Back to Blog
PrivacyUpdated September 16, 2026·4 min read

Your personal data in crypto: who holds it, how long, what leaks, and how to hold as little as possible elsewhere

Every crypto service you have identified yourself to keeps a file: exchanges, wallet vendors, tax tools, portfolio trackers, hardware shops. What each one holds, the retention rules that stop them deleting it, the breaches that show what happens next, how to find out what a company has on you, and the structural fix — using services that never build the file.

The inventory most people have never made

List every crypto-related company that knows your name. For a typical user after a few years it looks like this:

ServiceWhat it holdsRetention
Exchanges (each one)ID document images, selfie/biometric template, address, every deposit/withdrawal address, every trade, IP and device history5+ years after account closure (AML rules); often indefinitely in practice
Hardware wallet vendorName, shipping address, email, order historyIndefinite unless deleted on request
Portfolio tracker / tax softwareEvery address and xpub you gave it, exchange API keys, full transaction historyPer their policy; often indefinite
Wallet app with analyticsIP, device fingerprint, sometimes addresses queriedVaries
Block explorersAddresses you searched, from your IPLogs; varies
Fiat on-ramp widgets in walletsFull KYC, card detailsAs exchanges
Newsletters, forums, Telegram groupsEmail, handle, sometimes wallet addresses posted publiclyIndefinite

Each row is a database that can be breached, sold, subpoenaed or simply kept by a company that changes hands. The exchange row is the heaviest, and it repeats for every exchange account you ever opened — including the ones you forgot.

Why they cannot just delete it

Data-protection laws (GDPR and its equivalents) give you a right to erasure — and anti-money-laundering laws override it. Regulated exchanges must retain identity records and transaction data for a statutory period after the relationship ends, typically five years, sometimes longer. A deletion request to an exchange therefore usually returns "we are required to retain this". The only data you can reliably prevent from being retained is data you never provided.

What breaches look like in practice

The consequences are not abstract:

  • A hardware-wallet vendor's 2020 leak exposed hundreds of thousands of customer names and shipping addresses; recipients received phishing campaigns and, in some cases, physical threats, for years afterwards.
  • A 2025 incident at a major exchange involved overseas support contractors bribed to export customer records — names, addresses, partial ID data, account balances — used for targeted impersonation scams.
  • KYC vendor breaches have exposed passport scans and selfies collected on behalf of multiple clients at once.

The common thread: the data was collected for a legitimate reason, stored as required, and then used against the people it described. Retention rules guarantee the target stays available.

Finding out what a company has on you

Under GDPR (EU/UK) and similar regimes (California, Brazil, others), you can send a subject access request: the company must tell you what personal data it holds, why, for how long, and with whom it has shared it. It is worth doing for each exchange you have used; the answer is usually longer than expected and lists the vendors your document went to. Requests are free and must be answered within about a month.

Reducing the footprint

Ordered by effect:

  1. Stop creating new files. Every additional exchange account is another copy of your ID. For conversion between coins, an account-free exchange creates no file at all: BTC → XMR, USDT (TRC-20) → BTC, BTC → USDT (TRC-20) — addresses in, addresses out, nothing to retain. The no-KYC explainer covers what it does and does not protect.
  2. Close what you do not use. Closure does not delete the record, but it stops new data (logins, IPs, trades) accumulating and removes an active account from attackers' reach.
  3. Keep your own records; do not outsource them. A local spreadsheet or an offline tax tool instead of a cloud tracker that holds every address you own.
  4. Do not give xpubs to services. An extended public key reveals every address in the wallet, past and future.
  5. Ship hardware to a pickup point or a business address, not your home, and use an alias email.
  6. Use a distinct email and no phone number where possible. Phone numbers are the pivot for SIM-swap attacks; a TOTP app is safer than SMS everywhere it is offered.
  7. Withdraw to your own wallet. Balances left on an exchange are both a custody risk and an entry in the breached-balances table.

Self-custody and the data you must protect yourself

Moving off exchanges shifts one responsibility to you: the seed phrase. It is the one piece of data whose loss or exposure is unrecoverable. Store it offline, in at least two places, never photographed, never in a cloud note, never typed into a website. The hardware wallet guide and the wallet protection guide cover the details.

Frequently asked questions

Can I get an exchange to delete my KYC data after closing the account? Usually not within the retention period. Ask anyway — some data (marketing, device history) is deletable even where identity records are not.

Is a no-KYC exchange required to keep my data? It has no identity data to keep. It holds the order — addresses, amounts, hashes — which is already public on the chains involved.

What is the single most exposed item? The ID document image with a selfie. It is the one thing that enables full impersonation and cannot be reissued after a leak.

Are portfolio trackers safe? They are as safe as their security and their willingness to sell data. The exposure is total (every address); prefer local tools.

Where do I start? Send a subject access request to the exchange you have used longest. The reply will show you why the rest of this page matters.

Ready to swap privately?

No account required. Start in seconds.

Start swapping →