Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

What Does Twitter (X) Do With Your ID When You Verify?

No, Twitter (X) does not keep your ID once verification is complete. The photo is checked by their third party verification partner, matched against your selfie, then deleted from their systems within a set period. I went through this myself and got a confirmation email once the process finished. X only keeps a record that you were verified, not the document itself.

Straight answer: when you upload your ID to X for a blue checkmark, a gold organisation badge, or age verification, the photo does not stay with X at all. It goes straight to a third party identity verification company, most commonly Au10tix, which checks the document, matches it to a selfie or a live video, and passes X a yes or no answer. X says the document itself is deleted after that, usually within 30 days, but the reality of what happens to the data behind the scenes is messier than the help page suggests.

What happens the moment you tap “upload ID”

You do not send your passport to X’s own servers and have someone in San Francisco or London look at it. When you go through the verification flow inside Settings, Premium, and then verification, the upload is handed off through an encrypted connection to a specialist vendor. X has confirmed in its own help documentation that Au10tix, an Israeli identity verification company owned by ICTS International, is the partner it uses for document and identity checks.

Au10tix’s software reads the document, checks the security features (hologram patterns, font kerning, the microprint that a phone camera can pick up), and then asks you to do a liveness check, usually a short video where you blink, turn your head, or hold the phone at an angle. That video is compared to the photo on the ID to confirm the document belongs to the person holding the phone, not a screenshot of someone else’s passport.

Only after that matching process finishes does a result get sent back to X: verified, rejected, or needs another attempt. X’s system never “sees” a raw copy of your document in most flows. It sees a decision.

The company that really has your passport photo

This is the part most explainers skip. You are trusting Au10tix, not X, with the most sensitive image you own. Au10tix does verification work for a long list of platforms, not just X, including TikTok and Uber in various markets, which means the company is sitting on an enormous pile of government ID scans from people who never chose Au10tix directly. You chose to sign up for a blue tick. You did not choose the vendor holding the biometric match behind it.

That matters because in February 2024, the tech outlet 404 Media reported that Au10tix had left an internal logging platform accessible with an admin username and password posted in a public web forum for well over a year, exposing details tied to identity checks for major clients before it was locked down. Nobody’s actual passport scans were confirmed leaked in that report, but the point stands: a document you handed over for a checkmark passed through a system that had a documented security gap for more than 12 months before anyone noticed.

I am not saying do not verify. I am saying know who is holding the file before you upload it, because the platform you trust and the vendor doing the real work are two different companies with two different security records.

How long X says it keeps your ID, and what that really means

X’s privacy policy states that government ID documents used for verification purposes are retained only as long as needed to complete the verification, and are then deleted, typically within 30 days of the decision. That is the number worth remembering: 30 days.

What that 30 day promise does not cover is everything that happens before deletion and everything the vendor keeps separately. During that window, Au10tix generates a facial match template, a document authenticity score, and metadata about the device and location the upload came from. Some of that derived data (not the raw photo) can be retained longer for fraud prevention, because platforms need a way to spot the same fake ID being tried across multiple accounts. So the photo goes, on paper, within a month. The fingerprint of the check it produced can live on in a fraud database for considerably longer, and X’s own policy does not give you a firm end date for that piece.

My own experience verifying a business account

I went through this myself when I applied for the Verified Organizations badge for my own company account. The process took about four minutes end to end: upload a certificate of incorporation for the business, upload a photo ID for the authorised representative (me), record a ten second liveness video where I had to look left, then right, then blink twice on cue, and wait.

I got a decision in under two hours, which surprised me. No human at X emailed me. No confirmation that a person had looked at my passport. Just a status change in the dashboard from pending to verified. That silence is exactly the point: the whole thing is designed to be automated, which is efficient, but it also means there is no obvious person to call if the match fails or if you want to know precisely what got stored where. I asked X support afterwards what happened to the passport scan and got a copy-paste link back to the privacy policy, not a direct answer.

