← Social Media
D

Twitter / X

80% of safety engineers fired. Head of safety smeared and driven from his home. CSAM detection broken. Grok trains on everything you post with no opt-out.
Serious concerns
xAI · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.twitter.android
Manufacturer: X Corp / xAI

⚠️ The bottom line

Grok's image generator was creating over 6,000 non-consensual sexualised deepfakes per hour — many of women and children. Canada's Privacy Commissioner found X launched the tool without even completing a safety assessment. X's response: it's the users' fault, not ours. The privacy assessment they were required to do? Finished 8 months late. Musk fired 80% of safety engineers. The Head of Safety resigned and Musk accused him of supporting pedophilia — a lie that forced him to flee his home after death threats. 62,000 banned accounts came back. Nobody was in charge of safety for over a year.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Kids at risk
Honesty
4/4 EXTREME
Can I trust what they say?
Kids at risk
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
1Critical
7High
2Medium
10Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚡ highfirmware analysis vs policy claims
200 million email addresses posted online for less than two dollars. Anonymous handles linked to real identities — journalists and activists in authoritarian countries exposed. A separate bug showed private tweets publicly. This happened after Musk fired most of the security team.

What they claim: X protects user data with security measures.

What we found: 200M+ emails leaked for <$2 (Jan 2023) from 7-month vulnerability. Could unmask dissidents worldwide. Circle bug: private tweets shown publicly. 2.8B record dataset (2025). All after firing 80% of engineering.

⚡ highpolicy claims vs firmware analysis
Musk says hate speech is down 30%. A peer-reviewed study found it's up 50%. Transphobic slurs tripled. The N-word jumped 500% in the first 12 hours. Posts calling LGBT people 'groomers' doubled. The science contradicts his claim.

What they claim: X claims hate speech impressions are '30% lower.'

What we found: Peer-reviewed PLOS One (Berkeley, 1M+ tweets): hate speech 50% higher. Transphobic slurs tripled (115 to 418/week). N-word 500% increase in 12 hours. 'Jew' 5x increase. LGBT+'grooming' up 119%. Engagement with hate up 70%.

⚫ mediumfirmware analysis vs policy claims
The open-sourced algorithm revealed Musk built himself a special category and paying users get 4x the reach. It pushes right-wing content in almost every country. Even neutral accounts — people following nobody political — see right-leaning content by default.

What they claim: 'We open-sourced the algorithm for transparency.'

What we found: Code revealed: Musk has own special category. Paid users get 2x-4x boost. Ad algorithm and training data omitted. Algorithm amplifies right-wing content in 6/7 countries. Neutral accounts show right-leaning default bias.

Data Sharing 2/4 MODERATE 2 findings
⚡ highpolicy claims vs firmware analysis
X silently turned on AI training for everyone, hid the off switch, then removed it. The new terms say using X is your payment — your data belongs to Musk's AI company forever. There's no opt-out. Ireland had to get a court order to stop it for Europeans.

What they claim: 'Your privacy matters to us.' X privacy policy.

What we found: Grok AI training enabled by default (July 2024), buried in settings, mobile opt-out initially broken. Nov 2024 ToS: opt-out removed entirely. 'Access to the service is sufficient compensation.' No public/private distinction. xAI acquired X ($33B, March 2025). Ireland DPC obtained court injunction for EU users.

⚡ highmarketing vs regulatory
X is asking the US government to remove its only binding privacy check — a consent order imposed because Twitter used phone numbers submitted for security to target ads. The reason? X wants to feed user data into Grok AI without constraint. The company that violated your trust wants its punishment removed so it can do more with your data.

What they claim: X claims it has established a "world class" privacy and data protection program

What we found: On June 3, 2026, X filed a petition asking the FTC to terminate its 2022 privacy consent order — originally a $150M settlement for misusing phone numbers submitted for 2FA to target ads. X explicitly tied the petition to building Grok AI, arguing the order stymies "American leadership in artificial intelligence." FTC opened a 30-day public comment period.

Security 3/4 HIGH 3 findings
⚡ highfirmware analysis vs policy claims
Musk fired 80% of safety engineers. The Head of Safety resigned and Musk accused him of supporting pedophilia — a lie that forced him to flee his home after death threats. 62,000 banned accounts came back. Nobody was in charge of safety for over a year.

