data report card

Data Report Card · X

X Data Report Card

X · formerly Twitter
§ Enforcement action
Data
Practices
2Access2Portability2Friction1Deletion0Sells0Trains AI
=
D
§
5/12
Agent
Readiness
2Access 2Portability 1API access
=
B
5/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

§ This grade reflects a 2-point deduction (severity 1) for a verified regulatory action: 7/12 on data practices − 2 = 5/12D. The enforcement record is below.

Help me make a request →
Reviewed Jun 2026 · policies are checked weekly for changes  ·  stated — every cell is read from X's published policy; none has been tested (run by us) yet.
2Accessstated
Free self-serve archive covering tweets, DMs, media, followers, lists and ad data via Settings → Your account → Download an archive of your data.
X Help — Accessing your X data · accessed Jun 2026 ↗
2Portabilitystated
Archive is a ZIP containing an HTML index plus per-section .js / JSON data files (tweets, DMs, ad data, etc.), machine-readable.
X Help — Accessing your X data · accessed Jun 2026 ↗
2Frictionstated
Self-serve request typically ready in 24–48 hours (occasionally a few days for very active accounts); download link expires after 7 days.
X Help — Accessing your X data · accessed Jun 2026 ↗
1Deletionstated
Deletion is a two-step deactivation followed by a 30-day grace period; if you don't log in during that window the account is permanently deleted, though X retains some data per policy.
X Privacy Policy (Jan 2026) · accessed Jun 2026 ↗
0Sells / sharesstated
X shares data with advertisers and "third-party collaborators" for cross-context behavioral advertising; GPC honoring is not clearly affirmed in policy and applies only to the California ad pixel.
X Privacy Policy (Jan 2026) · accessed Jun 2026 ↗
0Trains AIstated
X’s own help page states "X may share with xAI your public X data as well as your user interactions, inputs and results with Grok on X to train and fine-tune Grok," on by default with an opt-out at Settings > Privacy & Safety > Grok & Third-party Collaborators.
X Help Center — About Grok · accessed Jun 2026 ↗
§Enforcement action — deducts 2 points (severity 1); data practices without the penalty scored C (7/12)verified
The FTC and DOJ fined Twitter (now X) $150 million in May 2022 for using phone numbers and email addresses collected for account security to target advertising.
US Federal Trade Commission · 25 May 2022 ↗
1API access — feeds Agent Readiness, not the /12stated
X's API v2 supports OAuth 2.0 with refresh tokens to read your own posts and profile, but read access is paid: the API runs on credit-based pay-per-usage pricing with no usable free read tier.
X — About the X API · accessed Jun 2026 ↗
X offers an excellent free, fast, machine-readable archive but its broad ad-sharing and opt-out-by-default Grok training pull the privacy dimensions down. Source-verified Jun 2026; all cells stated (read from published policy/support docs), none yet tested via live export.

Events

Breaches, policy changes, and export-format changes we’ve recorded at X — other parties’ actions, alongside the enforcement record above. An event never changes a grade by itself. All events →

No events on record for X.

Grade history

Every change to this company’s grade since it was first published, and why. All grade changes →

30 Aug 2026Trains AI on your datasource

This cell cited xAI’s privacy policy, and the SpaceXAI policy that replaced it (event ev-2026-0001) states Grok on X is governed by X’s own policy. Re-sourced to X’s own help page, which states X may share public posts and Grok interactions with xAI for training, on by default with a settings opt-out. Score unchanged at 0.

X Help Center — About Grok ↗Followed a published event →
Previously: xAI Privacy Policy (April 2026)

How to request your data from X

  1. Go to https://x.com/settings/download_your_data — X's data-request entry point.
  2. Sign in → confirm your password → Request archive (your posts and account data).
  3. Expected wait: usually 24–48 hours (link expires after 7 days) — X's stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact X — Privacy: https://privacy.x.com/en.

These steps reflect X's documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.