Mastodon is actually decentralised — not "decentralised" like Bluesky where one company runs everything. Thousands of independent servers, run by real people. No single company owns your data. This is genuinely better architecture. But your server admin can read your DMs. Direct messages aren't end-to-end encrypted. Your privacy depends on who runs your server — their competence, their motives, their security practices. A server run by a cryptographer is private. A server run by a hobbyist who doesn't update the software is a breach waiting to happen. Mastodon distributes trust. It can't guarantee it. Mastodon is maintained by fewer than 10 people on donations. Critical vulnerabilities have been found — one let attackers overwrite files on the server, another allowed account takeover through a crafted link. The fixes were available. But Mastodon can't force server operators to update. Thousands of independent servers, each patching on their own schedule — or not. A non-profit with limited funding maintaining infrastructure for millions of users, where the security of the network depends on the least diligent server operator updating their software. The architecture that makes Mastodon free from corporate control also makes it free from coordinated security response.
What they claim: Mastodon positions itself as a decentralised social network where users control their experience.
What we found: Mastodon is genuinely federated — thousands of independent servers run by different operators communicate via ActivityPub. This is a real structural privacy advantage: no single company controls your data. However, the decentralisation creates its own privacy problem. Each server administrator has full access to their users' posts, DMs, and account data. Direct messages on Mastodon are not end-to-end encrypted — server admins can read them. The quality of your privacy depends entirely on who runs your server. A server run by a privacy advocate is very different from a server run by a hobbyist with no security experience. Decentralisation distributes trust. It doesn't eliminate it.
What they claim: Mastodon is a non-profit (gGmbH) based in Germany, governed by EU data protection law.
What we found: The Mastodon non-profit is funded primarily by donations and Patreon supporters. In 2024, the organisation had a small team (under 10 people) maintaining software used by millions. Critical security vulnerabilities have been discovered — CVE-2023-36460 allowed attackers to create and overwrite any file the Mastodon process could access, and CVE-2024-23832 allowed account takeover through a crafted link. Not all server operators patch promptly. A non-profit with limited resources maintaining critical social infrastructure used by millions, where security depends on thousands of independent operators updating on time. The decentralised model's strength is its weakness: nobody can force a patch.