Privacy

Show the book. Keep the wallet.

You pay for a position from shielded ZEC in your own wallet. The position lives in a one-time account on Robinhood Chain that anyone can read. The wallet that paid stays unlinked from it.

Updated 2026-09-28. Figures that can change carry the date they were read.

What a stranger can read
  • Your position account on Robinhood Chainpublic
  • Every swap and transfer that account makespublic
  • The ZEC amount and time where you enter and leave the railpublic
  • The rail's record of each leg, recipient and refund address includedpublic
  • The wallet that paidunlinked
  • That wallet's balance, history and other addressesunlinked
  • Where your exit ZEC goes after it landsunlinked

What stays unlinked

Nobody watching either chain can see which shielded wallet funded your position, that wallet's balance, history and other addresses, or where your exit ZEC goes after it lands in Ironwood.

The position account itself is public by design. Anyone can read what it holds and every trade it makes on Robinhood Chain.

The unlinking holds when you use every address once. Give the desk a fresh u1 for refunds and another for the exit, and open a new position account for each position. Your wallet hands out new u1 addresses without limit, and without your viewing key nobody can tie them to each other or to your other addresses.

Privacy here keeps a wallet away from strangers, copy traders and anyone reading your posts on X. It keeps nothing from a lawful request, and you decide what to disclose.

What stays public

  • The position account's whole life on Robinhood Chain: the credit from the rail, every swap, every transfer and the exit. A second position on the same account joins the two histories.
  • The amounts and times at both edges on Zcash. At entry the chain shows value leaving the shielded pool for the rail's deposit address. At exit it shows the bridge paying value into Ironwood.
  • The exit payout. The bridge pays with an all-zero outgoing viewing key, so anyone can recover the amount, the receiving address and the memo of every bridge payout and refund (bridge code read 2026-09-28 UTC). A fresh exit u1 keeps that address from leading anywhere else.
  • The rail's record of every leg. 1Click's status endpoint answers anyone who holds a deposit address, with no key, and returns the full quote request, recipient and refund address included. A funded deposit address is public on Zcash, so treat both addresses as public.
  • What MERGER's server and its host see. MERGER's server relays every rail quote, every status check and every chain call and signed transaction the desk makes. So MERGER and Vercel, its host, see your IP address next to the position account, both u1 addresses and the deposit address on each request. MERGER stores none of it. Vercel logs each request with its IP address and its URL, and a status check carries the deposit address in its URL.
  • What the rail operator sees: the request details and every address on the leg, sent from MERGER's server, not from your browser. Its compliance docs say it screens quotes, with TRM Labs on live ones (read 2026-09-28 UTC).
  • Timing. The rail credits a deposit after 5 confirmations on Zcash and pays an exit about 140 seconds after your deposit confirms, so the two sides of each leg line up by time and amount. NEAR's own docs say public-mode deposits and withdrawals "can be matched to each other".
  • Entry and exit, linked through the position account. That link is by design: the position account is the public half of the product.

You can narrow what timing and amounts reveal. Pay in round sizes, wait a while before you exit, and never reuse an address or a position account.

The rail

Funding and exit run through NEAR Intents 1Click in its public, keyless mode. 1Click offers a second mode that stops its own matching of deposits to withdrawals. That mode needs a partner key, which its operator, Intents Technology, grants at its discretion (1Click terms, section 2.9), and it answers 401 without one (checked 2026-09-28 UTC). MERGER has no partner key, so every MERGER quote runs in public mode.

Entry

Each live quote comes with a fresh transparent t1 deposit address. Your wallet pays it from the shielded pool, a shielded-to-transparent send. The Omni Bridge connector credits the deposit after 5 confirmations on Zcash below 2,367.28 ZEC and 15 at or above it (the connector's get_config on NEAR, read 2026-09-28 UTC, applied by the bridge code). Across 12 deposits measured on 2026-09-28 UTC, from inclusion on Zcash in CipherScan's cross-chain history to the bridge's credit on NEAR, credit came 187 to 717 seconds after inclusion. A solver then pays ETH on Robinhood Chain to your position account.

Exit

The position account sends USDG to a 0x deposit address the rail issues for that quote. The bridge pays one Ironwood action to your exit u1, about 140 seconds after the deposit confirms on Robinhood Chain, by the time estimate the rail's exit quotes carried on 2026-09-28 UTC.

Status

MERGER's own status route passes the state to your page and drops the recipient and refund address. 1Click still publishes both to anyone who asks with the deposit address. Every u1 and every deposit address is used once, and the position account links the legs of one position by design.

The keyless fee echoed in each quote was 20 bps on 2026-09-28 UTC. MERGER adds 0 bps. The strip below reads the rail live: what 0.5 shielded ZEC buys right now, with its source and age.

