VOL. I  ·  EST. 2026  ·  "WE READ THE FINE PRINT SO YOU DON'T HAVE TO"
F
Verdict
EXHIBIT A

X (formerly Twitter).

"read the fine print. he did, then changed it."

Post-acquisition X rewrote the rules so your posts, replies, images, and Grok conversations feed xAI's models by default for everyone outside the EU §1 — the opt-out is a toggle buried under Settings → Privacy & Safety → Grok & Third-party Collaborators, and it's leaky: the 2026 terms still license your content for 'any purpose' §11. DMs were replaced by XChat, which is finally end-to-end encrypted — but the keys live on X's own servers, metadata isn't encrypted, and X's help page admits it offers no protection against man-in-the-middle attacks and can be compelled to read your messages §9. Public means public, forever: deleting a post hides it, it doesn't unwind copies in archives, in licensees' firehose dumps, or in Grok's training set §10. The regulators have noticed: USD 150M from the FTC (2022) §14, EUR 120M from the EU's first-ever DSA fine (Dec 2025), and an open Irish GDPR probe into Grok (Feb 2026) §15. X's current move? Asking the FTC to throw out the privacy order entirely §15.

Social media / 'everything app'
Analyzed: 2026-06-05
§2 · The short version

TL;DR — 8 answers.

The eight things you actually want to know, at a glance.

TL;DR — 8 answers F
YES Do they sell your data?
YES Are they tracking you on other sites?
YES Can your data train their AI?
~ Who can see what you do?
NO Can you delete everything?
NO Do they honor your opt-out?
~ Special handling for minors?
YES Been fined for this before?
§3 · The details

The questions, answered.

No legalese. Every answer the way your most cynical friend would put it.

YES
§8

Do they sell your data?

The full-firehose enterprise API is exactly that: every public post, sold to anyone with a checkbook.

YES
§4

Are they tracking you on other sites?

The X Pixel and embedded post widgets log impressions on millions of third-party pages, signed-in or not.

YES
§1

Can your data train their AI?

Default. Yes. For everyone outside the EU, your public posts, replies, images, and Grok chats all feed Grok unless you dig out the toggle under Settings → Privacy & Safety → Grok & Third-party Collaborators. EU users got carved out only after regulators forced it.

COND.
§9

Who can see what you do?

Public posts: everyone, including data licensees and Grok. XChat messages: encrypted in transit, but X holds the keys and admits it can be compelled to read them. Premium ID: X plus their verification vendor.

NO
§10

Can you delete everything?

Deleting a post hides it. Copies live in archives, in Grok's training set, and in third-party licensees who already pulled the firehose.

NO
§11

Do they honor your opt-out?

GPC: ignored. The Grok opt-out exists but is leaky — even when toggled, the 2026 terms keep a broad license to use your content for 'any purpose'. Opting out doesn't undo training already done.

COND.
§12

Special handling for minors?

Account requires 13+. Beyond that, minors get the same algorithmic feed as adults — and the Grok image tools that triggered the EU and Irish probes generated thousands of images that appeared to depict minors [[S15]].

YES
§15

Been fined for this before?

USD 150M (FTC, 2022 — 2FA phone numbers used for ads) [[S14]]. EUR 120M (EU's first DSA fine, Dec 2025). Open Irish GDPR probe into Grok (Feb 2026). And X is now asking the FTC to scrap the privacy order altogether [[S15]].

§3 · The privacy card

At a glance, honestly.

Eight signals, color-coded. Like a model card for a machine — except the machine is reading your data.

Privacy Card · X (formerly Twitter) · Analyzed 2026-06-05
F
Data sold / shared YES BAD
Cross-site tracking YES BAD
AI training YES opt-out: limited
Deletion right LIMIT. MIXED
GPC honored NO BAD
Keeps forever? YES BAD
Child protections COND. MIXED
Automated decisions YES human review: no
Collects
Identifiers, Public posts & engagement, Browsing & embeds, Biometric data, Government ID +5 more
Shares with
Advertisers, xAI (affiliate), Data licensees (full firehose API), Government on legal process +1 more
§5 · The label they should have shown you

The Privacy Label, honestly.

An Apple-style label for what's collected and a Cranor-style back-of-pack for what they do with it. Every cell links to the exact line in their policy.

X (FORMERLY TWITTER) — DATA COLLECTED
PER APPLE PRIVACY-LABEL TAXONOMY ↗
USED TO TRACK YOU
Data shared with third parties for cross-property tracking.
Identifiers §3
User ID · Device ID · Ad ID · IP address
Public posts & engagement §1
Posts · Replies · Reposts · Likes · Bookmarks · Grok conversations
Browsing & embeds §4
X Pixel on third-party sites · Embedded post views
Biometric data §6
Faceprints (X Verify / ID selfie) · Voice signatures (audio Spaces)
◐ LINKED TO YOU
Tied to your identity and stored against your account.
Government ID §6
Driver license / passport for Premium ID verification
Messages (XChat) §9
Message content (E2E, but keys stored on X servers) · Metadata: recipients, timestamps (not encrypted) · Legacy DMs (unencrypted)
Location §5
Approximate (IP) · Precise (per-grant) · Tagged in posts
Contact info & payment §3
Email · Phone · Billing (for Premium)
Inferred sensitive §12
Politics · Religion · Sexual orientation · Health
○ NOT LINKED TO YOU
Aggregated, supposedly anonymous.
Diagnostics §7
Crash data · Performance metrics
↓ BACK OF LABEL · WHAT THEY DO WITH IT (CRANOR FRAMEWORK)
Purposes
Grok & xAI model training (default-on outside the EU), Advertising & ad measurement, Algorithmic feed ranking & visibility filtering, Cross-product use across xAI / X corporate group, ID verification (Premium / X Verify). §1
5+ stated purposes. The interesting ones are buried in §7.
Sold or shared?
Yes. Advertisers, xAI (affiliate), Data licensees (full firehose API), Government on legal process, Successor entities on policy change. §8
"We don't sell data" is technically true and substantively false.
Retention
Indefinite, with caveats. §10
Public posts: retained for the life of the service. Deleted posts: removed from public view, retained for an undefined period for 'legal and safety' purposes, and not unwound from archives or licensees who already pulled the firehose. ID-verification data: retained for the life of the Premium subscription plus an unspecified tail. Posts already used to train Grok cannot be removed from the model.
User controls
Deletion: Limited · Opt-out: Limited §11
Delete works. Opting out of inference does not exist.
Honors GPC?
No. §11
Global Privacy Control browser signal: ignored.
Automated decisions
Yes. No human review. §12
For You algorithm · Ad targeting · Visibility filtering / 'freedom of speech, not reach' · Account locks & shadowbans. All algorithmic.
AI training on your data
Yes. EU opt-out only. §1
Your public posts/photos train commercial models.
Children's data
Under 13 blocked · 13–17 limited §8
Ad targeting paused for teens, but content profile still kept.
Breach disclosure
"As required by law." §15.3
Translation: the bare minimum legal window in your jurisdiction.
§5 · The receipts

The receipts, translated.

Five of the worst clauses, lifted verbatim. Strikethroughs are theirs. Marginalia is ours.

