X (formerly Twitter).
Post-acquisition X rewrote the rules so your posts, replies, images, and Grok conversations feed xAI's models by default for everyone outside the EU §1 — the opt-out is a toggle buried under Settings → Privacy & Safety → Grok & Third-party Collaborators, and it's leaky: the 2026 terms still license your content for 'any purpose' §11. DMs were replaced by XChat, which is finally end-to-end encrypted — but the keys live on X's own servers, metadata isn't encrypted, and X's help page admits it offers no protection against man-in-the-middle attacks and can be compelled to read your messages §9. Public means public, forever: deleting a post hides it, it doesn't unwind copies in archives, in licensees' firehose dumps, or in Grok's training set §10. The regulators have noticed: USD 150M from the FTC (2022) §14, EUR 120M from the EU's first-ever DSA fine (Dec 2025), and an open Irish GDPR probe into Grok (Feb 2026) §15. X's current move? Asking the FTC to throw out the privacy order entirely §15.
TL;DR — 8 answers.
The eight things you actually want to know, at a glance.
The questions, answered.
No legalese. Every answer the way your most cynical friend would put it.
Do they sell your data?
The full-firehose enterprise API is exactly that: every public post, sold to anyone with a checkbook.
Are they tracking you on other sites?
The X Pixel and embedded post widgets log impressions on millions of third-party pages, signed-in or not.
Can your data train their AI?
Default. Yes. For everyone outside the EU, your public posts, replies, images, and Grok chats all feed Grok unless you dig out the toggle under Settings → Privacy & Safety → Grok & Third-party Collaborators. EU users got carved out only after regulators forced it.
Who can see what you do?
Public posts: everyone, including data licensees and Grok. XChat messages: encrypted in transit, but X holds the keys and admits it can be compelled to read them. Premium ID: X plus their verification vendor.
Can you delete everything?
Deleting a post hides it. Copies live in archives, in Grok's training set, and in third-party licensees who already pulled the firehose.
Do they honor your opt-out?
GPC: ignored. The Grok opt-out exists but is leaky — even when toggled, the 2026 terms keep a broad license to use your content for 'any purpose'. Opting out doesn't undo training already done.
Special handling for minors?
Account requires 13+. Beyond that, minors get the same algorithmic feed as adults — and the Grok image tools that triggered the EU and Irish probes generated thousands of images that appeared to depict minors [[S15]].
Been fined for this before?
USD 150M (FTC, 2022 — 2FA phone numbers used for ads) [[S14]]. EUR 120M (EU's first DSA fine, Dec 2025). Open Irish GDPR probe into Grok (Feb 2026). And X is now asking the FTC to scrap the privacy order altogether [[S15]].
At a glance, honestly.
Eight signals, color-coded. Like a model card for a machine — except the machine is reading your data.
The Privacy Label, honestly.
An Apple-style label for what's collected and a Cranor-style back-of-pack for what they do with it. Every cell links to the exact line in their policy.
The receipts, translated.
Five of the worst clauses, lifted verbatim. Strikethroughs are theirs. Marginalia is ours.
Dark patterns spotted.
Tricks the policy and surrounding UX use to make you "consent" without really consenting.
Your rights, by where you live.
Same company, wildly different rights depending on your jurisdiction. Direct links to the specific opt-out / delete / access flows.
- ✓ Right of access
- ✓ Right to erasure
- ✓ Right to data portability
- ✓ Right to object to processing
- ✓ Right against solely-automated decisions
- ✓ Carve-out: EU public posts not used to train Grok (regulator-forced)
Source: §13
The actual sources.
Every claim above is anchored to a line in the policy we analyzed. Click any section ID to view it in context.
SOURCE: https://x.com/en/privacy · POLICY VERSION: 2024-11-15 · SNAPSHOT HASH:
- §1X Terms of Service · grant of rights / AI training (effective Nov 15, 2024)"You agree that this license includes the right for us to analyze text and other information you provide and to otherwise provide, promote, and improve the Services, including the training of our machine learning and artificial intelligence models, whether generative or otherwise."
- §2X Privacy Policy · changes to this policy & continued use"By continuing to access or use the Services after those revisions become effective, you agree to be bound by the revised Privacy Policy."
- §3X Privacy Policy · information we collect"We collect identifiers, contact information, billing information, and content you share on the Services, including posts, images, and messages."
- §4X Privacy Policy · information from third-party sites, pixels, and embeds"We collect information about your interactions with our embedded content and pixels on third-party sites that have integrated X content."
- §5X Privacy Policy · location information"We may infer your approximate location from your IP address and collect precise location only when you have granted permission."
- §6X Privacy Policy · identity verification & biometric information"If you choose to verify your identity, we may collect a government-issued identification document and biometric information, including facial geometry derived from your image."
- §7X Privacy Policy · advertising and analytics"We use the information we collect to deliver and personalize advertising on and off our services."
- §8X Privacy Policy · sharing, affiliates (xAI), and data licensees"We share information with our affiliates, including xAI, and with partners who license access to public content through our API."
- §9X Help Center · About Chat (XChat end-to-end encryption)"Currently, we do not offer protections against man-in-the-middle attacks. As a result of a compulsory legal process, X could be required to provide access to the contents of your messages."
- §10X Privacy Policy · how long we keep information & deletion"Public content you share on the Services is, by its nature, public; we may retain copies even after you delete the underlying content for legal, safety, and research purposes."
- §11X Help Center · Grok & Third-party Collaborators data-sharing setting"Allow your public posts as well as your interactions, inputs, and results with Grok and third-party collaborators to be used for training and fine-tuning."
- §12X Privacy Policy · algorithmic ranking, visibility filtering & inferences"Some content may have its visibility reduced in feeds and search, in accordance with our content policies."
- §13X Help Center · your privacy rights and choices"Depending on your location, you may have rights to access, correct, delete, or object to the processing of your personal data."
- §14FTC · $150M settlement over deceptive use of 2FA data (May 2022)"Twitter will pay a $150 million penalty for deceptively using account security data — phone numbers and email addresses collected for two-factor authentication — to target ads, in violation of a 2011 FTC order."
- §15EU DSA fine (Dec 2025), Irish DPC Grok probe (Feb 2026) & X petition to end FTC order (Jun 2026)"X was the recipient of the European Commission's first DSA non-compliance decision, fined €120 million; in February 2026 the Irish DPC opened a large-scale GDPR investigation into Grok's generation of sexualized images, and in June 2026 X petitioned the FTC to scrap the longstanding privacy order governing the company."