Rail: unread

Ironwood

The NU6.3 upgrade on Zcash activated Ironwood at block 3,428,143 on 2026-07-28. From that block Orchard accepts no new value, and value leaving it can cross the turnstile into Ironwood. A u1 with an Orchard receiver now receives into Ironwood, so the desk's exit and refund payouts land there.

Your Stock Tokens live on Robinhood Chain, in public. No pool on Zcash can hold them today: ZIP 226 and ZIP 227 remain Draft, and ZIP 259, the NU7 scope, leaves them out.

The strip below reads ironwood.live and CipherScan through MERGER's server for the shielded supply, Ironwood's share, the turnstile and the block height, and CoinGecko, Kraken and Binance for the ZEC price, each figure with its source and the time it was read.

Shielded supply: unread

Receipts and proof

A receipt shows a mix by percentage and the week it was made. A size band and the exact day are opt-ins: each detail you add makes a receipt easier to match to one account on Robinhood Chain, and the week with no band gives the least away.

Self-reported
The default. Nobody checked the mix, and the card says so.
Handle proven by post
You post a one-time code from your X account. MERGER takes the handle from the post's author through X's oEmbed endpoint, and one post proves one receipt. This ties your handle to the receipt.

A card never shows an address of any kind, a transaction id, an exact amount or an exact time. The server refuses a receipt that names one, the position account included. A receipt link carries no secret. X keeps every link you post, fragment included, and serves it to anyone, so never post a link that holds a key.

What MERGER keeps

Apart from market snapshots for the book and the rail, MERGER's server stores three things: receipts (the mix, the week or day, the optional band, and for a proven handle the handle, the X post id and the day of the proof), one-use markers that stop a proof post from counting twice (a receipt id and a day under the post id), and rate-limit counts keyed by a hash of the IP address. A receipt holds no address of any kind.

The site sets two signed, httpOnly cookies. Making a receipt sets merger_owner, which marks this browser as the receipt's maker for 24 hours. Starting a proof post sets merger_challenge, which holds the one-time code for 15 minutes.

Your browser keeps, on this device: the encrypted keystore, the desk's step state, a journal of the transactions it signed and SHA-256 hashes of every u1 it used. While a rail leg is in flight it also keeps that leg's deposit address, and a fund leg adds the ZEC amount, the send-before, cold and loss times, your refund u1 in plain text, and the balance and floor it checks the credit against; all of it leaves storage when the leg ends. The ETH the buys spent stays until the receipt's size band is read from it. The journal points at the position account, so anyone who can open this browser can tie that account to you. The server never receives your private key, your passphrase or your keystore. The pages load no third-party script and no analytics.

Vercel, which hosts the site, logs each request with its IP address and its URL, as web hosts do. The desk's status checks put the deposit address in that URL.

What MERGER never does

The site refuses to:

  • send your private key, keystore or passphrase to any server, MERGER's included.
  • hold your funds, sign a transaction for you, or ask for your seed phrase or a viewing key.
  • show a deposit address when the rail's echo of your recipient or refund address differs from what MERGER sent.
  • accept a payout or refund address on Zcash other than a mainnet u1 with an Orchard receiver and no transparent receiver.
  • look up a rail asset by its symbol, or run a live quote before you click.
  • sign a swap without a deadline, a minimum out, chain id 4663 and a passing simulation.
  • trade a token missing from the Robinhood registry, a paused token, or one whose paused() or decimals() it cannot read.
  • take a handle from anywhere but the author of the post, or let one post prove two receipts.
  • put an address on Zcash, a transaction id, an exact amount or an exact time on a card, or draw a card from text in a link.
  • show a price it could not read, or present two issuers' tokens as one thing.

Risks that remain

  • X stores any link fragment in a public post and serves it to anyone. Keep secrets out of posts.
  • 1Click publishes each leg's addresses and pairs its deposits with its withdrawals in public mode.
  • On a quiet chain, a mix under your handle can still point to one account, and a band or an exact day makes that likelier.
  • You trust the JavaScript this site serves for every key operation. The build is not reproducible, so you cannot match the served code to the source.
  • An RPC provider can give wrong answers about quotes and balances. The simulation before each send narrows that risk and leaves some of it.
  • MERGER's server and Vercel see your IP address beside every address the desk sends through them. The RPC providers and the rail see MERGER's server.
  • An X handle can be renamed or taken over after a proof.
  • The rail's operator can screen, freeze or refund by hand.
  • MERGER has not measured how Robinhood Chain's sequencer orders transactions. The minimum out on each swap caps what a reorder can take.
  • Robinhood Chain's terms (section 2.4) bind you not to misrepresent or obscure your identity. The desk unlinks one of your wallets from an account you also own, and changes nothing about who you are to a lawful request.

Stock Tokens are not offered to US persons and are restricted in Canada, the UK and Switzerland. That rule is yours to keep: do not use the desk where it applies to you.