X TERMS OF SERVICE · "YOUR RIGHTS AND GRANT OF RIGHTS" (effective Nov 15, 2024) §1
You agree that this license includes the right for us to analyze text and other information you provide and to otherwise provide, promote, and improve the Services, including ↑ "improve the Services" is doing a LOT of work here. the training of our machine learning and artificial intelligence models, whether generative or otherwise.
GROK ATE THAT
X HELP CENTER · "ABOUT CHAT" (XChat encryption) §9
Currently, we do not offer protections against man-in-the-middle attacks. ↑ this is the whole point of E2E. it's the missing part. As a result of a compulsory legal process, X could be required to provide access to the contents of your messages.
TRUST US, BRO
X PRIVACY POLICY · "INFORMATION YOU SHARE WITH US" (verification) §6
If you choose to verify your identity, we may collect a government-issued identification document and biometric information, including facial geometry derived from your image. ↑ 'choose' = the price of a blue check.
ID UPLOAD = FOREVER
X PRIVACY POLICY · "CHANGES TO THIS POLICY" §2
We may revise this Privacy Policy from time to time. By continuing to access or use the Services after those revisions become effective, you agree to be bound by the revised Privacy Policy. ↑ consent without a moment where you got to consent.
OPT-OUT NOT INCLUDED
X PRIVACY POLICY · "HOW LONG WE KEEP INFORMATION" §10
Public content you share on the Services is, by its nature, public; we may retain copies even after you delete the underlying content for legal, safety, and research purposes. ↑ 'research' is where Grok lives.
DELETE = DECORATIVE
§6 · The deceptive design

Dark patterns spotted.

Tricks the policy and surrounding UX use to make you "consent" without really consenting.

01
Forced consent (continued-use clause)
§2
Policy changes apply retroactively to all of your existing data. Continuing to log in is treated as accepting whatever the new owner has decided this quarter — including the November 2024 clause that added AI training.
"By continuing to access or use the Services after those revisions become effective, you agree to be bound by the revised Privacy Policy.
02
Buried, leaky opt-out (Grok training)
§11
The AI-training opt-out lives under Settings → Privacy & Safety → Grok & Third-party Collaborators. Even when toggled off, privacy advocates note the 2026 terms keep a broad license to use your content for 'any purpose,' and opting out never unwinds training already done.
"Allow your public posts as well as your interactions, inputs, and results with Grok and third-party collaborators to be used for training and fine-tuning.
03
Default-on AI training (no re-consent)
§1
Every non-EU account, including ones created years before xAI existed, is opted into Grok training by default, with no fresh consent flow when the policy changed in November 2024.
"...including the training of our machine learning and artificial intelligence models, whether generative or otherwise.
04
Encryption theater (XChat)
§9
XChat is marketed as end-to-end encrypted for everyone, but the private keys are stored on X's servers behind a 4-digit PIN, there is no forward secrecy, metadata is unencrypted, and X's own help page admits it cannot defend against man-in-the-middle attacks and can be compelled to hand over message contents.
"Currently, we do not offer protections against man-in-the-middle attacks.
05
Bundled consent (Premium ID verification)
§6
To get verified, you must hand over biometric data and a government ID together, with no granular consent for how each is processed or retained.
"we may collect a government-issued identification document and biometric information, including facial geometry derived from your image.
06
Trick question (visibility filtering)
§12
'Freedom of speech, not reach' presents shadow-banning as policy clarity, but the criteria for visibility filtering are undisclosed and there is no meaningful appeal.
"Some content may have its visibility reduced in feeds and search, in accordance with our content policies.
§7 · What you can actually do

Your rights, by where you live.

Same company, wildly different rights depending on your jurisdiction. Direct links to the specific opt-out / delete / access flows.

EU (GDPR)
DIFFICULTY: HARD
  • Right of access
  • Right to erasure
  • Right to data portability
  • Right to object to processing
  • Right against solely-automated decisions
  • Carve-out: EU public posts not used to train Grok (regulator-forced)
REQUEST →

Source: §13

California (CCPA/CPRA)
DIFFICULTY: HARD
  • Right to know
  • Right to delete
  • Right to opt-out of 'sale/share'
  • Right to correct
  • Right to limit use of sensitive info
REQUEST →

Source: §13

Default (rest of world)
DIFFICULTY: NIGHTMARE
  • Account deletion (with 30-day reactivation window)
  • Grok opt-out toggle (leaky)
  • Whatever local law forces them to provide
REQUEST →

Source: §11

§8 · Receipts

The actual sources.

