The inventory most people have never made
List every crypto-related company that knows your name. For a typical user after a few years it looks like this:
| Service | What it holds | Retention |
|---|---|---|
| Exchanges (each one) | ID document images, selfie/biometric template, address, every deposit/withdrawal address, every trade, IP and device history | 5+ years after account closure (AML rules); often indefinitely in practice |
| Hardware wallet vendor | Name, shipping address, email, order history | Indefinite unless deleted on request |
| Portfolio tracker / tax software | Every address and xpub you gave it, exchange API keys, full transaction history | Per their policy; often indefinite |
| Wallet app with analytics | IP, device fingerprint, sometimes addresses queried | Varies |
| Block explorers | Addresses you searched, from your IP | Logs; varies |
| Fiat on-ramp widgets in wallets | Full KYC, card details | As exchanges |
| Newsletters, forums, Telegram groups | Email, handle, sometimes wallet addresses posted publicly | Indefinite |
Each row is a database that can be breached, sold, subpoenaed or simply kept by a company that changes hands. The exchange row is the heaviest, and it repeats for every exchange account you ever opened — including the ones you forgot.
Why they cannot just delete it
Data-protection laws (GDPR and its equivalents) give you a right to erasure — and anti-money-laundering laws override it. Regulated exchanges must retain identity records and transaction data for a statutory period after the relationship ends, typically five years, sometimes longer. A deletion request to an exchange therefore usually returns "we are required to retain this". The only data you can reliably prevent from being retained is data you never provided.
What breaches look like in practice
The consequences are not abstract:
- A hardware-wallet vendor's 2020 leak exposed hundreds of thousands of customer names and shipping addresses; recipients received phishing campaigns and, in some cases, physical threats, for years afterwards.
- A 2025 incident at a major exchange involved overseas support contractors bribed to export customer records — names, addresses, partial ID data, account balances — used for targeted impersonation scams.
- KYC vendor breaches have exposed passport scans and selfies collected on behalf of multiple clients at once.
The common thread: the data was collected for a legitimate reason, stored as required, and then used against the people it described. Retention rules guarantee the target stays available.
Finding out what a company has on you
Under GDPR (EU/UK) and similar regimes (California, Brazil, others), you can send a subject access request: the company must tell you what personal data it holds, why, for how long, and with whom it has shared it. It is worth doing for each exchange you have used; the answer is usually longer than expected and lists the vendors your document went to. Requests are free and must be answered within about a month.
Reducing the footprint
Ordered by effect:
- Stop creating new files. Every additional exchange account is another copy of your ID. For conversion between coins, an account-free exchange creates no file at all: BTC → XMR, USDT (TRC-20) → BTC, BTC → USDT (TRC-20) — addresses in, addresses out, nothing to retain. The no-KYC explainer covers what it does and does not protect.
- Close what you do not use. Closure does not delete the record, but it stops new data (logins, IPs, trades) accumulating and removes an active account from attackers' reach.
- Keep your own records; do not outsource them. A local spreadsheet or an offline tax tool instead of a cloud tracker that holds every address you own.
- Do not give xpubs to services. An extended public key reveals every address in the wallet, past and future.
- Ship hardware to a pickup point or a business address, not your home, and use an alias email.
- Use a distinct email and no phone number where possible. Phone numbers are the pivot for SIM-swap attacks; a TOTP app is safer than SMS everywhere it is offered.
- Withdraw to your own wallet. Balances left on an exchange are both a custody risk and an entry in the breached-balances table.
Self-custody and the data you must protect yourself
Moving off exchanges shifts one responsibility to you: the seed phrase. It is the one piece of data whose loss or exposure is unrecoverable. Store it offline, in at least two places, never photographed, never in a cloud note, never typed into a website. The hardware wallet guide and the wallet protection guide cover the details.
Frequently asked questions
Can I get an exchange to delete my KYC data after closing the account? Usually not within the retention period. Ask anyway — some data (marketing, device history) is deletable even where identity records are not.
Is a no-KYC exchange required to keep my data? It has no identity data to keep. It holds the order — addresses, amounts, hashes — which is already public on the chains involved.
What is the single most exposed item? The ID document image with a selfie. It is the one thing that enables full impersonation and cannot be reissued after a leak.
Are portfolio trackers safe? They are as safe as their security and their willingness to sell data. The exposure is total (every address); prefer local tools.
Where do I start? Send a subject access request to the exchange you have used longest. The reply will show you why the rest of this page matters.
BTC → XMR
USDT (TRC-20) → BTC
XMR → BTC