Crypto & Digital Assets

The industry files

An exchange asks for a government ID and your face before you can trade. Money-laundering rules then attach that identity to your transfers and pass it to the exchange at the other end. Closing the account does not clear the file: the same rules keep it for at least five years after you leave.

The read at a glance

Tracking priority High

The exchange knows which public wallet is yours.

If it leaks Severe

A leak ties your real identity to your on-chain wealth, a permanent public link that changing a password cannot break.

Expect it kept Indefinitely

Exchanges run the same anti-money-laundering holds as banks; the ledger itself is permanent and public.

Identity demanded Full KYC

Trading requires full identity verification: ID document plus a liveness or face check.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

A leak here names you as someone who holds crypto, with your ID and often your home address attached. Buyers on one leaked customer list were phished and then threatened with violence in person.

What repeats in the policies

What you hand over

It starts with your ID and your face

To open an account where a company holds your crypto for you, you hand over a government ID and a selfie or short video. Many services turn that into a stored map of your face and compare it with the ID photo, usually through an outside identity firm. A wallet you hold yourself asks for none of this.

Where it goes

It does not stay between you and the exchange

When you send or receive crypto, money-laundering rules in the US, UK and EU require the identity they checked to be attached to the transfer and passed to the exchange at the other end. Around that sit outside firms handling transaction monitoring, fraud and identity checks, and each one gets a copy of your data.

What stays

Leaving does not clear the file

Closing the account does not clear the identity file. In the UK and EU, money-laundering rules require it to be kept for at least five years after you leave, and many policies give no number at all, saying only that it stays as long as the law requires. UK rules then require it deleted once those five years end, unless another legal reason applies, which the policies do not mention.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileIdentity DocumentsPurchasesFinancialPhotos & Biometrics Browsing & Activity · maybeMessages · maybeLocation · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Money and net worth Highly likely

Holdings and trades reveal it, and the chain keeps them forever.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Identity / anti-money-laundering records Law sets it about 5 years

Money-laundering rules require ID and transaction records after an account closes.

Financial regulatory records Law sets it around 5 to 7 years

Financial regulators require advice, suitability, and transaction records.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

The identity behind your crypto is a target. In one breach, bribed support staff handed over government-ID images and account balances. In another, a leaked list of hardware-wallet buyers put names and home addresses of crypto holders in the open. Companies also read the public ledger in real time and sell what they can match back to a named account.

Sold or shared Possible

Exchanges are less ad-driven, but wallet and trading behaviour is valuable market data.

AI training Moderate

Trading and fraud patterns train models, in a narrower market than open web content.

Even anonymised, this can still be you

A verified identity file sitting next to a wallet de-anonymises a permanent public ledger, and fifteen ordinary attributes already re-identify 99.98% of people (Rocher et al., Nature Communications, 2019).

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces Sometimes

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns Typical

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write Sometimes

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice Typical

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint Sometimes

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“we and other exchanges and financial institutions share certain basic information about you”

“we and other exchanges and financial institutions share certain basic information about you”

The identity they checked at signup is attached to individual crypto transfers and sent to the exchange on the other side. The recipients are not limited to that exchange: policies extend the sharing to regulators and other industry partners. This is required by anti-money-laundering rules in the US, UK and EU.

The move Which of your transfers carried your identity, and where it went, is theirs to answer.

“we may analyse public blockchain data, including transaction amounts, times and wallet addresses”

“we may analyse public blockchain data, including transaction amounts, times and wallet addresses”

The public chain is read back into your account. Wallet addresses, amounts and times that look anonymous on their own are joined to the identity on your account and held as data about you.

The move What they have tied to your account from the public chain is theirs to answer.

“we cannot erase or alter personal data on networks we do not control”

“we cannot erase or alter personal data on networks we do not control”

Some policies warn that on-chain transaction history sits outside the deletion right entirely. Only the copy the service holds off the chain can ever be removed; what is written to the public ledger stays.

The move Which parts of your record they can actually delete, and which are fixed on the chain, is theirs to answer.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.