Every claim above is anchored to a line in the policy we analyzed. Click any section ID to view it in context.

ANALYZED BY: claude-opus-4-8  ·  PROMPT VERSION: honest-policy-v1.3  ·  ANALYZED AT: 2026-06-05T00:00Z
SOURCE: https://x.com/en/privacy  ·  POLICY VERSION: 2024-11-15  ·  SNAPSHOT HASH:
  • §1
    X Terms of Service · grant of rights / AI training (effective Nov 15, 2024)
    "You agree that this license includes the right for us to analyze text and other information you provide and to otherwise provide, promote, and improve the Services, including the training of our machine learning and artificial intelligence models, whether generative or otherwise."
  • §2
    X Privacy Policy · changes to this policy & continued use
    "By continuing to access or use the Services after those revisions become effective, you agree to be bound by the revised Privacy Policy."
  • §3
    X Privacy Policy · information we collect
    "We collect identifiers, contact information, billing information, and content you share on the Services, including posts, images, and messages."
  • §4
    X Privacy Policy · information from third-party sites, pixels, and embeds
    "We collect information about your interactions with our embedded content and pixels on third-party sites that have integrated X content."
  • §5
    X Privacy Policy · location information
    "We may infer your approximate location from your IP address and collect precise location only when you have granted permission."
  • §6
    X Privacy Policy · identity verification & biometric information
    "If you choose to verify your identity, we may collect a government-issued identification document and biometric information, including facial geometry derived from your image."
  • §7
    X Privacy Policy · advertising and analytics
    "We use the information we collect to deliver and personalize advertising on and off our services."
  • §8
    X Privacy Policy · sharing, affiliates (xAI), and data licensees
    "We share information with our affiliates, including xAI, and with partners who license access to public content through our API."
  • §9
    X Help Center · About Chat (XChat end-to-end encryption)
    "Currently, we do not offer protections against man-in-the-middle attacks. As a result of a compulsory legal process, X could be required to provide access to the contents of your messages."
  • §10
    X Privacy Policy · how long we keep information & deletion
    "Public content you share on the Services is, by its nature, public; we may retain copies even after you delete the underlying content for legal, safety, and research purposes."
  • §11
    X Help Center · Grok & Third-party Collaborators data-sharing setting
    "Allow your public posts as well as your interactions, inputs, and results with Grok and third-party collaborators to be used for training and fine-tuning."
  • §12
    X Privacy Policy · algorithmic ranking, visibility filtering & inferences
    "Some content may have its visibility reduced in feeds and search, in accordance with our content policies."
  • §13
    X Help Center · your privacy rights and choices
    "Depending on your location, you may have rights to access, correct, delete, or object to the processing of your personal data."
  • §14
    FTC · $150M settlement over deceptive use of 2FA data (May 2022)
    "Twitter will pay a $150 million penalty for deceptively using account security data — phone numbers and email addresses collected for two-factor authentication — to target ads, in violation of a 2011 FTC order."
  • §15
    EU DSA fine (Dec 2025), Irish DPC Grok probe (Feb 2026) & X petition to end FTC order (Jun 2026)
    "X was the recipient of the European Commission's first DSA non-compliance decision, fined €120 million; in February 2026 the Irish DPC opened a large-scale GDPR investigation into Grok's generation of sexualized images, and in June 2026 X petitioned the FTC to scrap the longstanding privacy order governing the company."
Flag an issue

X (formerly Twitter) · Grade F

Spotted an error or outdated info? Let us know — we'll review it.

How accurate is this analysis?
Report a shady policy

Know a privacy policy that deserves the treatment? Two ways to tell us:

Option A — Email us

Drop us a line with the company name and policy URL.

✉ report-shady-policies@honestprivacypolicies.org
or
Option B — Quick form