The relay, why it exists and why it cannot hurt you
Checked against app build 2026-08-26-01-41 on 2026-08-26.
Why does gains.tax need a relay at all?
Because exchanges refuse direct requests from pages running in a browser, the CORS policy on their authenticated endpoints.
A page cannot call api.kraken.com itself, something server-side must forward the call. The relay is the smallest possible version of that something. It accepts a signed request from your browser, checks the destination against a two-host allowlist, api.kraken.com and api.binance.com, forwards it, and hands back the answer. That is the whole job.
Can the relay see my API secret or my transactions?
No. It never sees an API secret, because signing already happened in your browser.
It stores nothing, has no database and no accounts, and logs nothing. It strips every header except the exchange authentication headers and content type. It refuses any destination that is not one of the two exchange hosts, ask it to fetch anything else and the answer is a refusal. Your transactions never pass through it either, only the exchange calls you triggered, used by Kraken sync and Binance sync.
Can I run my own relay instead?
Yes, and that is the point of publishing it.
You are trusting that the deployed relay matches this description. If you would rather not, the relay’s source is a single small file, published so you can read it, and you can deploy your own copy to your own account and point the app at it in Settings. The address needs to start with https, and the app says so if it does not. The design goal is that trusting us should never be a requirement, only a convenience.
The privacy model page lists the relay alongside the other two optional network features, wallet scanning and price lookups, so the complete network surface of the app fits in one short list.