EXCHANGE
Compare entity, verification, support, custody and transaction-data paths.
SIGNALPAIR / SAME CLASS
The board puts multi-source privacy evidence beside its inference limits and compares reviewed files within one class.
PAIR CONTRACT
Compare entity, verification, support, custody and transaction-data paths.
Compare authority, recovery, telemetry, RPC and integration exposure.
No cross-class score and no inference from silence. A file exits the pair selector only where the evidence state is not met.
Cross-class comparison is refused; the board compares reviewed files within one class.
| DEMAND | Coinbase | Kraken |
|---|---|---|
| EVIDENCE STATE | PUBLIC RECORD REVIEWED | PUBLIC RECORD REVIEWED |
| PRIVACY LEDGER | IDENTITY + SUPPORT-CHAIN MAP REVIEWED | ENTITY + CONTROL DISCLOSURES REVIEWED |
| EDITORIAL VIEW | Coinbase gives unusually strong corporate disclosure for a consumer crypto platform, but its account relationship necessarily links identity, funding and transaction records. The 2025 incident shows why outsourced support access belongs in a privacy review even when private keys were not exposed. | Kraken documents security and product boundaries well, including the difference between Exchange and Wallet. Privacy conclusions remain restrained because terms and feature pages cannot show the complete live telemetry, vendor and retention graph. |
| PRIMARY TRADE-OFF | Corporate and regulatory transparency improve auditability; a centralised identity and support system creates a wider personal-data perimeter than self-custody. | Granular controls and transparent documentation reduce ambiguity, while compliance, bank funding and custody still place identity and transaction data across several parties. |
| SUPPORTED STRENGTH | Contracting and custody language is accessible | Exchange and Wallet boundary is explicit |
| OPEN LIMIT | No SignalQuoin network-capture test has been performed | No live request or tracker map yet |
| DECISION ROUTE | A US retail user connects a bank, completes KYC, executes one hosted trade, contacts support about a harmless limit question, then withdraws to a fresh self-controlled address. | An EEA or global user records the actual entity, uses the least-data bank rail, enables strongest available account controls, completes one Pro trade and requests a harmless support clarification. |
| DOES NOT FIT | People seeking pseudonymous onboarding, local-only transaction metadata, minimal identity retention, or a privacy conclusion that automatically covers Coinbase Wallet. | Users who want anonymous trading, one global controller, no third-party funding data, or a belief that self-custody Wallet and Exchange share a single privacy boundary. |
| OPEN DATA QUESTION | Which vendors receive each field and how long is it retained after account closure? | Which payment processor sees which fields, and can a manual route reduce recipients? |
| EVIDENCE CONFIDENCE | Medium-high for the contractual identity and custody data map and the 2025 support-chain incident; insufficient for current vendor list, actual telemetry, deletion execution and support-case access controls. | Medium-high for the regional entity, identity and control disclosures; insufficient for actual analytics traffic, vendor retention, rights-request handling and support access. |
| VERDICT | REVIEWED | REVIEWED |