Account
The shielded account
Encrypted note balances for USDG and tokenized stocks. Holdings, position sizes and cost basis stay hidden, while everything a bank account does keeps working.
Status: pre-launch. Noirpay is being built. This page describes the design as specified in the whitepaper; nothing on it is live on Robinhood Chain yet, and details can change before launch. See What's live today.
A Noirpay account looks like a neobank account: a handle, a balance, a card, statements. The difference is where the balance lives. Instead of a public wallet address, it is a set of encrypted notes in the shielded pool that only your spending key can open.
What's in the account
| Surface | What it does | Docs |
|---|---|---|
| Shielded balance | USDG and tokenized stocks as encrypted notes | this page |
| Shield / unshield | Screened entry and exit, identity-separated ramps, time-decorrelated exits | Shield and unshield |
| Private yield | Pooled routing into Robinhood Chain venues, credited per note | Yield |
| Card | Visa / Mastercard settling from shielded balance, Apple Pay and Google Pay | Card |
| Payments | Stealth handles, recurring payments, DCA, escrow, memos, invoicing | Payments |
| Vaults | Sub-accounts and note consolidation | Vaults |
| Tokenized stocks | Corporate actions for shielded holders | Tokenized stocks |
| Keys | Spending key, passkeys, hardware wallets, guardians, gas sponsorship | Keys and recovery |
| Disclosure | Viewing keys and attestations | Compliance |
What the explorer sees
| Public wallet on RHC | Noirpay account | |
|---|---|---|
| Balance | Exact, to the cent, for anyone | Encrypted notes; nothing to read |
| Positions | Every token and every size | Hidden, including tokenized stocks |
| Cost basis | Every fill, timestamped | Hidden; each buy settles into a fresh note |
| Salary | Every incoming payment | One line inside a shielded payroll batch |
| Who you pay | Every counterparty, forever | A one-time stealth address per payment |
| Yield | Every deposit and every claim | Credited pro-rata inside the pool |
Client-side by design
Notes are decrypted in your browser with your spending key. The portfolio dashboard, statements and the tax export are generated locally. The Noirpay server never sees your positions (what Noirpay sees).
Encrypted memos
Every transaction can carry a private bookkeeping label. Memos are encrypted with the note, readable only by you or by the holder of a viewing key whose scope covers them.
Self-custodial
Your spending key is generated and kept on your device. Noirpay cannot move your funds, cannot decrypt your notes, and cannot issue a viewing key on your behalf. Recovery goes through your guardians, not through us (keys and recovery).