ACCOUNT PRIVACY FILE
Binance
A centralised platform split across ADGM service entities, distinct from Binance Wallet and Binance.US, with extensive API and compliance records.
- REVIEW DATE
- STATUS
- partially verified
- CONFIDENCE
- medium
Written by SignalQuoin Editorial TeamIndependently reviewed by SignalQuoin Review TeamPublished by SignalQuoin Team
EDITORIAL ASSESSMENT
Binance's service depth creates a large observable surface: identity, orders, API keys, custody and regional eligibility all intersect. The current terms clarify entity roles, but a real privacy rating needs network and account-behaviour tests we have not run.
- Current global terms allocate service roles
- API interfaces are extensively documented
- US enforcement records provide material compliance context
- No live telemetry or API-permission audit
- Binance Wallet and Binance.US require separate files
- PoR is not a full liability or privacy review
CLAIM → EVIDENCE → LIMIT / 5
The privacy ledger
Unified account, divided roles
- CLAIM UNDER REVIEW
- The global platform presents one account while legal roles are divided among ADGM entities.
- EVIDENCE FOUND
- The 2026 terms allocate exchange, clearing/custody and other services to NEL, NCCL and NTL.
- DO NOT INFER
- The terms do not prove every user's locale or product has completed the same migration.
API exposure
- CLAIM UNDER REVIEW
- Automation adds credentials, IP, order and account-data paths beyond the web interface.
- EVIDENCE FOUND
- Binance documents REST, WebSocket and FIX surfaces.
- DO NOT INFER
- Documentation proves protocols exist, not least-privilege defaults, retention, uptime or absence of unauthorised access.
Sources: Binance API documentation ↗
Wallet separation
- CLAIM UNDER REVIEW
- The centralised exchange record cannot describe Binance Wallet or Binance.US.
- EVIDENCE FOUND
- The global terms and licence materials are service- and entity-scoped.
- DO NOT INFER
- Shared branding is not evidence of shared custody, privacy controller or regulatory coverage.
Sources: Binance Terms of Use — 21 July 2026 ↗ · Binance licences and registrations ↗
Reserve proof boundary
- CLAIM UNDER REVIEW
- Merkle and zk-SNARK tools can help verify snapshot inclusion.
- EVIDENCE FOUND
- Binance publishes its PoR verification interface and provider claims.
- DO NOT INFER
- The tool does not disclose all off-chain liabilities, data recipients or current solvency.
Sources: Binance Proof of Reserves ↗
Compliance history
- CLAIM UNDER REVIEW
- Historical US resolutions are relevant to governance and controls, but must remain entity- and date-specific.
- EVIDENCE FOUND
- DOJ records the 2023 plea and coordinated resolution; the SEC records its 2025 discretionary dismissal.
- DO NOT INFER
- The dismissal is not merits exoneration, and historical outcomes do not prove present unlawful conduct.
Sources: US v. Binance Holdings Limited ↗ · SEC Litigation Release 26316 ↗
EXPERT PRIVACY REVIEW / 8 FLOWS
From identity edge to revision trigger.
The ADGM global account and its exchange, clearing/custody, broker-dealer, API and chat surfaces, with historical US enforcement as governance evidence. Local platforms and Binance Wallet remain separate.
Experienced users able to manage API permissions and verify the exact regional platform, product and service entity.
Users who need a single entity, minimal profile linkage, simple deletion expectations, or privacy conclusions that cover every regional Binance service.
Current global terms allocate service roles
Kraken offers a different regional-entity and controls map; using a separate self-custody wallet narrows exchange key control but introduces public-chain and wallet-provider data.
IDENTITY / AUTHORITY BOUNDARY
A unified account can hold records maintained by multiple ADGM entities. Identity, KYC, chat, trading, custody and API events can therefore cross functional boundaries defined in the agreement.
- 01
An eligible user identifies the serving entity, records KYC and chat disclosures, creates a read-only API key, executes no value-bearing action, then revokes access and inspects available logs.
