Reviewed Jun 2026 · some cells re-verified Aug 2026 · policies are checked weekly for changes · stated — every cell is read from Bluesky's published policy; none has been tested (run by us) yet.
1Portabilitystated
The stated portability right (“a structured, commonly used, and machine-readable format”) is request-path only. Full-repository CAR export is documented as developer tooling — Bluesky's help center states “For non-devs, the tooling is still being built” — so no self-serve consumer export tool appears in the company's own docs.
Bluesky Help Center — Data Privacy FAQ · accessed Aug 2026 ↗
1Deletionstated
Self-serve permanent deletion exists, but no purge timeline is stated: deleted post text “takes a bit longer… to be fully deleted in storage” and is wiped by periodic back-end deletes, and the policy allows retention “for backups, archiving, prevention of fraud and abuse”. Public data already copied by other AT Protocol services sits outside Bluesky's control.
Bluesky Help Center — Data Privacy FAQ (deletion) · accessed Aug 2026 ↗
1Trains AIstated
The privacy policy is silent on whether Bluesky uses personal data or content to train AI models — it neither claims to nor commits not to — so model-training use is scored at the unclear level (Telegram/Netflix parity). Note the network's data is public by design and readable by anyone, including AI developers.
Bluesky Privacy Policy — (no AI-training clause) · accessed Aug 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
The AT Protocol exposes a hosted OAuth API — “OAuth is the primary mechanism in atproto for clients to make authorized requests to PDS instances” — and public repository endpoints; a consumer can authorize a remote agent to read their full account repository.
AT Protocol — OAuth specification · accessed Aug 2026 ↗
Graded 2026-08-31 against the Bluesky Privacy Policy (last updated Aug 14, 2025) and Bluesky's help-center articles. Consumer surface = the Bluesky app and bsky.app, operated by Bluesky Social, PBC, a US public benefit company. Bluesky is a public social network built on the open AT Protocol: posts, likes and blocks are public by design, and copies of that public data held by relays, mirrors and other services on the network are outside this policy — this grade describes Bluesky's own service. Deactivation and permanent deletion are self-serve in Settings; every other right runs through a support ticket or support@bsky.app. The company's own docs describe full-repository export (a CAR file) as developer tooling — the help center still states that for non-developers “the tooling is still being built” — so no consumer export tool is documented. The policy is silent on AI training. All cells stated, not tested.
Events
Breaches, policy changes, and export-format changes we’ve recorded at Bluesky — other parties’ actions, alongside the enforcement record above. An event never changes a grade by itself. All events →
No events on record for Bluesky.
Grade history
Every change to this company’s grade since it was first published, and why. All grade changes →
No changes since this grade was first published in Jun 2026.