Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision states that X may associate a user's account with browsers and devices beyond those used to sign in, including signed-out devices, and may infer identity by linking hashed email addresses with common components to a user's account.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes that X's identity inference and cross-device tracking practices extend to signed-out users and to probabilistic email address matching, which has implications for the scope of data processing disclosed to users and may require evaluation under GDPR's transparency and purpose limitation principles.
⚠ The terms permit X to associate the user's account with additional browsers, devices, and inferred identity data as described unless the user adjusts relevant account settings
Cross-platform context
See how other platforms handle Inferred Identity and Cross-Device Association and similar clauses.
Compare across platforms →Monitoring
X has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Subject to your settings, we may also associate your account with browsers or devices other than those you use to sign into X (or associate your signed-out device or browser with other browsers or devices or X-generated identifiers). When you provide other information to X, including an email address or phone number, we associate that information with your X account. Subject to your settings, we may also use this information in order to infer other information about you and/or your identity, for example by associating your account with hashes of email addresses that share common components with the email address you have provided to X.Excerpt from X's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR's transparency and purpose limitation requirements, CCPA's disclosure obligations for inferences drawn about consumers, and FTC guidance on cross-device tracking and deceptive identity inference practices. The Irish DPC has authority for EU and EEA users; the FTC has authority for US users. 2) GOVERNANCE EXPOSURE: Medium. Cross-device tracking and probabilistic identity inference are common industry practices but carry regulatory exposure, particularly in the EU where GDPR requires a clear lawful basis for inferred data processing. The association of hashed email components to infer identity may constitute profiling under GDPR, triggering additional transparency and objection rights for EU users. 3) JURISDICTION FLAGS: EU and EEA users may have rights to object to profiling under GDPR. California residents are entitled under CCPA to know about inferences drawn about them and to request deletion of inferred data. The policy references Your X Data as a mechanism to review inferred information, which may partially address these disclosure requirements. 4) CONTRACT AND VENDOR IMPLICATIONS: Advertisers and analytics partners who receive X-generated identifiers or cross-device data should assess whether their data processing agreements with X accurately reflect the scope of inferred data flows. B2B customers should evaluate whether cross-device association affects their own privacy notice obligations to end users. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that user-facing settings actually prevent cross-device association and identity inference as described, and that the settings are adequately disclosed. Data mapping exercises should capture inferred identity as a distinct data category. For EU and EEA deployments, the lawful basis for profiling-adjacent identity inference should be documented, and a legitimate interest assessment may be warranted.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause establishes that X's identity inference and cross-device tracking practices extend to signed-out users and to probabilistic email address matching, which has implications for the scope of data processing disclosed to users and may require evaluation under GDPR's transparency and purpose limitation principles.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.