Cyberdog, totally get your concern, I will update the UI to add some further info.
tldr: I get read-only permissions from Coinbase OAuth and don't store any user data. You can also setup your own server -- one click to deploy to heroku, further instructions in the github! https://github.com/joshblum/profbit