"No KYC" is easy to say and easy to misread. It means no identity verification: no ID, no selfie, no proof of address. It does not mean that nothing about you exists anywhere. If you are going to rely on a tool for privacy, you should know precisely what it can and cannot see.

What a swap necessarily receives

Some information is unavoidable, because without it the swap cannot happen at all:

The two addresses. The one you send from, and the one you want the coins delivered to. These are the swap. There is no version of the service that works without them.

The amounts and the pair. Obvious, and also public: both transactions land on their respective blockchains anyway.

Your IP address, at the moment you connect. Every web request carries one. This is the piece people most often forget.

What it never receives

No name, no email, no phone number, no document, no date of birth, no proof of address. There is no account, so there is no login history and no profile accumulating behaviour over time. Each swap is a separate event.

This matters for a specific, unglamorous reason: data that was never collected cannot be leaked, subpoenaed, sold, or lost in a breach. A service that verified your identity holds that file whether it wants to or not.

Where the leak usually is

The weakest link is almost never the swap. It is what surrounds it.

Where the coins came from. If you fund a swap directly from a KYC exchange withdrawal, that exchange knows the address you sent to, and so does anyone reading the chain. The swap did not learn your identity, but the trail connects anyway.

Where the coins go afterwards. Sending the output straight back into a verified account rebuilds the same link from the other end.

Address reuse. Reusing a receiving address across services ties those services together on a public ledger, permanently.

Why Monero changes the picture on one side

On transparent chains like Bitcoin or Ethereum, both sides of the swap remain visible forever to anyone who looks. Monero conceals sender, receiver and amount at the protocol level, so the receiving side stops being a public record.

That is one half of the problem, not the whole of it. The funding side is still whatever chain you sent from.

Practical steps that actually help

Use a fresh receiving address for each swap. Do not fund directly from, or withdraw directly into, a verified account if the connection matters to you. Consider how you connect, since your IP is the one identifier you hand over without noticing. And be realistic: privacy is a chain of choices, and the swap is only one link in it.