Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from Coinbase's published policy; none has been tested (run by us) yet.
1Deletionstated
Coinbase honors deletion requests through the Privacy Rights Dashboard, but as a regulated money-services business it retains personal and transaction data (typically up to five years) to meet Bank Secrecy Act / anti-money-laundering obligations, so deletion is scored at the partial level.
Coinbase — Global Privacy Policy (retention) · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
A consumer can grant an app OAuth 2.0 access to their Coinbase account data via the Coinbase App API (scopes such as wallet:user:read and wallet:transactions:read), with refresh tokens (offline_access) and revocation from account settings, so agent access is scored at the full level.
Coinbase — App OAuth2 access & refresh tokens · accessed Jun 2026 ↗
Reviewed Jun 2026 from Coinbase's Global Privacy Policy, US Privacy Notice, and Privacy Rights Dashboard help pages. All cells are "stated" (read from published policy), not tested. Coinbase is a regulated financial service: deletion is offered but heavy BSA/AML retention (up to ~5 years) applies, and it discloses identifiers to advertising partners (a CCPA "sale / share" with opt-out). The May 2025 support-contractor breach and the class actions / DOJ-SEC inquiries that followed are NOT recorded as enforcement, because no regulator or court judgment has issued.