How it works
What stays private
Robinhood Chain is a public ledger. Gloam adds a shielded pool on top. Privacy here means unlinkability and hidden holdings, not that transactions vanish from the explorer. Here is exactly what that does and does not hide.
- Hidden
- the link, the bag
- Public
- deposits + exits
- Anon set
- more users = stronger
- Sealed swaps
- paused (H1)
What an explorer actually shows
This is the part people get wrong, so it is worth stating plainly. Put your own address into the block explorer and you will find your shield deposit: a public transaction from your wallet, into the pool, for the exact amount, and its Shielded event carries your address, the amount, and the note commitment together. Nothing about the deposit is hidden.
The commitmentis a Poseidon hash (a 32-byte value). If you paste it into the explorer search you get nothing back, because it is not a transaction or an address, just a leaf in the pool's Merkle tree. Querying the contract returns only commitmentSeen(commitment) == true. The hash reveals no amount, no secret, and no owner on its own.
The privacy is on the spend. When you later send or cash out, the zero-knowledge proof shows that you own some note in the tree and publishes a nullifier, without revealing which note. So a withdrawal to a fresh address, or a private send, cannot be linked back to your deposit. That unlinkability is the product.
What stays hidden
- The link between your deposit and any later spend or exit
- How much you hold while it is in the vault
- Who paid whom, and how much, on a private send (live on testnet)
What the public still sees
- Each shield deposit: your address, the asset, and the amount
- Each cash out: the asset, the amount, and the destination address
- That the pool was used, the caller of each transaction, and timing
- Every commitment and nullifier as opaque hashes, plus the pool total
The anonymity set is the whole game
A shielded pool hides you in a crowd. If you are the only note of your size, an exit of that size is trivially yours. Today the testnet pool is small, so treat unlinkability as weak until it fills up. This is true of every shielded pool, Gloam included. We would rather say it than let you assume more privacy than you have.
What we will not promise
- Invisibility from law, courts, or a subpoena
- Privacy once you cash out to a public address
- Safety if your device or browser is compromised
- Strong anonymity while the pool has few users
- Recovery if you lose a note secret
Private from the public, not from an operator
Some chains offer privacy through operator-run environments, for example Tempo Zones, where a designated operator sees every transaction inside the zone and only the wider public is kept out. Gloam is a different model. It is a self-custodial shielded pool with no operator in the middle: only you hold the note secret, and only a party you choose sees a balance, through selective disclosure. When Gloam settles a private agent payment over x402, the payer and the payee learn the amount and no one else does. Where a regulated asset needs oversight, compliance visibility is opt-in per payment through an issuer-scoped disclosure, never a standing view handed to an operator.
Security and compliance
Passkey lock (optional)
Your notes are encrypted at rest in this browser under a device key. In Settings you can protect that key with a passkey: Face ID, Touch ID or a security key. Gloam asks the passkey for a secret only it can produce (the WebAuthn PRF extension), uses it to wrap the key, and stores only the wrapped copy. Each time you open the app, the passkey unlocks it. There is no server or account behind this, and removing the passkey asks for it first.
Backups are separate. A backup holds your balances themselves, so restoring one needs only the backup, plus its passphrase if you set one, on any browser. It never needs the passkey. If you lose the passkey, a backup is the only way back. Browsers or passkeys without PRF support keep the device key, unchanged.
Sanctions screening
Before a deposit, and before the relay submits a cash out, Gloam checks the public addresses involved against the OFAC list of sanctioned digital currency addresses: the wallet that deposits, and the address a cash out pays. Nothing private is screened. Notes, receive tags, amounts and private sends are never looked at.
- Against what: a snapshot of the EVM addresses in the 0xB10C OFAC list, built from the OFAC SDN list. It ships with the app with its source commit and date (snapshot of 2026-10-05, 124 addresses) and is refreshed by a script, so it can lag the official list until the next refresh.
- When: in the app before your wallet signs a deposit, on the server at
/api/screen, and inside the relay before it checks or sends anything. - What you see:a blocked wallet gets one neutral message, "This wallet can't use Gloam.", and nothing more.
- Optional: an operator can add the Chainalysis free sanctions API by setting
CHAINALYSIS_API_KEYon the server.
Screening lives in the app and the relay, not in the vault contract, which stays permissionless.
Stablecoin issuer policies on Tempo (TIP-403)
Every stablecoin on Tempo points at a transfer policy in Tempo's TIP-403 registry: open to all, closed to all, the issuer's allowlist or blocklist, or separate lists for senders and recipients. The token checks it on every transfer. Gloam respects it at the only two places value moves: a deposit is a transfer from your wallet into the vault, and a cash out is a transfer from the vault to a public address.
- Deposit: your wallet must be allowed to send the stablecoin, and the vault must be allowed to receive it.
- Cash out:the vault must be allowed to send it, and the destination must be allowed to receive it. If the destination's own Tempo receive policy would refuse the vault, Gloam says so instead of letting the payment be held.
- When: next to sanctions screening, in the app before your wallet signs, at
/api/screen, and inside the relay. These are read-only calls to the chain. A wallet the issuer does not allow sees the same neutral message. - Private sends move no tokens, so the policy never sees them, and nothing private is read.
The token enforces its policy on-chain whatever Gloam does. That makes this compliant privacy with no operator: the issuer keeps its controls at the public edges, nobody sees inside the vault, and there is no Gloam operator in between. As of October 2026 on Tempo Moderato, OUSD and PathUSD both use policy 1, open to all.
Issuer freeze risk.An issuer can also pause its stablecoin, or set a policy that stops the vault itself from sending it. Then no balance in that stablecoin can be cashed out until the issuer lifts it, and nobody, the Gloam team included, can move it out another way. The app reads the vault's standing for each stablecoin, shows it as "Issuer policy" in the "What the explorer shows" card, and warns before you deposit or cash out if the vault is blocked.
No admin withdraw
Nobody, including the Gloam team, can move pooled funds. The vault has no withdraw function for its owner: money leaves only through a cash out that carries a valid proof.
Timelock on rule changes
After setup, every change to how proofs, rates or prices are checked is queued on-chain and can only take effect three days later, in public.
Relay limits
The relay submits only the vault's private send and cash out and the payment message board. It dry-runs every payment first, cannot change a cash out's recipient or amount (both are bound in the proof), and rate limits each device and each network.
Before mainnet
Gloam is testnet only today, and there are honest gaps we will not ship to real value without closing:
- Dev-ceremony proving keys. Mainnet needs a real multi-party trusted setup and an external audit.
- Sealed swaps are disabled pending the H1 solvency fix.
See the production gate for the full list. More detail: How shield works and the whitepaper.