Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Open source decentralized social network based on ActivityPub. Embedded posts are served by the chosen instance and generally set no advertising or tracking cookies.
Mastodon is an open source, decentralized social network built on the ActivityPub protocol. Instead of one company, it runs as many independent servers called instances, such as mastodon.social, that federate with each other. Anyone can host an instance, and you can embed a public post using an iframe served directly by the instance that hosts it.
A standard Mastodon embed loads an iframe from the instance domain along with its media CDN. The instance receives the visitor IP address, user agent and referring page in order to serve the content. Unlike commercial social platforms, default Mastodon embeds generally set no advertising or tracking cookies and there is no central ad network. An instance may set a first party session cookie for its own operation.
Because a standard embed sets no profiling cookies, the cookie consent obligation under the ePrivacy Directive is limited. However, loading the iframe still transmits the visitor IP to the instance, which is personal data. A privacy by design approach, such as click to load, is recommended so that no data leaves the page until the visitor chooses to view the post.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Where the only processing is serving requested content and any strictly functional session cookie, an instance can often rely on legitimate interest under Article 6(1)(f). Many operators still prefer to obtain consent or use click to load for transparency, since the visitor IP reaches a third party server when the embed loads.
Transfers depend entirely on the instance location. An EU hosted instance keeps data within the EU, while an instance hosted elsewhere may involve a transfer to a third country that you should assess. Federation means that public posts can be copied to other instances that follow the author, so public content may be replicated across servers in different jurisdictions.
Prefer an EU hosted instance, use a click to load placeholder so the iframe loads only after interaction, and document the instance you embed from in your privacy notice. Because there is no profiling and largely no cookies, Mastodon is a low risk way to display social content compared with advertising driven platforms.
Websites using Mastodon must obtain user consent under GDPR regulations.
DPIA considerations
The risk is low because standard Mastodon embeds set no profiling cookies. Focus the assessment on the location of the chosen instance for transfers and on the fact that loading the iframe transmits the visitor IP. A click to load approach greatly reduces the processing.
Sample consent text
This page can embed a Mastodon post served by a third party instance. Loading it transmits your IP address to that instance to display the content. No advertising cookies are used. Do you want to load the Mastodon post?
Third-party domains contacted
mastodon.socialfiles.mastodon.socialCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _session_id | First-party | Session | Functional session cookie that the Mastodon instance may set to operate the embedded view. It carries no advertising or cross site profiling purpose. |
| _mastodon_session | First-party | Session | Server session cookie used by some Mastodon instances to maintain the embedded request state. Strictly functional, not used for tracking. |
| cookieconsent_status | First-party | 1 year | Optional cookie stored by an instance to remember a visitor cookie choice on its own pages. Not used for advertising. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
A standard Mastodon embed generally sets no advertising or tracking cookies. The hosting instance may set a first party session cookie for its own operation, but there is no central ad network and no cross site profiling.
Since there is no profiling cookie, the consent obligation is limited, but loading the iframe transmits the visitor IP to the instance. A click to load approach or consent is recommended as a privacy by design measure.
Serving the requested content and any strictly functional session cookie can often rely on legitimate interest under Article 6(1)(f). If you choose to ask for consent, the basis is Article 6(1)(a).
It depends on the instance. An EU hosted instance keeps data in the EU, while an instance hosted outside the EEA involves a transfer you must assess. Federation can also replicate public posts across instances in different countries.
A full DPIA is usually not required because there is no profiling and largely no cookies. A short assessment of the instance location and the IP transmission on load is generally sufficient for this low risk integration.
Prefer an EU hosted instance, use a click to load placeholder so the iframe loads only after interaction, and name the instance in your privacy notice. This keeps the processing minimal and transparent.
You can link to the original post or show a static screenshot, which loads nothing from the instance. You can also use a self hosted feed reader that fetches posts server side, avoiding any direct contact between the visitor and the instance.
Note that you embed content from a named Mastodon instance, that loading transmits the visitor IP to that instance, and that no advertising cookies are used. Mention the instance location and any functional session cookie it may set.