This provision states that X may associate a user's account with browsers and devices beyond those used to sign in, including signed-out devices, and may infer identity by linking hashed email addresses with common components to a user's account.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes that X's identity inference and cross-device tracking practices extend to signed-out users and to probabilistic email address matching, which has implications for the scope of data processing disclosed to users and may require evaluation under GDPR's transparency and purpose limitation principles.
⚠ The terms permit X to associate the user's account with additional browsers, devices, and inferred identity data as described unless the user adjusts relevant account settings
Cross-platform context
See how other platforms handle Inferred Identity and Cross-Device Association and similar clauses.
Compare across platforms →"Subject to your settings, we may also associate your account with browsers or devices other than those you use to sign into X (or associate your signed-out device or browser with other browsers or devices or X-generated identifiers). When you provide other information to X, including an email address or phone number, we associate that information with your X account. Subject to your settings, we may also use this information in order to infer other information about you and/or your identity, for example by associating your account with hashes of email addresses that share common components with the email address you have provided to X.Excerpt from X's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR's transparency and purpose limitation requirements, CCPA's disclosure obligations for inferences drawn about consumers, and FTC guidance on cross-device tracking and deceptive identity inference practices.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause establishes that X's identity inference and cross-device tracking practices extend to signed-out users and to probabilistic email address matching, which has implications for the scope of data processing disclosed to users and may require evaluation under GDPR's transparency and purpose limitation principles.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.