When we were designing HODLTrack's onboarding, we had an obvious choice in front of us: ask for exchange API keys like every other crypto tracker does.
It would have been easier to build. Users love the "connect once, never type a trade again" experience. And every competitor does it.
We chose not to. Here's why.
Exchange API keys — even read-only ones — are a persistent security surface. Once you paste your Coinbase or Binance key into a tracker, that tracker has ongoing access to your balance, your trade history, and depending on the exchange, parts of your KYC data. Most users never revoke those keys. If the tracker gets breached, acquired, or just pivots their privacy policy, your data is already there.
We're building a portfolio tracker for people who care about privacy. Asking for API keys on day one sends exactly the wrong signal.
So we built CSV import instead.
You export a balance snapshot from Binance, Coinbase, Kraken, or Crypto.com — a one-time file that you control. We process it and it's gone. No persistent connection, no background polling, no ongoing access to your exchange account.
The tradeoff is that updates aren't automatic — users add new trades manually after the initial import. For most people, that's 30 seconds per trade. We think that's a worthwhile tradeoff for not having a live wire into your exchange account.
We just published a step-by-step guide covering the export flow for all four major exchanges, common import issues, and how the CSV maps to HODLTrack's holdings view.
Would love any feedback from people who've wrestled with the same design decision — is auto-sync a dealbreaker for your users, or do people actually accept the manual approach if you explain the tradeoff clearly?
Full guide → How to Import Your Binance, Coinbase & Kraken Transactions into HODLTrack
I actually like that you optimized for trust over convenience. Auto-sync sounds great until people have to hand over API keys. For a privacy-focused product, I'd rather spend an extra 30 seconds importing a CSV than wonder who still has access to my exchange data six months later.
This is exactly the validation we needed — thank you. "Optimized for trust over convenience" is honestly a better frame than anything we wrote ourselves.
The internal debate when building this was real. Auto-sync is table stakes in this category and we knew we'd lose some signups by not offering it. But we kept coming back to the same question: if HODLTrack got acquired tomorrow, what data would the new owner have? With API keys: your live exchange balance, full trade history, ongoing access until you revoke. With CSV import: nothing — you processed a file and moved on.
The 30-second framing is something we're going to start using more explicitly in the product. Most people don't consciously weigh convenience vs trust — they just click "connect." Naming the tradeoff upfront changes the decision.
If you end up trying HODLTrack, would love to hear what the actual import experience feels like end-to-end.
I'd be happy to.
While reading your reply, I realized there's one strategic business decision sitting underneath the trust vs. convenience trade-off that I don't think I can do justice to in a thread.
Happy to explain what I mean if it's useful. What's the best email to reach you on?
hodltrackapp@gmail.com
Just sent it over by email.
Looking forward to hearing your thoughts once you've had a chance to read it.
Here's the link to the full guide:
https://hodltrack.app/blog/how-to-import-binance-coinbase-transactions-hodltrack