Privacy Tips
TL;DR: In the decentralized web, "Public" effectively means "Permanent." Once data leaves your server, you lose control over it.
The Fediverse is built on openness. While this is its strength, it is also a privacy risk. Keep the following realities in mind:
- Public means Accessible: Anyone can search or view your public posts. Even if your server tries to limit search visibility, these restrictions are easily bypassed by anyone with a little technical know-how.
- You can't block "Listening": Even if you block users, other servers can still subscribe to your public broadcasts without needing your approval.
- Data Correlation: Search engines and scrapers can easily link your identities across different platforms if you post the same content publicly.
Why Deletion Doesn't Always Work
The Fediverse works by copying your posts to the servers of everyone who follows you. When you delete a post, your server simply sends a polite "please delete this" request to those other servers.
If a remote server is offline, broken, or malicious, it will not receive or honor the delete request.
Besides, there are Web archives, search engine caches, and screenshots that operate outside the Fediverse's control.
How to Protect Yourself
You don't need to stop posting, but you should post intentionally.
- Before posting publicly, ask yourself: "Am I okay with anyone seeing this?"
- If the content is personal, don't make it public.
GoToSocial's Privacy Related Settings
GoToSocial's default settings tries to give you more privacy (e.g., it doesn't broadcast your posts to the global public timeline by default), but your profile is still visible to anyone with a link.
To increase the privacy of your posts, you could try:
- Lock Your Account: Ensure new followers require manual approval.
- Change Default Visibility: Go to Settings and set your default post visibility to "Followers Only."
- Hide Your Network: In Settings, hide your "Following" and "Followers" lists so others can't map your social circle.
- Hide Your Post in Web View: set "Visibility level of posts to show on your profile web page" settings to "Show no posts."
- Use "Local Only": When the time is right, use the "Local Only" visibility setting if your app supports it. This prevents the post from ever leaving your server. (If your app asks if this is a "Mastodon Glitch" feature, select "No.")