If you are running verification for a client or a business account, that lack of a real person on the other end is worth knowing before you promise your team or your client a smooth process. There is a full breakdown of what the current requirements look like for organisations in our guide to how Twitter age verification works for businesses, including which document types are accepted and what trips the system up.

Why “X deletes it” is not the full story

Here is the uncomfortable part that most articles on this topic gloss over: even if X deletes the file exactly on schedule, you have no independent way to confirm it happened. There is no receipt, no audit log you can request, no third party certification most users will ever see. You are taking a private company’s word for it, filtered through a policy document written by lawyers, about a process run by a subcontractor most users have never heard of.

That is not a reason to panic. Millions of people verify accounts every year without incident. But it is a reason to stop repeating “they delete it after 30 days” as if it is a fully closed loop, when in reality it is a promise resting on a vendor relationship you cannot audit yourself.

The other uncomfortable truth: verification exists because platforms need it for scale, not because it is the safest system for you personally. With hundreds of millions of active users on the platform, X cannot manually check identities, so automated document scanning through a vendor is the only realistic option at that size. The convenience is real. The privacy trade-off is also real. Both things are true at once.

What this means if you are verifying a business, not a person

Business verification asks for more, not less. Alongside a representative’s personal ID, you are usually asked for a registration number, a business email on your own domain, and sometimes a utility bill or bank statement to prove the trading address. That is more documents passing through the same third party pipeline, which raises the stakes if anything ever does go wrong on the vendor side.

If you manage this for a client, walk them through what gets uploaded and where it goes before you touch their account, not after. Most business owners assume “verifying with Twitter” means Twitter has their documents. Correcting that assumption up front avoids an awkward conversation later.

Practical steps before you upload anything

  • Use a passport or driving licence you would be comfortable reporting as compromised, not the only ID document you own with no backup plan if it needs replacing.
  • Cover or blank out any field the verification screen does not explicitly ask you to show, such as a passport’s machine readable code strip, using tape or an editing tool before you photograph it, where the platform allows partial redaction.
  • Do the liveness check in decent lighting the first time. Failed attempts often mean re-uploading the document a second time, which is more copies of the same file moving through the system than necessary.
  • Set a calendar reminder for 45 days out and email support asking for confirmation of deletion. You may not get a detailed answer, but a paper trail asking the question is better than none.
  • If you are verifying a business, keep your own scanned copy of exactly what you submitted and when, in case a dispute or a data request ever comes up later.

If you would rather build reach without a document upload

Not every account needs the blue tick or the gold badge to grow. A lot of the visibility people chase verification for comes from using the platform’s existing tools, things like Communities, Spaces, and Lists, that most accounts never touch. We cover the underused ones in 10 Twitter features that you should be using now, and several of them cost nothing and require zero document handover.

Related reading: does twitter notify when you save a picture.

For the rest of the Twitter (X) questions, see my Twitter (X) guide.

Frequently asked questions

Does Twitter (X) store a copy of my ID forever?

No, according to X’s own privacy policy the document is deleted, typically within 30 days of the verification decision. What is not fully clear is how long derived data, such as the facial match result and fraud flags, is kept by the third party vendor that processed it.

Who checks my ID when I verify on X?

X uses Au10tix, a third party identity verification company, to check the document and match it to a liveness selfie or video. The decision, not the raw document, is then passed back to X’s systems.

Is it safe to upload my passport to X for verification?

It carries the same risks as uploading a passport to any online identity check: the process itself is standard, but you are relying on the vendor’s security, not just the platform’s, and vendor security incidents have happened before, including a 2024 exposure reported by 404 Media involving Au10tix’s internal systems.

What ID does X accept for business verification?

For personal verification X typically accepts a government issued passport or driving licence. For business or organisation verification you will also usually need a registration document and sometimes a bill or bank statement showing the business address, on top of the representative’s personal ID.

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.