Account

Shield and unshield

How money enters and leaves the pool: licensed ramps with identity separation, a bridge, screening at both edges, and exits that can't be matched to entries.

Status: pre-launch. Noirpay is being built. This page describes the design as specified in the whitepaper; nothing on it is live on Robinhood Chain yet, and details can change before launch. See What's live today.

Ways in

RouteWhat happens
Fiat on-rampA licensed provider performs identity checks and converts fiat to USDG. The provider holds your KYC record; Noirpay does not link it to your notes (identity separation).
BridgeUSDG or tokenized stocks bridged to Robinhood Chain from another chain, then shielded.
Direct shieldUSDG or stock tokens already in a Robinhood Chain wallet, deposited into the pool.
Incoming paymentA payment to your stealth handle or an invoice link shields itself on arrival.

Every route passes edge screening before a note is minted.

Identity separation

KYC happens at the ramp, under the ramp provider's license. The ramp knows who you are and that it sent USDG to the pool. The pool knows a screened deposit arrived. No single party holds both halves of the link between your identity and your notes, and Noirpay does not store it.

Ways out

RouteWhat happens
Fiat off-rampUnshield to a licensed provider that pays out to your bank.
Unshield to a walletWithdraw USDG or stock tokens to a Robinhood Chain address.
Card settlementNot an unshield: the card settles from shielded balance at the pool level.

Exits are screened the same way entries are, and each withdrawal can carry an association-set proof showing it isn't linked to tainted deposits.

Time-decorrelated withdrawals

The simplest way to link a shield to an unshield is timing: same amount, an hour apart. Noirpay breaks that by default:

  • Scheduling. An exit is placed in a queue and executed inside a randomised window you set (minutes to days).
  • Splitting. A withdrawal can be split into several partial exits of uneven size.
  • Amount decorrelation. Exits draw from consolidated notes, not from the note that was shielded.

You can turn this off for a specific withdrawal when speed matters more than unlinkability; the app tells you what you're giving up.