Provision record
X · X Privacy Policy · View original document ↗

Inferred Identity Across Devices and Browsers

Medium severity Unique · 0 of 352 platforms
Stay ahead of the changes
Track X and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

This provision states that X associates devices and browsers with user accounts, including devices not directly used to sign in, and may infer identity by associating accounts with hashed email addresses that share components with the user's registered email address.

ⓘ

This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This clause establishes that X performs cross-device and cross-browser identity inference, including for signed-out users, and uses hashed email component matching for identity association. These practices affect the scope of data linkage and profiling that occurs even when users are not actively signed in to the platform.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Review and adjust X's privacy settings related to device and browser association and identity inference, accessible through account settings under Privacy and Safety.

If You Do Nothing

⚠ If users do not adjust applicable settings, X may associate their accounts with additional browsers and devices and infer identity connections using email address component hashing as described in the policy.

Cross-platform context

See how other platforms handle Inferred Identity Across Devices and Browsers and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
When you sign into X on a browser or device, we will associate that browser or device with your account. Subject to your settings, we may also associate your account with browsers or devices other than those you use to sign into X (or associate your signed-out device or browser with other browsers or devices or X-generated identifiers). When you provide other information to X, including an email address or phone number, we associate that information with your X account. Subject to your settings, we may also use this information in order to infer other information about you and/or your identity, for example by associating your account with hashes of email addresses that share common components with the email address you have provided to X.

Excerpt from X's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: Cross-device tracking and identity inference practices implicate GDPR provisions on profiling and automated decision-making, as well as CCPA's definitions of personal information and cross-context behavioral advertising.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has addressed cross-device tracking and identity inference practices in the context of consumer privacy and unfair or deceptive practices.
    File a complaint →

Provision details

Document information
Document
X Privacy Policy
Entity
X
Document last updated
May 5, 2026
Tracking information
First tracked
Sept. 22, 2026
Last verified
Sept. 22, 2026
Record ID
CA-P-00030003
Document ID
CA-D-00030
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
edf76eaa067519848cb54fba209bc01ecbfa7d3226be11cd5b9ab14e9555769e
Analysis generated
September 22, 2026 01:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: X
Document: X Privacy Policy
Record ID: CA-P-00030003
Captured: 2026-09-22 01:55:42 UTC
SHA-256: edf76eaa06751984…
URL: https://conductatlas.com/platform/x/x-privacy-policy/inferred-identity-across-devices-and-browsers/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does X's Inferred Identity Across Devices and Browsers clause do?

This clause establishes that X performs cross-device and cross-browser identity inference, including for signed-out users, and uses hashed email component matching for identity association. These practices affect the scope of data linkage and profiling that occurs even when users are not actively signed in to the platform.

Is ConductAtlas affiliated with X?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.