This provision states that X associates devices and browsers with user accounts, including devices not directly used to sign in, and may infer identity by associating accounts with hashed email addresses that share components with the user's registered email address.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes that X performs cross-device and cross-browser identity inference, including for signed-out users, and uses hashed email component matching for identity association. These practices affect the scope of data linkage and profiling that occurs even when users are not actively signed in to the platform.
⚠ If users do not adjust applicable settings, X may associate their accounts with additional browsers and devices and infer identity connections using email address component hashing as described in the policy.
Cross-platform context
See how other platforms handle Inferred Identity Across Devices and Browsers and similar clauses.
Compare across platforms →"When you sign into X on a browser or device, we will associate that browser or device with your account. Subject to your settings, we may also associate your account with browsers or devices other than those you use to sign into X (or associate your signed-out device or browser with other browsers or devices or X-generated identifiers). When you provide other information to X, including an email address or phone number, we associate that information with your X account. Subject to your settings, we may also use this information in order to infer other information about you and/or your identity, for example by associating your account with hashes of email addresses that share common components with the email address you have provided to X.Excerpt from X's Privacy Policy
REGULATORY LANDSCAPE: Cross-device tracking and identity inference practices implicate GDPR provisions on profiling and automated decision-making, as well as CCPA's definitions of personal information and cross-context behavioral advertising.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause establishes that X performs cross-device and cross-browser identity inference, including for signed-out users, and uses hashed email component matching for identity association. These practices affect the scope of data linkage and profiling that occurs even when users are not actively signed in to the platform.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.