privacydeep-dive

Pixelfed: The Privacy Trade-Offs of Fediverse Photo Sharing

Pixelfed promises an Instagram alternative without the surveillance. Here's what decentralized photo sharing actually protects you from — and what it doesn't.

When Instagram updated its terms to allow broader use of user photos for AI training, a wave of photographers and everyday users started looking for an alternative. Pixelfed — the decentralized photo-sharing platform built on the open ActivityPub protocol — became the most-discussed answer for people who want to share images publicly without feeding a surveillance advertising machine.

But “decentralized” and “private” are not synonyms. Understanding what Pixelfed actually changes about your privacy — and what it leaves untouched — matters before you migrate your feed or make promises to your audience about how their data is handled.


What Pixelfed Is and How It Works

Pixelfed is an open-source photo-sharing platform built on ActivityPub, the same protocol that powers Mastodon, PeerTube, and the broader fediverse. Instead of uploading photos to a single company’s servers, you create an account on an “instance” — a server run by a community, an organization, or yourself — and your photos live there.

Because all fediverse software speaks the same protocol, a Pixelfed account can follow a Mastodon account, and a Mastodon user can interact with Pixelfed posts without having a Pixelfed account. This creates a federated network where no single company controls the infrastructure or sets the terms for everyone.

From a user-experience standpoint, Pixelfed looks like Instagram. You post photos, follow accounts, receive comments and likes. The interface is deliberately familiar. The architecture underneath is structurally different.


What Decentralization Actually Changes

The most significant privacy shift that Pixelfed provides is structural: your photos and engagement data are not in Meta’s hands.

This has concrete consequences:

AI training. Meta has amended Instagram’s terms multiple times to expand the use of user content for training AI systems. Pixelfed instances have no such policy by default. If you join an instance run by a community that has committed not to use your photos for AI training, they’re operating outside the Meta pipeline. The instance administrator, not a company with a commercial AI program, sets that policy.

No advertising surveillance. Instagram’s core business is behavioral advertising. The platform observes what you look at, what you linger on, what ads you almost click, and builds an interest profile that it sells to advertisers. Pixelfed has no advertising model. Most instance operators run servers as a community service, not as a business extracting value from user attention.

No cross-platform profiling. Meta connects your Instagram behavior to your Facebook activity, your WhatsApp messages, and your browsing across millions of websites that carry the Meta Pixel. Pixelfed has no relationship with any of that infrastructure. Your photo-sharing behavior stays within the fediverse.

These are real, meaningful improvements over Instagram for anyone whose concern is commercial surveillance of their public photo activity.


What Decentralization Does Not Change

This is where the analysis gets more complicated — and where the marketing around the fediverse tends to oversimplify.

Your instance administrator has access to your data

When you post a photo to Pixelfed, it lives on your instance’s server. The person or organization running that server — the instance administrator — has technical access to everything on it. This includes content you’ve posted to followers-only audiences and, in most implementations, your direct messages.

This is not a theoretical concern. Server administrators hold database credentials. A sufficiently motivated admin can access your content, your metadata, and your connection logs. There is no technical mechanism that prevents this.

For most community-run instances with transparent administrators who operate servers as a public service, this risk is manageable. But it is not zero. Pixelfed is not end-to-end encrypted. The instance administrator is not Meta — but they’re also not nobody.

Before joining an instance, the questions worth asking are: Who runs this server? What is their privacy policy? What jurisdiction are they operating in? Do they have a track record of transparent operation? What happens to your data if they shut down?

Federation means your photos travel

When you post publicly on Pixelfed, your post federates to other servers whose users follow you. Copies of your photos exist on those servers. If you follow someone on another instance and they can see your posts, those posts have been delivered to their server.

Deleting a photo sends a deletion message through the ActivityPub protocol, and most well-maintained servers will honor it. But there is no guarantee that every server will delete promptly, or at all. Archiving projects and poorly maintained instances may retain federated content indefinitely.

Public posts on the fediverse should be treated as potentially permanent. If you post something publicly, assume it could persist on some server somewhere even after you delete it from your instance.

Law enforcement requests go to your instance operator

Meta’s responses to government legal requests are handled by Meta’s legal team, which publishes annual transparency reports. Requests are filtered through a global operation with legal expertise.

On Pixelfed, law enforcement requests go to your instance administrator. That may be a single person running a server as a hobby. They may not have legal resources. They may not know what they’re required to produce or what they can lawfully resist. They may be subject to legal pressure in a jurisdiction where data protection is weaker than you expect.

