Compliance

What Noirpay sees

The data Noirpay processes, the data it is built never to hold, and what that means for legal requests.

Status: pre-launch. Noirpay is being built. This page describes the design as specified in the whitepaper; nothing on it is live on Robinhood Chain yet, and details can change before launch. See What's live today.

Built never to see

DataWhy not
Your balance, positions, cost basis, memosNotes are encrypted to your spending key and decrypted only in your client
Your spending keyGenerated and kept on your device; recovery is via guardians, not Noirpay
A link between your KYC record and your notesKYC lives with the licensed ramp (identity separation)
A master viewing keyNone exists. Every key is issued by the account holder

Processed to run the service

DataPurpose
Screening results for shields and unshieldsKeeping the pool clean; legal obligations
Relayer, paymaster and API request logsOperating the service; abuse prevention
Business account details and seatsBilling the company
Association-set publicationsLetting withdrawals prove pool hygiene

Request logs are minimised and retained for a limited period. They record that a proof was submitted, not what it contained.

Noirpay complies with valid legal process. Because notes are encrypted client-side, what it can produce is limited to the processed table above: edge events and operational logs. It cannot produce balances, positions or transaction detail, and it cannot compel a viewing key, because it has none.

Your own disclosure

Everything beyond the processed table is disclosed only by you, through viewing keys and attestations.