Policies
Privacy
zk-pad hides who the beneficiary is and where their money goes. It does not make trading anonymous, and it cannot hide what a coin's own name and image say. Here is exactly what is hidden and what is not.
Summary#
Hidden
- Who the beneficiary is, and the wallet that finally receives the funds.
- Which beneficiary id a claimant checks. The app downloads every balance and searches locally.
- The stealth key. It never leaves your browser.
- The Railgun 0zk address a beneficiary shields to.
- For social escrows that were never advertised, which account they belong to.
Not hidden
- Every trade: wallet, amounts, price and time are public on BSC.
- Fee accruals and balances per beneficiary id, and every claim from that id.
- Coin name, ticker, image and description, which often reveal who the beneficiary is.
- Claim transactions, as seen by the relayer that submits them.
- Patterns that small anonymity sets and timing can reveal.
What this app collects#
Nothing about you. There are no analytics, tracking pixels, fingerprinting, cookies, advertising IDs or third-party scripts, and the app sets no session identifiers.
- Pages are served with
Referrer-Policy: no-referrer, and external links open withnoopener noreferrer. - Requests to the indexer and services are sent without credentials or cookies.
- Token images are not loaded by default. They live on https hosts or IPFS gateways chosen by each creator, and fetching one reveals your IP address, the time and which token you are viewing to that host. Every token shows a generated avatar instead. See Token images to opt in for this tab session.
- Your wallet and its RPC provider see the reads and transactions you make. Pick a provider you trust, or run your own node.
Token images#
With Load token images off (the default), the app never requests a token image: lists and token pages show a deterministic gradient avatar derived from the token address. Turning it on fetches each image directly from the URL in the token's on-chain metadata (ipfs:// through the public ipfs.io gateway), without a referrer. The choice is kept in this tab's session storage only, so it resets when you close the tab. Previews of an image URL you type yourself in the launch wizard or metadata editor always load.
Who sees what#
- Indexer
- Serves public chain data. Beneficiary data is only ever served as a full download. It is built without per-user request logging or IP retention.
- Relayer
- Receives signed messages (claims, consolidations, key rotations, pings) and submits them on-chain for a fee taken from the claim. It does not keep per-user logs, but it necessarily sees each request while handling it.
- Attestors
- Only take part in social escrow binds. They verify your account via OAuth, sign a BindOwner message and can veto suspicious binds during the timelock.
- Railgun / PPOI
- Shields are screened against a sanctions list for about one hour. Screening looks at the submitting address (the relayer), not the beneficiary.
Local storage#
The app stores only non-secret preferences in your browser:
- selected network and interface choices such as filters;
- for the current tab session only (session storage), whether you turned on “Load token images”;
- only if you opt in, encrypted claim kits. They are encrypted with AES-GCM under a key derived from your passphrase (PBKDF2-SHA256, 600,000 iterations) and never leave your device. Without the passphrase they are unreadable, including to us.
Clearing your browser data removes all of it. Downloaded claim-kit files are your responsibility to keep safe.
Staying private as a beneficiary#
Use Tor or a trusted VPN
This hides your IP from the relayer, the RPC provider and image hosts.Shield to Railgun, not to a known wallet
Consolidate into USDT and shield (USDT only). Wait out the ~1-hour PPOI standby, then wait longer.Break amount and timing links
Claim round amounts, split withdrawals and never unshield exactly what you shielded right afterwards.Guard the claim link
Anyone with it can claim. Rotate the key if it may have leaked. See the FAQ.