Privacy

This page describes the privacy model for zk.money. For more information, see the Privacy Policy.

In general, what happens inside zk.money is private. Whatever crosses the edge of the system, into and out of Ethereum, is not private. That is true of every Ethereum transaction, and is not particular to zk.money.

Who can see your funds

An enclave can never spend your funds, and nobody can read what it sees. Your wallet encrypts each operation to the enclave, and the enclave opens it inside a sealed server only to co-sign it. Co-signing is what it checks the operation for; it never receives your signing key. The company running the machine around the enclave sees only encrypted bytes and their sizes: not your balance, and not your payments.

A payment between two zk.money users is not public. No amount and no name reaches a public chain.

A payment link carries nothing to a web server. Everything a link holds sits after the # in the address, which a browser never sends to a server. An email link names a Google or Apple address, and the claimer's browser proves that address with a zero-knowledge proof, so the address itself stays offchain.

Ethereum is public. Funds enter from an Ethereum address and leave to an Ethereum address. Those amounts and addresses are public. The tie between a deposit address and you is not, because that address comes from a shared secret.

The tag-to-address link is public. The AccountRegistry on Ethereum holds your Aztec address, your Ethereum account address, and a public key. Your tag is stored as a hash, so an address cannot be turned back into a tag. But anyone who knows or guesses your tag can compute that hash and read your addresses. Treat your tag as public.

Your messaging address is public and permanent. zk.money publishes an XMTP binding on Ethereum when it creates your account, every time, with no setting to turn it off. You can overwrite the value, but you cannot erase the history.

Two services see slightly more than the chain does. The Aztec node your wallet reads from can tell that one account is behind a set of note requests, which links those requests to each other. When someone outside zk.money pays your tag, the resolver sees that sender's network address, your tag and address, and the amount. Neither one sees your balance, and neither can move anything.

What you can do about it

  • Your tag is public, and so is the address behind it. Anyone who knows your tag can look up your Aztec address. They cannot see your balance, your payments, or who you pay. But if you pick a tag people already associate with you, they can tell the account is yours.
  • Deposits and withdrawals are visible on Ethereum, like any other Ethereum transaction: the address, the amount and the time. If you deposit from an exchange account in your name, that exchange knows you funded zk.money. If you withdraw to an address already tied to you, the destination is tied to you.
  • A deposit and a withdrawal of the same size, close together, invite a guess, even though no contract links the two.
  • Do not use a deposit address twice.

What zk.money services keep

zk.money's services see operational metadata — a deposit-address request, a tag claim, a rate-limit counter — and never your balance or what a payment inside zk.money says.

The account service that signs your tag claim keeps a hash of the name, the account address it was issued to, a nonce, the signature it issued, and timestamps. It also keeps rate-limit counters keyed by a hashed client identifier, which expire with their window.

The web wallet is a static site with no server of its own. It sends usage events to zk.money's analytics only if you turn them on, and the deposit and screening events never carry an address.

An error report is different. You choose to send one, and it goes whether or not analytics is on. A report can quote your tag or an address in its free text, and it travels under its own identifier, so it cannot be joined to your usage events.