Compliance
What Noirpay sees
The data Noirpay processes, the data it is built never to hold, and what that means for legal requests.
Status: pre-launch. Noirpay is being built. This page describes the design as specified in the whitepaper; nothing on it is live on Robinhood Chain yet, and details can change before launch. See What's live today.
Built never to see
| Data | Why not |
|---|---|
| Your balance, positions, cost basis, memos | Notes are encrypted to your spending key and decrypted only in your client |
| Your spending key | Generated and kept on your device; recovery is via guardians, not Noirpay |
| A link between your KYC record and your notes | KYC lives with the licensed ramp (identity separation) |
| A master viewing key | None exists. Every key is issued by the account holder |
Processed to run the service
| Data | Purpose |
|---|---|
| Screening results for shields and unshields | Keeping the pool clean; legal obligations |
| Relayer, paymaster and API request logs | Operating the service; abuse prevention |
| Business account details and seats | Billing the company |
| Association-set publications | Letting withdrawals prove pool hygiene |
Request logs are minimised and retained for a limited period. They record that a proof was submitted, not what it contained.
Legal requests
Noirpay complies with valid legal process. Because notes are encrypted client-side, what it can produce is limited to the processed table above: edge events and operational logs. It cannot produce balances, positions or transaction detail, and it cannot compel a viewing key, because it has none.
Your own disclosure
Everything beyond the processed table is disclosed only by you, through viewing keys and attestations.