This cuts both ways. You’re not subject to Meta’s compliance decisions, and some instance operators in privacy-protective jurisdictions may be less cooperative with governments than Meta is. But you also don’t have Meta’s legal infrastructure working on your behalf — for whatever that’s worth.


Federation and the Limits of “Followers-Only” Posts

One privacy subtlety that many Pixelfed users don’t fully understand: followers-only posts are federated to the home instances of every follower who can see them.

If you have 200 followers spread across 40 different instances, a followers-only post is delivered to 40 different servers. The administrators of all 40 of those servers can technically access that post. The “followers-only” designation controls who can see it in their feed; it does not control which servers physically receive a copy of the content.

For truly private sharing — content you want only specific people to see, without it leaving your control — Pixelfed’s followers-only posts are not the right tool. Private file sharing or end-to-end encrypted messaging serves that purpose better.


Self-Hosting: The Maximum-Privacy Option

If you run your own Pixelfed instance — which requires a server, a domain, technical setup, and ongoing maintenance — you eliminate the third-party instance administrator risk entirely. You become the administrator. You hold the data. Law enforcement requests come to you directly.

Self-hosting is not a small project. You’re responsible for keeping the software updated, managing storage, handling backups, and dealing with spam and abuse reports. For people who have the capability and are serious about keeping their public photo sharing entirely outside commercial infrastructure, it is the most complete privacy option in the Pixelfed ecosystem.

For most people, it isn’t realistic. Joining a well-run community instance with a transparent operator is the practical approach.


Choosing an Instance: What Actually Matters

If you’re moving to Pixelfed, evaluating instances is as important as evaluating the software.

Jurisdiction. An instance based in a country with strong data protection laws — Germany, Iceland, Switzerland, or elsewhere in the EU — generally provides better legal protection than one hosted in jurisdictions with broad government access provisions.

Published privacy policy. A serious instance administrator documents what data they log, how long they keep it, what they share with third parties, and how they handle law enforcement requests. If there’s no privacy policy, assume the worst.

Account deletion policy. Before committing, verify that deleting your account actually removes your content — not just deactivates it. This is worth testing with a throwaway post.

Instance stability. Smaller instances run by one person can disappear without warning, taking your content and account history with them. Established instances with multiple administrators and long track records are more reliable.

Transparency culture. Instances whose administrators communicate openly about outages, policy decisions, and challenges are more trustworthy than those that operate silently. Look for administrators who post publicly about what they’re doing and why.


When Pixelfed Makes Sense — and When It Doesn’t

Pixelfed is the right tool for public photo sharing where your primary concern is keeping your content out of Meta’s advertising and AI training infrastructure. Street photography, landscapes, travel photos, community documentation — content intended for a public audience — can live on Pixelfed without feeding a commercial surveillance system.

Pixelfed is not designed for private storage. Family photos, personal documents, private moments, sensitive files — these belong in private storage, not on a public photo-sharing platform, regardless of how the platform’s privacy compares to Instagram. The appropriate question for public sharing and the appropriate question for private storage are completely different, and the answer to one does not answer the other.


The Realistic Picture

The fediverse, including Pixelfed, represents a genuine structural improvement over the dominant social media platforms. Photos shared on Pixelfed are not building Meta’s advertising profile for you. They’re not training Meta’s AI models by default. The infrastructure is not owned and operated by a company whose revenue depends on your engagement data.

That said, “not Meta” is not the same as “fully private.” Pixelfed is a public sharing platform that distributes your photos across federated servers whose administrators are humans, not mathematical guarantees. The privacy it provides is better than Instagram for the purpose of public photo sharing, and it’s not appropriate for the purpose of private storage.

Understanding the difference, and choosing tools that match the actual function, is more useful than treating any single platform as a universal privacy solution.


The Two Distinct Problems

Public photo sharing and private memory storage solve different problems, and the tools that are appropriate for one are not appropriate for the other.

For public sharing without commercial surveillance, Pixelfed is a serious option that has matured significantly over the past several years and serves a real need.

For private storage — photos and files you want to keep without sharing publicly, without contributing to AI training pipelines, and without exposing to advertising inference — private cloud storage from a provider with clear data practices is the appropriate tool.

daftei handles the second problem. Files stored on daftei are encrypted at rest with AES-256 and in transit with TLS 1.3. daftei doesn’t run advertising, doesn’t sell personal data, and doesn’t use your stored content to train AI systems for anyone other than you. The 5 GB free tier and Pro plan cover private archiving without the trade-offs of public federation.

The two use cases can coexist. A Pixelfed account for public photo sharing and a private encrypted store for personal memories are not in competition — they’re complementary tools for structurally different purposes.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts