On this page

Privacy & Trust Boundaries

See which note details stay private and what observers can still learn.

Private note data#

Spend witnesses stay on the holder's device. Proofs, hashes and encryption protect note openings, input ownership and recipient delivery under their respective assumptions. The relayer can submit a request without holding plaintext account history.

Public chain fields and application traffic remain visible. The table below lists what each operation exposes.

How the wallet, Pool and disclosure tools fit together
How the wallet, Pool and disclosure tools fit together

What the chain shows#

OperationPublic data
DepositFunding wallet, asset, amount and timing
Private transferCommitments, nullifiers, proof submission and public fields
WithdrawalPayout asset, amount and recipient
External actionVenue, route and input/output amounts
Controlled spendController calls and their authorization effects
Payment sessionFunding budget, merchant and lifecycle state
Direct wallet submissionSubmitting wallet and transaction metadata

Encryption and proof assumptions#

X-Wing protects recorded delivery using its hybrid cryptographic assumptions. Spend proofs use Groth16 over BN254, whose soundness still depends on elliptic-curve assumptions. Protecting encrypted delivery does not make that proof system post-quantum.

Wallet-signature recovery inherits the security of the wallet key. Passkey and paper recovery are other access methods. Production key setup and independent circuit and contract review are still required.

Network and service records#

An RPC operator or relay can see connection timing and the public requests sent to it. External services can keep content, IP and billing logs outside the Pool. Requests in one payment session remain linkable.

Tell users what each part of your application publishes. Private transfers cannot make a provider's API logs or card records anonymous, and public venue execution has its own visible amounts.

Screening Pending deposits#

Where a spend path requires it, direct Pending inputs are checked against the publisher's effective source policy. That check does not cover the entire ancestry of an Active note or give a regulatory verdict about its holder.

A source-revealing Pending exit publishes the original deposit source and amount. The holder chooses a public payout recipient separately, so the path need not return money to the original depositor.