How a Transfer Works
Every Cyphron account combines two pieces: a Robinhood Chain smart account that you custody yourself, and confidential token contracts that keep each payment's amount secret. You hold the keys. Settlement is final in a fraction of a second. The amount is encrypted on your device before anything is sent.
The parties to a payment are always visible. The amount never is.
From tap to settlement
You compose the transfer in the app
↓
The Privacy Engine generates a ZK proof on your own device
↓
Ciphertext and proof go to Robinhood Chain
as a confidential token transfer
↓
The verifier contract checks the proof and updates both encrypted balances
↓
Both addresses are written to the public record.
No observer can read the amount.
↓
Sender and recipient each decrypt it using keys only they control
↓
About 100ms later, the payment shows in both activity feeds
The proof shows three things: the encrypted amount is well-formed, it is not negative, and the sender's balance can cover it. It is built entirely on the client. No Cyphron server ever receives your plaintext balance or the amounts you send, whether while you are typing, in transit, or at rest.
What goes on-chain
A transfer produces one Robinhood Chain transaction containing:
- The sender's address
- The recipient's address
- An ElGamal ciphertext in place of the amount
- A zero-knowledge proof of validity
- The block number and timestamp
All of these can be looked up by anyone using the block explorer. Anyone can verify the payment happened; nobody else can see how much it was for. Everyone can audit it, but only two parties can read it.
Where the boundaries sit
Visible to all: the two addresses, which token was used, and the simple fact that a transfer happened.
Encrypted: how much was sent and the balances that follow.
Never available to Cyphron: your plaintext balance, your plaintext amounts, and your decrypted history. The only exception is a disclosure you choose to create for a counterparty or a regulator.
Cyphron's servers relay requests, render the interface, and monitor chain events. They hold none of your keys and no readable version of your balance. That is guaranteed by how the system is built, not by a promise in a policy.
Real-time updates
An indexer run by Cyphron tracks contract events and keeps the app's view up to date, so nobody needs to poll the chain. Status changes, such as a transfer going from submitted to settled, are pushed over a WebSocket as soon as the block is produced.
Read on
- Account Types: find the account type that suits your use
- How Amounts Stay Encrypted: the full cryptographic picture