Skip to main contentSkip to footer
All companies
Privacy PolicyAnalyzed 2026-08-30

X (Twitter)

62score
Risk level
Medium Risk

Weighted across nine legal categories. Lower is worse.

Executive summary

This document is strictly a Privacy Policy rather than a comprehensive Terms of Service, resulting in several critical consumer-protection categories being entirely absent. While it demonstrates strong regulatory compliance frameworks (GDPR, CCPA, DPF) and provides basic data controls, it relies on overly broad data collection for AI training, lacks transparent account termination procedures, and omits essential billing and liability safeguards. Consumers should consult the separate Terms of Service for complete contractual rights and risks.

Category breakdown

6 of the nine categories are not addressed by this document, so they are left out rather than scored.

User Accounts

Registration, suspension, and termination

45

Account suspension and termination lack specific violation criteria, notice periods, or appeal processes, while indefinite retention of identifiers for banned users poses a significant consumer risk.

Key findings

  • Vague 'violate our Rules' trigger for suspension
  • Indefinite retention of email/phone for banned accounts
  • 30-day restoration window only

Evidence from the document

Where you violate our Rules and your account is suspended, we may keep the identifiers you used to create the account (such as your email address or phone number) indefinitely to prevent repeat policy offenders from creating new accounts.

Recommendations

  • Define specific, objective grounds for suspension
  • Provide written notice and a reasonable cure period before termination
  • Limit identifier retention to legally required durations

Data Privacy

Data collection, usage, and protection

65

The policy provides robust regulatory compliance frameworks and user controls, but suffers from overly broad data collection for AI training, extensive third-party sharing, and lengthy retention periods that lower consumer safety.

Key findings

  • Explicit GDPR/CCPA/OCPA compliance and DPF participation
  • Broad AI training permissions for third parties
  • Cookies retained up to 13 months; ad data up to 12 months

Evidence from the document

If you do not opt out, in some instances the recipients of the information may use it for their own independent purposes in addition to those stated in X’s Privacy Policy, including, for example, to train their artificial intelligence models, whether generative or otherwise.
We generally collect device information, location information, inferred identity information and log information using cookies. We keep cookies and information collected using cookies for up to 13 months.

Recommendations

  • Narrow AI training consent to explicit opt-in
  • Reduce cookie and interaction data retention periods
  • Clarify third-party data usage restrictions

Modification of Terms

How agreements can be changed

70

Material changes require notice and a pre-continuation review opportunity, but the unilateral determination of what constitutes a 'material' change and the lack of a fixed notice period weaken consumer safeguards.

Key findings

  • Notice required for material changes
  • Company unilaterally defines 'material'
  • No fixed advance notice window or explicit rejection right

Evidence from the document

If we do revise this Privacy Policy and make changes that are determined by us to be material, we will provide you notice and an opportunity to review the revised Privacy Policy before you continue to use X.

Recommendations

  • Specify a minimum 14-30 day advance notice period
  • Remove unilateral discretion over what qualifies as material
  • Grant explicit right to terminate with pro-rated refund upon objection
Read the source documentSee the full interactive report

Ex-TerCo provides automated analysis of legal documents for informational purposes. This is not legal advice. Terms can change at any time.