What "no KYC" actually means
"No KYC" is the most-claimed and least-defined phrase in the exchange business. It appears on services that have never asked anyone for a document, and equally on services that will ask you for a passport the moment an order trips a risk score — while holding your deposit. Both wrote the same two words on the same kind of landing page.
The distinction is not a matter of degree. One of them cannot ask you for identification, because there is no mechanism by which it would; the other simply has not asked yet. This post is about how to tell which one you are looking at, before you fund an address.
The three things the phrase gets used for
No account. You are not asked to register, confirm an e-mail or set a password. This is the weakest of the three claims. Not having an account is a user-experience fact, not a privacy guarantee — the service can still hold a record pairing your deposit address with your payout address, which is the linkage that actually matters.
No verification under a threshold. Extremely common, and usually unstated. The service operates without documents up to some daily or per-order volume, above which it behaves like any registered exchange. The threshold is often not published, and it is not necessarily the only trigger.
No verification at all. The service has no process to collect documents and no counterparty who could demand them. This is the claim worth checking, because it is the only one that holds when an order is unusual.
The question that separates them: who holds the coins?
Most instant swap sites are front-ends. They quote you a rate, take your deposit and route the actual trade to a partner exchange — a registered venue with accounts, a compliance desk and legal obligations. The front-end genuinely never asks you for KYC, and can say so honestly. But the venue holding the funds can, and when a compliance system flags an order, it is that venue's decision whether the payout goes out.
This is where the phrase "deferred KYC" comes from, and why the complaints follow a consistent shape: everything worked fine for months, then one order stopped at "processing", and the resolution offered was to submit identity documents to a company the user had never heard of. The leverage is total, because the coins are already there. Refusing means the funds stay put.
So the question is not "do you require KYC?" — everyone answers no. The question is who holds the liquidity, and what obligations do they have? A service filling swaps from its own reserves has no partner in a position to make that demand. A router does, whether or not it says so.
On OnionSwap the answer is the former: every swap is filled from reserves we hold ourselves, published on the home page and refreshed every fifteen minutes. There is no verification step to fail because there is no counterparty behind us who could introduce one.
No KYC is not the same as no logs
These get conflated constantly and they are independent properties. A service can collect zero documents and still retain, indefinitely, a database row linking your deposit address to your payout address — which for a chain analyst is the single most valuable artefact the swap produces. It joins two addresses that the blockchains themselves do not connect.
Three things worth checking, in order of how often they are quietly wrong:
Is a retention period stated? "We don't keep logs" with no number attached is a slogan. A specific period is a commitment you can hold the service to. Ours is seven days after payout, after which the order record is dropped — which is also why the track page stops finding old orders.
Are web server access logs disabled? Separate from order records, and the default on most stacks is that they are on. An IP-timestamped request log sitting next to an order database gives up most of what the order database was careful not to store.
Does the site load third-party resources? A hosted font, an analytics tag, a CDN script or a captcha widget hands your IP and browsing to another company on every page load, regardless of the exchange's own policy. This is checkable in about ten seconds in your browser's network tab, and it is the claim most often contradicted by the page making it.
Practical checks before you fund anything
Look for a stated limit and where it comes from. A service that publishes a maximum and explains it — ours follows the reserve of the asset you are receiving — is telling you what happens at the ceiling. A service with an unexplained cap is often describing an unstated verification threshold.
Read the refund policy before you need it. Underpayments, expired orders and amounts below the minimum are routine, and how they are handled tells you whether returning funds requires an identity check. A refund flow that asks for documents is KYC with extra steps.
Check whether the site works without JavaScript. Not for its own sake, but because a page that runs entirely on server-rendered HTML and form posts has far less surface for fingerprinting than one that ships a framework and a wallet connector. Ours does; scripts only refresh the reserve figures in the background.
Test with a small amount. The oldest advice and still the best. A first swap well below anything that would trip a threshold tells you what the flow actually does, for the cost of a network fee.
Prefer an onion mirror if it matters. A Tor mirror that serves the same pages without external requests means you are not depending on the operator's word about IP logging in the first place.
Is any of this legal?
For an individual, using a service that does not verify identity is generally lawful in most jurisdictions, and the regulatory obligations that exist attach to the service rather than to you. Tax reporting duties are entirely unaffected by how a trade was made — a swap is a disposal wherever disposals are taxable, regardless of whether anyone asked for your name. Rules vary by country and change, so this is not advice about yours.
What privacy buys you is not exemption from any of that. It is the ordinary expectation that a routine financial transaction does not become a permanent, publicly-indexed, identity-linked record — which is what happens by default on a transparent chain, and which is exactly the reason converting to Monero and back again is such a common operation.
The short version
Ask who holds the coins. Ask how long the order record lives. Check the network tab yourself rather than reading the privacy page. Everything else — the badge on the landing page, the phrase in the meta description, the count of supported assets — is marketing that costs nothing to write.