Trust model
Every party that touches a payment, what it learns, and what it cannot do. Including us.
A privacy tool is only as honest as its list of who can see what. This page names every party involved in receiving and spending with ephemeral.
Summary
| Party | Sees | Cannot see or do |
|---|---|---|
| Anyone on-chain | Sender, amount, time, the one-time address, the announcement, every later move from it | That the address is yours, unless you link it |
| The sender | The one address they paid | Your other payments or your balance |
| Your RPC provider | Your IP and the addresses your client queries | Your keys |
| The name gateway next | Which addresses it issued for your name, and the IP of the lookup | Your keys or existing funds. If compromised, it could misdirect new payments to a name |
| A viewing-key holder | Every payment to you and its amount | Spend anything |
| The ephemeral team | Nothing from your client. As operator of the name gateway: the addresses issued for your name | Your keys; we cannot move funds |
| You | Everything, with your keys | Nothing is hidden from you |
The chain
Everything on Ethereum is public forever. A stealth payment shows the sender, the amount, the time and a brand-new address. What it does not show is the link between that address and you. That link exists only in the shared secret, which takes your viewing key or the sender's one-time key to compute. See Stealth address math.
The sender
The sender knows the address they paid, because they computed it. They cannot compute any other stealth address of yours, and they cannot spend from the one they paid.
Your RPC provider
To scan, your client downloads announcements. That reveals that you use stealth payments, but not which announcements are yours: the check happens on your device. Reading balances and sending withdrawals does reveal the addresses involved, together with your IP. If that matters to you, use your own node or a private RPC.
The name gateway
A private name resolves through an ENS offchain resolver (EIP-3668). The gateway behind it computes a fresh stealth address from your public meta-address for each lookup and publishes the announcement, since a sender with an ordinary wallet will not. It therefore knows which addresses it issued for your name, and the IP of each lookup. We run this gateway. It never holds a private key and cannot move funds that already landed. If it were compromised, it could hand out an address it controls for new payments to a name; the defences are on Private names. A sender who wants zero trust can pay your raw meta-address instead.
The viewing key
Anyone with your viewing key can find every payment to you. That is by design: it is how you give an accountant read-only access. It can never move funds. If it leaks, publish a new meta-address and future payments use new keys.
The ephemeral team
We run no server that holds keys, no pool, and no contract in the payment path. We cannot see the payments your client finds, and we cannot freeze or move any payment. The one exception to what we see is the name gateway above. If we disappear, your payments stay yours: any ERC-5564 client with your keys can find and spend them.
What you trust
- The cryptography of secp256k1 and keccak256.
- Your device and your wallet.
- That the client you run is the published one. Once its source is published, verify it or run it yourself.