- 02
Read-only API: Verified account → scoped key → market/account reads → revoke
- 03
Support chat: Account or public chat → bot/human handoff → case record
- 04
Alternative path: Kraken offers a different regional-entity and controls map; using a separate self-custody wallet narrows exchange key control but introduces public-chain and wallet-provider data.
| FLOW QUESTION | BOUNDED FINDING | PROOF STATE | VERIFICATION PLANNED |
|---|---|---|---|
| Who performs KYC? | The terms require identity verification before account access and permit independent-source verification. | SUPPORTED RECORD | Capture fields, vendors and account-entity disclosure for a test jurisdiction. |
| How is one account split? | Exchange, clearing/custody and broker-dealer entities maintain different records behind a unified operational account. | SUPPORTED RECORD | Map which entity appears on each confirmation, custody record and notice. |
| Where do identity and assets meet? | Custody and settlement records sit within the unified account, creating strong linkability between verified identity and asset activity. | SUPPORTED RECORD | Inspect statements and exports without assuming every regional account follows the same structure. |
| What do PoR and account controls prove? | PoR is balance-snapshot evidence, not a privacy or complete-solvency conclusion. API key controls need live scope inspection. | PARTIAL RECORD | Use read-only scope, inspect logs and keep PoR identifiers separate. |
| What does enforcement add? | The DOJ and SEC records are historical governance evidence involving named entities and claims; they do not prove today's privacy behaviour for every service. US v. Binance Holdings Limited ↗SEC Litigation Release 26316 ↗ | SUPPORTED RECORD | Refresh current entity and monitoring records before changing the conclusion. |
| What can API access reveal or change? | Official documentation exposes broad trading protocols, while actual key scopes, IP restrictions, logs and revocation behaviour remain unobserved. | VERIFICATION PLANNED | Create and revoke a no-funds read-only key; preserve scope and event evidence. |
| How is chat content used? | The terms say chat may be monitored, analysed, saved and processed, including for personalised insights, offers or investigations; non-human agents may be involved. | SUPPORTED RECORD | Submit a synthetic documentation question and record disclosures and retention controls. |
| How are licences and claims revised? | A provider licence page is useful routing material but primary register and product matching remain necessary. Binance licences and registrations ↗Binance Terms of Use — 21 July 2026 ↗ | PARTIAL RECORD | Diff entity, product, privacy and AI/chat policies on every material update. |
| SCENARIO | SEQUENCE | DATA DISCLOSED | OPEN QUESTION |
|---|---|---|---|
| Read-only API | Verified account → scoped key → market/account reads → revoke | Identity-linked account events, API key metadata, IP/device and requested account data. Binance API documentation ↗Binance Terms of Use — 21 July 2026 ↗ | Are scope defaults least-privilege, are events exportable, and how fast does revocation propagate? |
| Support chat | Account or public chat → bot/human handoff → case record | Chat history and account context under the terms. | Which content is used for personalisation or investigation, and what retention or objection controls apply? |
Model the unified account as linked records rather than one database. Attach every datum to function, entity, legal basis or product rule; observe API and chat with synthetic content and least privilege.
High for the reviewed ADGM entity/function allocation and chat processing clauses; medium for provider licence and API surfaces; insufficient for actual telemetry, internal access boundaries and rights handling.
- Local terms supersede the ADGM allocation for the tested user.
- API, AI/chat or privacy policies materially change data use.
- New regulator or monitor records alter the governance assessment.
CHANGE / REVISION TRAIL
Rechecked ADGM terms, API and enforcement records; added unified-account and chat-processing maps.
Opened the entity-aware privacy dossier.
Local terms supersede the ADGM allocation for the tested user.
DECISION FAQ
Is a unified account one legal entity?
No. The reviewed ADGM terms allocate records and services among several entities.
Is chat ephemeral?
The terms allow monitoring, analysis, saving and processing; a specific retention period still needs verification.
Was API revocation observed?
No. The least-privilege scenario is planned.
What would change this privacy conclusion?
Local terms supersede the ADGM allocation for the tested user. API, AI/chat or privacy policies materially change data use. New regulator or monitor records alter the governance assessment.
PRIMARY SOURCE REGISTER
6 records
Source access and applicable scope were recorded on 16 August 2026; records are attributed by class.- termsBinance Terms of Use — 21 July 2026 ↗Retrieved 2026-08-16
- productBinance licences and registrations ↗Retrieved 2026-08-16
- productBinance API documentation ↗Retrieved 2026-08-16
- productBinance Proof of Reserves ↗Retrieved 2026-08-16
- regulatorUS v. Binance Holdings Limited ↗Retrieved 2026-08-16
- regulatorSEC Litigation Release 26316 ↗Retrieved 2026-08-16
