it easier to back up your data or move on from the service.
-
positive ●●●●○ privacyAccount deletion available
The policy says you may irreversibly delete your account at any time. That gives users a clear exit path, though deletion is permanent.
-
negative ●●●○○ privacyCookies track account use
Cookies are used to recognize your browser and associate it with your account, as well as save preferences. This is standard, but it does mean persistent browser tracking on the site.
-
positive ●●●○○ privacyShort server log retention
Server logs containing IP addresses are retained, if kept at all, for no more than 90 days. That is a relatively limited retention period for operational logs.
-
neutral ●●○○○ privacyModeration-related data use
Your information may be used for moderation, including checking for ban evasion by comparing IP addresses. This is a normal platform operation, but it means account and network activity are used for enforcement.
Documents
Bluesky offers useful privacy rights, clear account deletion, transparency about public-by-design data, and says it does not sell personal data for targeted advertising. However, broad content licensing, unencrypted DMs, long/indefinite retention tied to legal and safety purposes, arbitration with class-action waiver, and limited deletion in a decentralized network make the service only moderately user-friendly.
Bluesky presents itself as a decentralized social network with relatively transparent policies and some meaningful user rights, but it also imposes standard platform protections. User posts remain owned by users, yet broad licenses apply, most activity is public by design, direct messages are unencrypted, disputes generally go to arbitration, and deletion may be incomplete across the wider AT Protocol network.
Points of interest
-
negative ●●●●● privacyDMs stored unencrypted
Direct messages are not end-to-end encrypted and may be accessed for trust and safety purposes. Users should not treat Bluesky DMs as highly confidential communications.
-
negative ●●●●○ privacyMost activity is public
Posts, profile, likes, follows, and blocks are public by design. This makes social graph and activity data broadly visible rather than private by default.
-
negative ●●●●○ termsDeletion may be incomplete
Even if you delete your account, copies of your content may remain on other services using the AT Protocol. In practice, deletion across the decentralized network may not be fully enforceable.
-
negative ●●●●○ termsMandatory arbitration clause
Most disputes must go through a 60-day informal process and then binding individual arbitration instead of court. This usually makes it harder to bring claims publicly or use normal court procedures.
-
negative ●●●●○ termsClass actions waived
Users generally cannot participate in class or representative actions against Bluesky. That reduces leverage for small-value claims that are impractical to pursue individually.
-
positive ●●●●○ privacyNo targeted ad sales
Bluesky says it does not sell or share personal data for targeted advertising. That's a meaningful privacy-positive commitment compared with many social platforms.
-
positive ●●●●○ privacyAccess, deletion, portability rights
Depending on location, users can request access, correction, deletion, portability, restriction, objection, and review of automated decisions. These are substantial privacy rights, especially for users in stronger-regulation jurisdictions.
-
negative ●●●○○ termsBroad content license
You keep ownership of what you post, but grant Bluesky a worldwide, royalty-free license to reproduce, adapt, distribute, display, moderate, and promote that content. This is broad enough to cover product use and marketing uses.
-
negative ●●●○○ privacyLong retention discretion
Bluesky keeps data while your account is active and may retain it longer for trust and safety, disputes, audits, legal compliance, and claims. The policy does not give firm deletion deadlines for many categories.
-
negative ●●●○○ termsLiability capped at $100
If something goes wrong, Bluesky's financial liability is generally limited to US$100, except in narrow cases like fraud, gross negligence causing death or personal injury, or non-waivable statutory rights.
-
positive ●●●○○ termsClear account deletion option
The terms explicitly say you can delete your account at any time in settings. A built-in deletion flow is more user-friendly than requiring manual support requests.
-
positive ●●●○○ termsAppeal moderation decisions
If your account is suspended or restricted, you can appeal using an in-app tool or email within two weeks. EU/EEA users also retain access to out-of-court review and local courts.
Documents
Comparison is based on each service's published Terms of Service and Privacy Policy. Read the source documents linked above before relying on any specific clause.