Privacy model
Hide participants. Prove the market.
A privacy protocol earns trust through clarity. This page says exactly what is private today, what is still visible, what our infrastructure can see, and what changes when native shielded assets arrive.
Wallet identity
Private
Trade size
Private
Portfolio
Private
Market rules
Verifiable
What is private today?
ShieldedShielded ZEC participation
Deposits and withdrawals move through Zcash shielded pools. On-chain observers see a payment to the reserve, not who you are.
One key per market
Every asset and reference market is held under its own key derived from your seed — never an address, never one identity across markets. The ledger cannot link your markets to each other or to your social identity.
Client-side portfolio
Balances and positions are published as encrypted snapshots on one common feed that everyone downloads identically. Your browser opens only its own. There is no server read of what a wallet holds and no way to learn which markets you scan for.
No public whale leaderboard
Launched assets publish a holder distribution (counts, top-1/top-10 share) — never addresses or per-holder balances.
No portfolio profiling
Your portfolio, positions, entry prices and history are returned only to your own proven claim-key. There is no public portfolio page for anyone.
Pseudonymous social
Comments, feed and chat use per-token BLAKE2b pseudonyms. No wallet-to-identity mapping exists on the platform.
No trackers
No analytics scripts, no fingerprinting, a strict content-security policy, and the frontend only talks to ZecPad's own API.
What is still visible?
Reserve inflows on-chain
A shielded payment to the reserve is visible as a shielded transaction with a hidden sender. On the transparent testnet reserve, amounts and t-addresses are public.
Aggregates
Per-market open interest, open-position counts and 24h volume; per-asset supply, holders count, distribution shares and an anonymous trade feed. The settlement feed itself is public but shows only tags and ciphertext.
Launched-asset ledger
In the pre-ZSA model, ZPAD-20 asset balances are an application ledger settled from on-chain memos. Supply is verifiable; balances are keyed by claim-key, not address.
Timing
The time a trade or entry happened is visible in aggregate feeds. Amount buckets can be inferred from curve moves.
Network metadata
Your IP reaches the API and the lightwalletd endpoint like any web app. Use Tor or a VPN if that matters to you.
Level 1 (public privacy) ships today, plus the first step of Level 2: per-market keys, commitments and encrypted snapshots on a common feed, client-side reconstruction. Not yet: nullifier-based spends and zero-knowledge proofs that would hide balances from the platform itself.
What can ZecPad infrastructure see?
What the server stores
Per-market key → balance / lots (it must, to run the curve and enforce caps), the encrypted feed snapshots, and a per-market trade log. Comments and posts under pseudonyms. Uploaded coin images.
What the server can link
A market key to its own activity in that one market. It holds no mapping from market keys to a person or to each other, and no seeds, viewing keys or addresses for positions. Linking is only possible through network metadata (IP, timing) or a voluntary reward-claim link you sign.
What operators can see
Aggregates, reconciliation snapshots and solvency reports. Payout addresses for sells are user-supplied and treated as private operator data.
What is encrypted
Shielded memos on-chain. The claim-key can be encrypted at rest in your browser (optional passphrase). The server database is not end-to-end encrypted in the pre-ZSA model.
Honest summary: in the pre-ZSA model you trust ZecPad's settlement layer to settle each market honestly, the same way you trust it to settle the curve. It sees each per-market balance when it settles it; it does not see your portfolio, your identity, or which markets you scan. You do not trust it with your wallet keys. The reserve spending key never lives on the API host.
What changes with ZSA?
Native shielded custom assets
Launched assets (JENSEN, EVKING…) become native Zcash Shielded Assets you custody directly, instead of application-ledger balances.
Private multi-asset balances
Asset balances live in your shielded wallet, not on the platform — the platform no longer holds per-user asset state.
Native shielded transfers
Asset-to-asset and asset-to-ZEC moves become shielded transactions with the same privacy as ZEC.
More complete private markets
Reference-market representations and private asset-to-asset pairs become possible once issuance, custody and settlement structures actually exist.
ZSA is not the beginning of ZecPad; it is the upgrade that turns the application-level private market into a native multi-asset private market layer. The pre-ZSA architecture is designed to migrate without a redesign.
What is provable?
Supply
Every launched asset has a fixed 1B supply with 800M on a deterministic curve. State derives from one field (ZEC raised) and anyone can recompute it.
Noted balances (homomorphic)
Every private note carries a Pedersen commitment; the sum over live notes must equal the published per-market totals plus the blinding sum. Verifiable from the public feed by anyone, revealing no amounts.
Creator allocation
The creator's launch buy is capped at 5% of curve supply and vested. A privacy-preserving 'dev sold' signal is published without revealing the creator.
Reserve
The reserve publishes its full viewing key. Anyone can recompute inflows and outflows on-chain and check them against liabilities — including open market positions.
Oracle
Every market shows its price source, timestamp, staleness limit and session state. Settlement is refused on stale or unavailable data.
Fees
Flat, published rules: 1% on curve trades, 0.30% on market entry and exit, a flat launch fee. Shown before you confirm.
Your own holding (selective disclosure)
You can prove a balance to anyone by opening your live note; they verify the commitment, your key's signature and the note's liveness against the public feed. The server is not involved.
Holder limit (range proofs)
Assets launched with a holder limit publish one range proof per live note: 0 ≤ balance ≤ cap over the note's Pedersen commitment (bit decomposition + Schnorr OR-proofs, no trusted setup). Verifiable in your browser on /verify. Trade-off: those proofs reveal which note tags hold that asset — never amounts or owners.
Indexed market collateral
Every indexed market publishes its base liability, worst-case liability (1.30× band), real reserve, segregated vault, collateral ratio and remaining capacity. Buys are refused when CR would fall below 110%; sells are always payable.
Solvency (ZK)
Reserve solvency is reported from the published viewing key today. Cryptographic solvency proofs over encrypted state are roadmap.
Language we hold ourselves to
- ✓ Private ZEC-settled market exposure
- ✓ Shielded participation
- ✓ Real-world price reference
- ✓ Reference-linked market
- ✓ Provable market integrity
- ✓ Native shielded assets when ZSA is available
- ✗ “100% anonymous stocks”
- ✗ “Buy real shares invisibly”
A market position is economic exposure to a reference price. Only a future, legally structured, custody-backed representation would ever be described as backed by the underlying asset.