At a bare minimum they have everything they need to brute force your password.
Companies don't do this because of liability, but your random volunteer Mastodon admin is guaranteed to run passwords through a GPU crack program, which will find 99% of them in hours.
Even if it's set up like Proton mail where you have a local encryption key that takes a long time to construct, that just means they can't crack as good a password.
At a bare minimum they have everything they need to brute force your password.
Companies don't do this because of liability, but your random volunteer Mastodon admin is guaranteed to run passwords through a GPU crack program, which will find 99% of them in hours.
Even if it's set up like Proton mail where you have a local encryption key that takes a long time to construct, that just means they can't crack as good a password.