Theoretically speaking of course ;)

If my home instance gets hacked, what’s the worst case scenario for my personal data?

  • Skull giver@popplesburger.hilciferous.nl
    link
    fedilink
    English
    arrow-up
    25
    ·
    edit-2
    1 year ago

    Data collected by a standard Lemmy server:

    • IP address of the device you’re using to access Lemmy

    • Posts, comments, favourites, upvotes, downvotes, subscriptions, blocked users, blocked communities. This also includes PMs (don’t use Lemmy PMs, make use the fact that your Lemmy can include a link to a Matrix account!)

    • Username, hashed password, email address if provided

    • TOTP public key if you have 2FA enabled

    • Your application if your server requires/required you to apply to register

    • Avatar, profile description, account registration date

    Installed apps may track more information (i.e. paid apps will probably collect some information so you can actually use the pro features, maybe device IDs, possibly advertising information if you can find a Lemmy app with ads)

    Individual Lemmy apps may or may not collect more information; the code is open so servers can modify the source code if they so wish.