Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

What Twitter (X) Does With Your Personal ID Data

If you are skim reading
The short version: when you hand Twitter (X) a photo of your passport or driving licence for age or identity verification, that image goes through a third-party vendor for a facial and document match, then X keeps a record that you were verified plus your stat

The short version: when you hand Twitter (X) a photo of your passport or driving licence for age or identity verification, that image goes through a third-party vendor for a facial and document match, then X keeps a record that you were verified plus your stated birth date, and both feed into ad targeting, safety enforcement and, since 2023, the training data for its AI model Grok. Deleting your account does not delete this immediately. Some of it sits in backend logs for weeks after you think it is gone.

Why Twitter even wants your ID in the first place

For years X only asked for ID in narrow cases: getting the blue checkmark back when it briefly meant something, appealing a suspended account, or proving you were a real business for ad billing. That has changed. The UK's Online Safety Act and similar EU rules now push platforms toward age assurance, meaning X has to make a reasonable effort to know whether you're over 18, not just take your word for it when you signed up at 13 and typed in a random birth year.

So X rolled out age verification that, for some UK and EU accounts flagged as possibly underage or accounts that want to see sensitive content, asks for either a selfie video (matched against an age-estimation model) or an ID upload. I wrote a longer breakdown of exactly which countries this applies to and why it's inconsistent in this piece on whether X requires age verification everywhere, and the short answer is no, it's patchy and depends heavily on where your account and IP address are registered.

What happens to the ID once you upload it

X does not build its own facial recognition and document-checking system from scratch. Like most platforms doing age assurance at scale, it routes the verification through a specialist vendor. Yoti has been the partner most publicly named for age estimation on X, and Au10tix (an Israeli identity verification firm, which I have a soft spot for given my own base is partly in Israel) has handled document checks for X in the past for account verification.

Here's the process step by step, based on X's own help centre documentation and the vendor privacy notices linked from it:

  • You upload a photo or scan of a government ID, or record a short selfie video.
  • The image or video is sent to the third-party vendor's servers, not stored permanently on X's own infrastructure in most cases.
  • The vendor runs a match: does the face in the selfie match the ID photo, or does the age-estimation model put you above or below the threshold.
  • The vendor sends X a result, usually just "verified over 18" or "verification failed", not the raw document.
  • X logs the outcome and the date against your account, and (per its privacy policy) may retain the fact of verification for the life of the account plus a retention window after deletion.

The reassuring bit is that X's help documentation says the actual ID image is typically deleted from the vendor's systems within 30 days once the check is done. The less reassuring bit is that "typically" is doing a lot of work in that sentence, and there is no independent audit that most users will ever see confirming it happened for their specific document.

A real example: what happened when I tried to close a legacy account

A couple of years back I helped a client wind down an old brand Twitter account, one of those accounts that had picked up a blue tick years earlier back when that meant something and had submitted a driving licence to prove the business was legitimate. We wanted it gone completely, name, ID, everything, before the brand rebrand launched.

We submitted a deactivation request. Thirty days later the account was gone from public view. Fine. But when we later requested X's full data export under a GDPR data subject access request (any UK or EU user can do this, it's a legal right, not a favour), the export that came back six weeks after the account had "disappeared" still listed a verification event from that driving licence check, timestamped, with the result flag, sitting in what X called account metadata. The image itself wasn't in there. The fact that a real, specific person had proven their identity on that account was.

That's the bit most articles about "Twitter privacy" skip past. Deactivating or deleting your account stops other people seeing your tweets. It does not mean the identity trail evaporates on day 31. Some fields get anonymised, some get bundled into aggregate analytics, and some, per X's own retention schedule, can sit around for up to 18 months in backup systems for legal and fraud-prevention purposes. If your identity data touched their systems once, treat it as touched for a long time, not gone.

The uncomfortable part nobody likes saying out loud

Here's the bit that sits uneasily with the "we're just keeping kids safe" framing that platforms use whenever age verification comes up. The infrastructure built to check whether you're over 18 is the exact same infrastructure that feeds targeting and monetisation. Once X has a confirmed birth date and a confirmed real identity behind an account, that account becomes more valuable to advertisers, not less. A verified adult in a confirmed age band with a confirmed location is a cleaner, more sellable data point than an anonymous handle guessing at a birth year.

Nobody at X is going to put it this bluntly in a press release, but the commercial incentive and the safety incentive point in the same direction: get more accounts tied to real, verified identities. That's not necessarily sinister, but it means the "we only use it for safety" line, which most coverage of this topic repeats without pushing on, is only half the story.

