Sigilo Open Sigilo

How Sigilo works

Sigilo is a chat app for frontier AI models that you pay for from a private balance on Robinhood Chain. It is built so that your payments and your conversations never meet: the chain cannot see what you bought, and Sigilo never learns which wallet paid.

The privacy boundary

FactWho can learn it
That a wallet deposited into the pool, and how muchEveryone. Deposits are public transactions.
That a pool note paid Sigilo for creditNobody but you and Sigilo. On-chain it is a private transfer like any other.
Which wallet funded a credit purchaseNobody. The zero-knowledge proof hides which deposit the payment came from.
What you type and what the model answersSigilo's server while it relays the request (not stored), and the model provider while it answers (zero-retention endpoints only, under Sigilo's account).
Your saved conversationsOnly your browser. They are encrypted with a key derived from your recovery phrase.
Your IP addressSigilo's server while it answers you. It is not logged; rate limits use a salted hash held in memory.

Two kinds of guarantee are mixed here, and you should know which is which. The payment privacy is cryptographic: it holds even if Sigilo's servers are hostile. "Not stored" and "not logged" describe the software Sigilo runs; you are trusting that. If that matters to you, use a VPN or Tor. Every model request asks OpenRouter for zdr: true and data_collection: "deny", so only providers that keep no data serve it; a model without such an endpoint is hidden rather than used.

Privacy in a pool grows with the number of people using it. A new pool is a small crowd: deposit, wait, and avoid buying credit for exactly the amount you deposited.

Private credit

  1. