Twitter (X) Privacy Settings: A Practical Walkthrough

July 1, 2026 · 7 min read

X (Twitter) has dozens of settings scattered across nested menus, and most of them have shipped, moved, or been renamed at least once. This guide walks through the privacy controls that actually change what other people and advertisers can learn about you, in rough order of impact. Settings live under Settings and privacy → Privacy and safety unless noted otherwise; exact menu names occasionally shift between app versions, but the concepts below are stable.

1. Protect your posts — the single biggest switch

The "Protect your posts" toggle (under Audience and tagging) converts your account from public to protected. Protected means only approved followers can see your posts, your replies don't appear to non-followers, and your content stops being indexed or viewable by outside tools. It's the one setting that changes your account's fundamental visibility model rather than trimming around the edges. Two things people consistently get wrong about it: it is not retroactive against copies (anything already screenshotted, quoted, or archived stays out there), and your existing followers keep access unless you remove them individually. We break down the details in .

2. Discoverability — stop your phone number from outing you

Under Discoverability and contacts, two checkboxes control whether people who have your email address or phone number can find your account. If you use a pseudonymous account, these are the settings most likely to betray you: anyone who has your number in their contacts — colleagues, relatives, that group chat from 2019 — can otherwise surface your account through contact syncing. Turn both off, and while you're there, review and remove any previously uploaded contacts.

3. Photo tagging

Under Audience and tagging, you can allow tagging by anyone, only people you follow, or no one. Tags put your account name on other people's photos, which makes you discoverable through their audiences. "Only people you follow" is a sensible default; "no one" is better if you keep a low profile.

4. Direct messages

Under Direct messages, decide whether strangers can DM you. Open DMs are useful for journalists and anyone expecting tips or business inquiries; for everyone else they're mostly a spam and phishing channel. Also worth noting: the "read receipts" toggle is here — turning it off hides your read status in both directions.

5. Location — off unless you have a reason

Precise location attached to posts has been opt-in for years, but check Location information anyway, and use the option to remove historical location data if you ever had it on. Separately, remember that photos you upload can no longer leak GPS coordinates through EXIF data — platforms strip it — but the photo's visible content (street signs, storefronts, window views) remains the most common way people accidentally reveal where they live.

6. Data sharing and ad personalization

Under Privacy and safety → Data sharing and personalization you'll find the switches that govern how your activity feeds the ad machine:

  • Personalized ads — whether your on-platform behavior shapes the ads you see.
  • Inferred identity — whether X may connect your account to browsers and devices you haven't logged in from.
  • Data sharing with business partners — whether certain account data may be shared with third parties.
  • Off-platform activity — whether X uses information about your visits to other websites (collected via embeds and trackers) for personalization.

None of these affect what other users see; they affect what the company and its partners assemble about you. Turning them off doesn't stop data collection entirely — it limits how the data is used.

7. Muting, blocking, and quality filters

Not strictly privacy, but adjacent: muted words and muted accounts shape your experience silently (the other party isn't notified), while blocking is visible to the blocked account. If you're dealing with harassment, mute liberally, block deliberately, and remember that protected mode (setting #1) is the strongest tool available.

A realistic threat-model checklist

Settings only matter relative to what you're protecting against. Three common profiles:

  • "I just don't want ads following me around": turn off everything under data sharing and personalization, and consider a tracker-blocking browser extension for the embeds you encounter across the web.
  • "I post under a pseudonym": discoverability toggles off, photo tagging off, location off, and treat your writing style, posting hours, and photo backgrounds as the actual attack surface — settings can't fix those.
  • "I only want friends reading": protect your posts, audit your current follower list, and accept the trade-off that your reach and links to your posts will stop working for outsiders.

Finally, remember the asymmetry that governs everything on a public account: anything public can be copied by anyone, at any time, and no later settings change reaches those copies. Settings are also worth re-auditing once or twice a year — platforms add new toggles, quietly reset others during redesigns, and occasionally opt existing users into new features by default. The best time to configure privacy settings is before you post — the second best time is now.