THE INDUSTRY FILES

Crypto & Digital Assets

An exchange account opens with a government ID and your face, and anti-money-laundering rules attach that identity to your transfers, passed along with them. Closing the account does not clear the file: the same rules keep it for at least five years after you leave.

TRACKING PRIORITY HIGH

A permanent identity-to-wealth link. Worth keeping on the list.

IF IT LEAKS SEVERE
EXPECT IT KEPT INDEFINITELY

Exchanges run the same anti-money-laundering holds as banks; the ledger itself is permanent and public.

IDENTITY DEMANDED FULL KYC

Trading requires full identity verification: ID document plus a liveness or face check.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

A leak here names you as someone who holds crypto, with your ID and often your home address attached. Buyers on one leaked customer list were phished and then threatened with violence in person.

What repeats in the policies

WHAT YOU HAND OVER

It starts with your ID and your face

To open an account where a company holds your crypto for you, you hand over a government ID and a selfie or short video. Many services then turn that into a stored map of your face and compare it against the ID photo, and a separate identity company commonly runs the check. Wallets you control yourself are the exception: used on their own, they ask for none of this.

WHERE IT GOES

It does not stay between you and the exchange

When you send or receive crypto, anti-money-laundering rules in the US, UK and EU require the identity they checked to be attached to the transfer and passed to the exchange on the other side. Around that sits a ring of outside firms: transaction-monitoring, fraud, and identity-check vendors that each get a copy of your data. Sending crypto is not a private handoff between two wallets.

WHAT STAYS

Leaving does not clear the file

Closing or deleting the account does not clear the identity file. In the UK and EU, anti-money-laundering rules require it kept for at least five years after you leave; many policies name no number at all and say only that the file stays as long as the law requires. In the UK, those same rules then require it deleted once that period ends, unless a further legal reason applies, which the policies do not mention.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileIdentity DocumentsPurchasesFinancialPhotos & Biometrics Browsing & Activity maybeMessages maybeLocation maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Money and net worth HIGHLY LIKELY

Holdings and trades reveal it, and the chain keeps them forever.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

identity / anti-money-laundering records ABOUT 5 YEARS LAW SETS IT

Money-laundering rules require ID and transaction records after an account closes.

financial regulatory records AROUND 5 TO 7 YEARS LAW SETS IT

Financial regulators require advice, suitability, and transaction records.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

The identity behind your crypto is a target. In one breach, bribed support staff handed over government-ID images and account balances; in another, a leaked list of hardware-wallet buyers put names and home addresses of crypto holders in the open, and those buyers were then hit with phishing and threats of physical harm. Identified exchange activity also feeds a commercial surveillance layer that reads the public ledger in real time.

SOLD OR SHARED POSSIBLE

Less ad-driven, but wallet and trading behaviour is valuable market data.

AI TRAINING MODERATE

Trading and fraud patterns train models; documented, narrow market.

Even anonymised, this can still be you

Anonymised is their word, but a verified identity file next to a wallet de-anonymises a permanent public ledger, and fifteen ordinary attributes already re-identify 99.98% of people (Rocher et al., Nature Communications, 2019).

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces SOMETIMES

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns TYPICAL

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write SOMETIMES

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice TYPICAL

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint SOMETIMES

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“Regarding the Travel Rule, we and other custodial exchanges and financial institutions share certain basic information about you.”

The identity they checked at signup is attached to individual crypto transfers and sent to the exchange on the other side. The recipients are not limited to that exchange: policies extend the sharing to regulators and other industry partners. This is required by anti-money-laundering rules in the US, UK and EU.

THE MOVE Which of your transfers carried your identity, and where it went, is theirs to answer. Their reply goes on your record.

“We may analyze public blockchain data, including timestamps of transactions, transaction IDs, transaction amounts, and wallet addresses.”

The public chain is read back into your account. Wallet addresses, amounts and times that look anonymous on their own are joined to the identity on your account and held as data about you.

THE MOVE What they have tied to your account from the public chain is theirs to answer. The reply, or the silence, goes on your record.

“As blockchains are networks we do not control, we are not able to erase, modify, or alter personal data on such networks.”

Some policies warn that on-chain transaction history sits outside the deletion right entirely. Only the copy the service holds off the chain can ever be removed; what is written to the public ledger stays.

THE MOVE Which parts of your record they can actually delete, and which are fixed on the chain, is theirs to answer. Their reply goes on your record.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →