Somewhere on X's servers is a file about you, and the platform is legally obliged in much of the world to hand it over on request. It contains everything you'd expect — every post, like, and DM — and several things most people don't expect, including the advertisers who uploaded your contact information and the interest categories an algorithm has assigned to you. Requesting your data archive is free, takes two minutes of effort, and is the single most concrete way to see what a platform actually knows. Here's how, and what you'll find.
Requesting the archive
The path: Settings and privacy → Your account → Download an archive of your data. You'll re-verify your password and a confirmation code, then submit the request. Preparation isn't instant — the platform compiles the file and notifies you when it's ready, typically within a day or two, and the download link expires after a limited window, so grab it promptly. You'll receive a ZIP file: inside is a small HTML application (open Your archive.html in a browser for a friendly viewer) and a data folder of machine-readable JSON files, which is where the interesting material lives.
The expected contents
The unsurprising bulk: every post you've written (including replies you forgot within the hour), your media uploads, likes, bookmarks, follower and following lists, Lists, and your complete direct message history — a detail worth pausing on. DMs feel ephemeral in the app; in the archive they're a permanent transcript, including conversations from a decade ago with accounts that no longer exist. If you've ever treated DMs as disappearing messages, the archive is the correction.
The instructive contents
- The ad files. Look for the advertising-related JSON files: one lists ads you've seen and engaged with; another — the genuinely eye-opening one — lists advertiser audiences you belong to, including advertisers who uploaded lists of contact information that matched yours. Companies you've never interacted with know your email or phone number, bought or collected elsewhere, and used it to target you here.
- Inferred interests. The platform's guesses about what you care about, assembled from your behavior. Expect a long list that is part uncanny, part absurd — the absurd entries are their own lesson in how much of ad targeting is confident noise.
- IP and location history. Login records with IP addresses and timestamps — a coarse map of where you've been when you opened the app.
- Contacts, if you ever synced them. If you once tapped "find friends," the phone numbers and emails you uploaded may still be sitting there. (The upload can be undone in discoverability settings — see our settings walkthrough.)
- Deleted-adjacent residue. Archives have been observed to include traces users assumed were gone. Read yours before assuming deletion meant erasure.
What to do with it
Three practical uses. Preservation: the archive is the only complete, portable copy of your posting history you'll ever have — store the ZIP somewhere durable, especially if you're considering leaving the platform, because after deletion this file is all that remains. It's also the honest answer to "how do I back up my own tweets," a better one than any third-party scraper. Audit: skim the ad and interest files and adjust your data-sharing settings to taste; the archive shows you precisely what the toggles have been feeding. Perspective: reading your own decade-old posts is a strong argument for occasional pruning, and the archive lets you do that pruning informed rather than nostalgic.
Handle the file with care
A caution that sounds obvious until someone learns it the hard way: the archive is the most sensitive single file you own about your online life. It contains every private conversation you've ever had on the platform, in plain readable JSON, alongside enough behavioral data to reconstruct your last decade. Treat it accordingly — store it encrypted or at least inside password-protected storage, don't leave it in a shared downloads folder or unencrypted cloud sync, and never send it to anyone, including services offering to "analyze your Twitter data" for you. Anyone with the file has your DMs. The platform required your password twice before releasing it; apply at least that much ceremony to where it lives afterward.
The bigger point
Data-access rights — GDPR's in Europe, and equivalents elsewhere — exist precisely so that "what does this company know about me" has a checkable answer instead of a vibe. Most people never exercise them. The archive turns abstractions like "platforms build profiles from your behavior" (the machinery we describe in our digital footprint primer) into a folder of files with your name on them, which lands differently. Request it once and you'll never again need convincing that the profile exists; you'll have read it. Every major platform offers the same export, and running the exercise on each one is a reasonable weekend project for anyone who wants their relationship with these services to be informed consent rather than the other kind.