OpaqueApp

Docs/Introduction

Who sees what

The complete visibility table.

Privacy claims are only useful when they are exact. This is the exact table.

ViewerDeposits and withdrawalsYour balanceTransfers insideWho is behind a note
Anyone reading the chainVisibleHiddenHiddenHidden
Opaque's servers and relayerVisibleHiddenHiddenHidden
One auditor, aloneVisibleHiddenHiddenHidden
Someone you paidVisibleHiddenThe one note you sent themHidden
YouVisibleVisibleVisibleVisible
Both auditors, togetherVisibleVisibleVisibleVisible

Notes on each row

Anyone reading the chain sees a stream of commitments, nullifiers and proofs. None of them carries an asset, an amount or an owner.

Opaque's servers index the same public stream and relay transactions you have already proven. They never receive a key. The app downloads every leaf and every nullifier and matches them on your device, so the server cannot tell which notes belong to whom.

One auditor, alone holds one share of the audit key. A single share decrypts to noise.

Someone you paid receives one note and the key to read it. They learn its amount and that it came from a proof; they do not learn your balance, your other notes or your history.

Both auditors, together can open the sealed record attached to any transaction, one transaction at a time. See The audit key.

Deposits and withdrawals

The amounts and addresses at the pool's boundary are public. If you deposit 12,340 shares and someone withdraws exactly 12,340 shares an hour later, the chain has not linked the two, but a careful observer may guess. What Opaque does not hide covers this in detail and how to shape your activity around it.