data report card

Data Report Card · Bluesky

Bluesky Data Report Card

Social app · AT Protocol · Bluesky Social, PBC
Data
Practices
1Access1Portability1Friction1Deletion2Sells1Trains AI
=
C
7/12
Agent
Readiness
1Access 1Portability 2API access
=
C
4/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

Help me make a request →
Reviewed Jun 2026  ·  some cells re-verified Aug 2026 · policies are checked weekly for changes  ·  stated — every cell is read from Bluesky's published policy; none has been tested (run by us) yet.
1Accessstated
The policy lists “obtaining access to or a copy of your personal information” among rights that depend on where you live; the documented path is a support ticket through your account or emailing support@bsky.app — no portal, no stated scope or timeline.
Bluesky Privacy Policy — Your Privacy Choices and Rights · accessed Aug 2026 ↗
1Portabilitystated
The stated portability right (“a structured, commonly used, and machine-readable format”) is request-path only. Full-repository CAR export is documented as developer tooling — Bluesky's help center states “For non-devs, the tooling is still being built” — so no self-serve consumer export tool appears in the company's own docs.
Bluesky Help Center — Data Privacy FAQ · accessed Aug 2026 ↗
1Frictionstated
Deactivation and permanent deletion are self-serve (Settings → Account, with an email confirmation code); every other right runs through a support ticket or support@bsky.app with no stated response timeline. An appeal right is stated. No dark patterns are documented.
Bluesky Help Center — How to delete/deactivate my account · accessed Aug 2026 ↗
1Deletionstated
Self-serve permanent deletion exists, but no purge timeline is stated: deleted post text “takes a bit longer… to be fully deleted in storage” and is wiped by periodic back-end deletes, and the policy allows retention “for backups, archiving, prevention of fraud and abuse”. Public data already copied by other AT Protocol services sits outside Bluesky's control.
Bluesky Help Center — Data Privacy FAQ (deletion) · accessed Aug 2026 ↗
2Sells / sharesstated
The policy states “We do not sell or share Personal Data for the purpose of displaying advertisements” and, in the US-specific section, that it does not sell or share Personal Data for cross-context behavioural advertising — the plain no-sell shape.
Bluesky Privacy Policy — sharing / US state disclosures · accessed Aug 2026 ↗
1Trains AIstated
The privacy policy is silent on whether Bluesky uses personal data or content to train AI models — it neither claims to nor commits not to — so model-training use is scored at the unclear level (Telegram/Netflix parity). Note the network's data is public by design and readable by anyone, including AI developers.
Bluesky Privacy Policy — (no AI-training clause) · accessed Aug 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
The AT Protocol exposes a hosted OAuth API — “OAuth is the primary mechanism in atproto for clients to make authorized requests to PDS instances” — and public repository endpoints; a consumer can authorize a remote agent to read their full account repository.
AT Protocol — OAuth specification · accessed Aug 2026 ↗
Graded 2026-08-31 against the Bluesky Privacy Policy (last updated Aug 14, 2025) and Bluesky's help-center articles. Consumer surface = the Bluesky app and bsky.app, operated by Bluesky Social, PBC, a US public benefit company. Bluesky is a public social network built on the open AT Protocol: posts, likes and blocks are public by design, and copies of that public data held by relays, mirrors and other services on the network are outside this policy — this grade describes Bluesky's own service. Deactivation and permanent deletion are self-serve in Settings; every other right runs through a support ticket or support@bsky.app. The company's own docs describe full-repository export (a CAR file) as developer tooling — the help center still states that for non-developers “the tooling is still being built” — so no consumer export tool is documented. The policy is silent on AI training. All cells stated, not tested.

Events

Breaches, policy changes, and export-format changes we’ve recorded at Bluesky — other parties’ actions, alongside the enforcement record above. An event never changes a grade by itself. All events →

No events on record for Bluesky.

Grade history

Every change to this company’s grade since it was first published, and why. All grade changes →

No changes since this grade was first published in Jun 2026.

How to request your data from Bluesky

  1. Go to https://bsky.social/about/support/privacy-policy — Bluesky's data-request entry point.
  2. In-app: Settings → Account for deactivation/deletion; data-rights requests via a support ticket or support@bsky.app — no portal, no consumer export tool documented.
  3. Expected wait: requests via support ticket or email; an appeal right is stated; no stated response timeline — Bluesky's stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact Bluesky — Support: mailto:support@bsky.app.

These steps reflect Bluesky's documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.