Account
Shield and unshield
How money enters and leaves the pool: licensed ramps with identity separation, a bridge, screening at both edges, and exits that can't be matched to entries.
Status: pre-launch. Noirpay is being built. This page describes the design as specified in the whitepaper; nothing on it is live on Robinhood Chain yet, and details can change before launch. See What's live today.
Ways in
| Route | What happens |
|---|---|
| Fiat on-ramp | A licensed provider performs identity checks and converts fiat to USDG. The provider holds your KYC record; Noirpay does not link it to your notes (identity separation). |
| Bridge | USDG or tokenized stocks bridged to Robinhood Chain from another chain, then shielded. |
| Direct shield | USDG or stock tokens already in a Robinhood Chain wallet, deposited into the pool. |
| Incoming payment | A payment to your stealth handle or an invoice link shields itself on arrival. |
Every route passes edge screening before a note is minted.
Identity separation
KYC happens at the ramp, under the ramp provider's license. The ramp knows who you are and that it sent USDG to the pool. The pool knows a screened deposit arrived. No single party holds both halves of the link between your identity and your notes, and Noirpay does not store it.
Ways out
| Route | What happens |
|---|---|
| Fiat off-ramp | Unshield to a licensed provider that pays out to your bank. |
| Unshield to a wallet | Withdraw USDG or stock tokens to a Robinhood Chain address. |
| Card settlement | Not an unshield: the card settles from shielded balance at the pool level. |
Exits are screened the same way entries are, and each withdrawal can carry an association-set proof showing it isn't linked to tainted deposits.
Time-decorrelated withdrawals
The simplest way to link a shield to an unshield is timing: same amount, an hour apart. Noirpay breaks that by default:
- Scheduling. An exit is placed in a queue and executed inside a randomised window you set (minutes to days).
- Splitting. A withdrawal can be split into several partial exits of uneven size.
- Amount decorrelation. Exits draw from consolidated notes, not from the note that was shielded.
You can turn this off for a specific withdrawal when speed matters more than unlinkability; the app tells you what you're giving up.