X (Twitter)
X (Twitter) is a major social media platform with significant data collection practices, including extensive behavioral tracking, location data harvesting, and ad ecosystem integration. While the app uses HTTPS encryption, the backend data sharing, lack of end-to-end encryption for DMs, and aggressive monetization create moderate privacy risks.
Data Breach: Twitter
In 2022, 5.4 million X (Twitter) user records were exposed due to an API vulnerability, linking email addresses and phone numbers to accounts.
Regulatory & Legal
2022 data breach exposed 5.4M user email addresses and phone numbers. 2023 API abuse allowed unauthorized data scraping. Ongoing concerns about post-acquisition privacy governance.
How we got to 52.
Firebase, Mixpanel, Segment, and proprietary telemetry track engagement and content consumption
AdMob, AppLovin, and historically Meta Audience Network enable cross-app profiling
User data retained indefinitely; shared with law enforcement and business partners
GPS and IP-based location for ad targeting and trending topics
DMs are not end-to-end encrypted - X servers can access content
X Premium paywall with countdown timers and algorithmic suppression of free posts
Privacy team reductions since 2022; transparency reports less frequent
Detailed privacy policy, GDPR data subject rights, Data Download tool
Hidden inside the code.
What it asks for.
Precise GPS for location-targeted ads and trending topics
Contact list uploaded as hashes for friend discovery
Required for Spaces and video posting, but increases data surface
Keep reading.
The spyware detection ritual is broken
Standard spyware detection advice misses the point. The real surveillance on your phone is already installed, sold as fe...
What trackers are actually hiding in your apps
We scanned 32 of the most-installed Android apps and counted every embedded tracker SDK. The average app hides 5 tracker...
Similar risk profiles.
Scan X (Twitter) yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.