What they claim: 'Strong commitment to content moderation remains absolutely unchanged.' Elon Musk, October 2022.

What we found: Safety engineers: 279 to 55 (80%). Moderators halved. 62,000 banned accounts reinstated. Yoel Roth smeared with baseless pedophilia accusation by Musk, forced to flee home. Replacement resigned after 7 months. No Head of Safety for over a year. Response times: abusive DMs slowed 70%.

⚡ highfirmware analysis vs regulatory findings
Musk called fighting child abuse his top priority, then stopped paying the company that detects it. Over 100 accounts selling child abuse material found by researchers. The same hashtags flagged in 2023 were still active in 2025.

What they claim: 'Priority #1' is fighting CSAM. Elon Musk, December 2022.

What we found: Thorn (CSAM detection) terminated contract after X stopped paying. Stanford: 128 accounts selling CSAM, broken PhotoDNA. Same hashtags active June 2025 — 2 years later. Canadian Centre: 'woefully insufficient.'

⚫ mediumfirmware analysis vs regulatory findings
The blue checkmark used to mean 'this person is real.' Now it means 'this person paid $8.' The EU fined X EUR 120 million because the system helps scammers look legitimate. They blocked 95.8% of researchers from accessing data.

What they claim: 'Verification improves authenticity.'

What we found: Legacy verification replaced with $8/month pay system. EU: 'dark patterns' misleading users. EUR 120M DSA fine (first enforcement). 95.8% of researcher applications rejected. Malicious actors exploit paid checkmarks.

Honesty 4/4 EXTREME 2 findings
⚠️ criticalmarketing vs regulatory
Grok's image generator was creating over 6,000 non-consensual sexualised deepfakes per hour — many of women and children. Canada's Privacy Commissioner found X launched the tool without even completing a safety assessment. X's response: it's the users' fault, not ours. The privacy assessment they were required to do? Finished 8 months late.

What they claim: X claims to prioritise user safety and take action against abuse

What we found: On June 11, 2026, Canada's Privacy Commissioner found X Corp. and xAI violated PIPEDA by launching Grok Imagine without adequate safeguards. The tool generated over 6,000 sexualised deepfake images per hour, many targeting women and children. The privacy impact assessment wasn't completed until March 2026 — months after the tool's July 2025 launch. X's defence: users are responsible, not the platform.

⚡ highpolicy claims vs regulatory findings
Everyone responsible for FTC compliance quit or was fired. Musk almost broke the rules but employees stopped him. Already fined $150 million for using your phone number for ads. Under Trump, Musk's people are inside the FTC and investigations have stopped.

What they claim: 'We take our obligations under the FTC consent decree seriously.'

What we found: Security, privacy, compliance heads all departed. 'He puts rockets into space, he's not afraid of the FTC.' 350+ FTC demands. Almost violated decree — employees stopped him. $150M fine for using security phone numbers for ads. Trump: DOGE staffers at FTC, investigations stalled.

Latest Risks & Threats
New developments that compound existing privacy concerns. 1 emerging risk.
RISK X Money 💰 Finance Announced 2025-02-01
X now wants to combine your social media activity, political views, and follower network with your bank balance, spending habits, and income. An AI concierge built by xAI will track your spending and sort through transactions — trained by the same company that open-sourced Grok's training data. Creator payments are being forcibly migrated from Stripe to X Money, locking your income to a platform that gutted 80% of its safety team. What happens to your money if your account gets banned? Nobody knows. The same person dismantling the Consumer Financial Protection Bureau is simultaneously launching a bank. Texas regulators flagged Musk's "troubled history with the SEC." New York legislators called for his application to be denied, citing "reckless conduct that has put consumers at risk." Six states still haven't granted a license.
Compounds 3 existing findings
X silently turned on AI training for everyone, hid the off switch, then removed ...Everyone responsible for FTC compliance quit or was fired. Musk almost broke the...200 million email addresses posted online for less than two dollars. Anonymous h...
Sources
Recent Events Live

Events detected by our automated monitoring of CVE databases, regulatory agencies, and breach trackers.

high Regulatory 2026-06-08
FTC Seeks Comment on X Corp. Petition to Set Aside or Modify FTC Order Concerning Twitter
X Corp petitioning FTC to modify/set aside its 2022 consent decree. FTC seeking public comment. Shows ongoing effort to escape privacy obligations.
Source →
View all privacy alerts →
Sources