What XEROPAY sees
Client-side portfolio. No master viewing key. Edge sees deposits and withdrawals — not your notes.
Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.
| Component | Sees | Does not see |
|---|---|---|
| Client | Everything, locally | — |
| Pool (when live) | Commitments, nullifiers, proof validity | Amounts, owners, assets |
| Edge screener | Deposit and withdrawal addresses | Notes inside the pool |
| Relayer / paymaster | That a proof was submitted | Note contents |
| XEROPAY servers | Account metadata you choose to store | Decrypted balances |
No master key
Every disclosure is scoped, time-boxed, and issued by you. Support cannot “just look.” If a future jurisdiction required a back door, that would be a different product — and these docs would say so.
Metadata we may hold
Email for the waitlist. Workspace members for business seats. Webhook endpoints you configure. That is not a shadow ledger of notes.