The same pattern shows up in X's 2023 policy update, which gave itself explicit permission to use public posts and account data (including inferred age and location signals) to train Grok, its AI model. You can opt out in your privacy settings under "Grok" but the setting defaults to on, and most people never find it because it's buried three menus deep, not on the main privacy page most people check once and never revisit.

What data X holds against your identity

Beyond the ID verification result itself, X's data categories (per its own privacy policy, last meaningfully rewritten in 2024) include:

  • Your stated birth date, plus any age estimation result if you went through facial age checks instead of ID upload.
  • Device and browser fingerprints tied to your account, used to spot ban evasion and to link accounts even when you change your username, which doesn't reset your underlying account ID or history at all.
  • Your IP address history, used to infer country and, at a rough level, city.
  • Phone number and email used for signup, even if you later remove them from your public profile.
  • Behavioural signals like what you've watched, which ties into the platform's watch history tracking, a feature most users don't realise persists and feeds recommendations even when they think their activity is "private".
  • Payment details for anyone who's ever bought X Premium, ad credits, or tipped a creator.

Individually none of this feels alarming. Stacked together against a confirmed real identity from an ID check, it's a fairly complete profile of who you are, where you are, and what you do, sitting behind a username that could be swapped out overnight.

How to check and limit what X holds on you

You have more control here than most people use. Concrete steps, in order of how much effort each takes:

  • Go to Settings and Privacy, then Your Account, then Download an Archive of your Data. This gives you the same export I used for that client's account, and it's the single best way to see what's logged against you.
  • Check Settings, Privacy and Safety, Data Sharing and Off-X Activity, and turn off "Allow additional information sharing with business partners" if it's on, which it usually is by default.
  • Find the Grok data usage toggle under Privacy and Safety, Grok, and switch off using your posts for training if you'd rather not contribute.
  • If you're in the UK or EU, submit a formal Subject Access Request through X's privacy contact form rather than relying on the self-serve export, because the formal request legally obliges a fuller response within one month.
  • Remove your phone number from the account once you no longer need it for two-factor login recovery, since it's one of the strongest identity linkers X holds.

None of this is complicated. Most people simply never open these menus because the platform doesn't put them anywhere near the surface.

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

Why this matters more if you run a business account

If you're using X to build a brand, the identity question isn't just a personal privacy worry, it's a business risk. Verified business accounts tied to a real ID mean a support ticket dispute, a copyright claim, or a compliance request can pull a real name and address into the process fast. I've seen agencies get caught out here, assuming a "company" handle kept the humans behind it anonymous, only to find X's records tied the account straight back to whoever completed the original verification years earlier.

If audience ownership and reducing platform risk matter to you, this is also exactly why I keep telling clients not to build a business entirely on rented platform ground. An email list is data you own, with no third-party vendor sitting between you and your audience, no algorithm change, and no identity verification requirement that could freeze your access overnight.

And if this whole area, what your platforms hold, what they share, and how to bring that risk down while still using AI tools sensibly, feels like more than you want to untangle alone, it's the kind of thing an AI consultant for small business should be walking through with you as part of a wider data and platform audit, not treating as a footnote.

Related reading: does twitter save your selfie.

Related reading: does twitter notify if you save a picture.

Related reading: my twitter replies are hidden.

Related: writing for us on data analytics.

Frequently asked questions

Does Twitter (X) delete my ID photo after verification?

X's help documentation says the uploaded ID image is typically deleted from the verification vendor's systems within 30 days of the check being completed, but the fact that you were verified, along with the confirmed age result, stays logged against your account for as long as the account exists and often for a retention period after you delete it.

Can I use Twitter without ever submitting ID?

Yes, for most accounts and most countries you can use X without ever uploading ID, since verification is currently triggered mainly by specific flags: appealing a suspension, restoring a legacy blue tick, business ad account verification, or being flagged for age assurance in a country enforcing rules like the UK's Online Safety Act.

Does deleting my Twitter account remove my identity data completely?

Not immediately and not always completely. Public content and profile visibility disappear within about 30 days of deactivation, but backend metadata including verification results and device history can remain in X's systems for a further retention window, sometimes referenced as up to 18 months for fraud and legal-compliance purposes.

Does Twitter use my ID or age data to train its AI?

X's 2023 privacy policy update gives it permission to use account data, including inferred age and public posts, to train its AI model Grok, and this setting defaults to on. You can turn it off manually under Settings, Privacy and Safety, Grok, though the option is buried deep enough that most users never find it.

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.