| The coin, its pool, its fee F and its quote token | Public | TokenLaunched event |
| The creator's launch address | Public | The sender of the launch transaction |
| Every trade, trader address and amount | Public | Like any DEX trade |
| Holders and balances of the coin | Public | Standard ERC20 |
| The dev buy | Public | DevBuy event |
| Fees generated, and the protocol / beneficiary amounts | Public | Auditable by design |
| The beneficiary id | Public | An opaque 32-byte hash |
| The beneficiary id's balances | Public | balanceOf(id, asset) |
| Who the beneficiary is (stealth key) | Hidden | Known only to the creator and whoever they gave the claim link to |
| Who the beneficiary is (social escrow) | Hidden from the chain | Every attestor of the committee can decrypt the hint on its own (threshold 1), so each of them knows |
| Who the beneficiary is (public social recipient) | Public | The platform account is named in a plaintext hint, with an attestor-signed label. Its per-account totals across coins are public. |
| The wallet of a public social recipient | Hidden | Bound to a fresh signing-only key; exits are shielded only (relayer and UI refuse direct claims) |
| What the coin's name, ticker, image and description say | Public | Often names the beneficiary. zk-pad cannot hide what the creator writes. |
| The beneficiary's wallet | Hidden | The stealth key is never funded and never sends a transaction |
| That a claim happened, its amount, asset, time, relayer and relayer fee | Public | Claimed event |
| A direct claim's destination address | Public | Use a fresh address |
| A Railgun claim's 0zk address | Hidden | Only the recipient's Railgun wallet can read the note |
| What happens to a shielded note afterwards | Hidden | Subject to Railgun's anonymity set on BSC |
| The stealth owner address | Public once registered | Revealed in the registration calldata. It is a throwaway key that never holds funds. |
| Social escrow bind: the new owner key and timelock | Public | BindProposed / BindFinalized events |
| The beneficiary's IP address | Visible to the relayer, attestor and RPC you contact | Unless you use Tor or a similar network. Services keep no per-user logs, but you are trusting that. |
| Which id you looked up | Hidden | The SDK downloads every id's balances and nonces (fetch-everything) and filters locally; the web app makes no id-specific RPC reads (consolidation prices come from one fixed batch of unit oracle quotes, the same for every visitor) |
| Your claim link or stealth key | Hidden from servers | Kept in the URL fragment, which browsers never send. Claim-kit files get random names, and search boxes refuse pasted keys and claim links instead of putting them in a URL. |