Who can see what
The simple version: you see a space's contents once you're in it, and not before.
- Spaces are private by default. Posts, chat, members, and activity are for members — no one else. A private space you don't belong to doesn't even acknowledge it exists: it reads as not found.
- You only ever see what you already have access to. Search and feeds never surface anything from a space you're not in.
- Groups tighten this further. A closed group inside a space is readable only by its own members and the space's admins — other members of the space stay outside.
What a space can show the world
Everything public is opt-in, and it's layered:
- A public site. A space can turn on a public page at its own web address, and pick what it shows: a join page — its name, description, look, and how to join — or a front page of the posts it has made public. Public spaces can also appear in the Discover browser inside the app. Everything the space hasn't made public stays members-only.
- Public posts. A space can make individual posts publicly readable, each with its own shareable page. Making a post public is an explicit, per-post choice. Public post pages are read-only — comments and members stay inside — and a public post can share just its opening: with a fold, visitors see the part above it and an invitation to join for the rest. A post that isn't public shows visitors a join prompt instead of the content.
- Public topics. Instead of publishing posts one at a time, a space can make a whole topic public — every post in it becomes readable from the space's public page at once, each following the same fold rule as an individual public post. Comments and members still stay inside.
- Public events. A space can put individual calendar events on its public page — anyone can see the details, no account needed. Making an event public is an explicit, per-event choice, and the rest of the calendar stays members-only. See Calendar.
- Secret links. For a post you haven't made public, a space can hand out a private link that lets whoever holds it read the post's opening — without making the post public and without granting them membership. The link can be rotated or switched off at any time, so sharing stays under the space's control.
Your profile
Your basics — name, handle, avatar, bio, and any links you've added — can be seen by anyone signed in to DFOS, even with no space in common. That's how people recognize you when you turn up somewhere.
The fuller picture — your activity in a space, when you joined, what you share in common — is only visible to people you share that space with.
Your profile is public by default. Your name, handle, avatar, bio, and links are part of the wider DFOS network — your profile gets its own page on the open web, visible to anyone whether or not they're on DFOS, and you're findable in the directory. Spaces you belong to can appear on that page too, but only public spaces — you can hide any of them, and memberships in private spaces are never shown. Your email is never part of your public profile. If you'd rather stay out of it, one setting makes your profile private and drops you from the directory — see Accounts.
Media works a little differently — it has its own public and private split. See Media.
Proof that something exists
There's one more thing a space can put on the open web, and it's off unless the space turns it on: a space can anchor existence proofs for its members-only posts on the DFOS protocol. An existence proof says this space anchored a post at this moment, and carries no way at all to read it — no title, no body, no media, not even who's credited on it, and no key that could be handed out later.
It's there so a space can stake a signed, dated claim on work before it's published, and it changes nothing about who can read what.
The setting is one choice, in the space's settings: who may verify that its members-only posts exist — Everyone, or No one. Every space starts at No one, so a space opts in to publishing existence proofs about its private posts. Publicly readable posts always carry proofs at either setting; they're already on the open web, so there is nothing there to hold back. See Posts on the protocol.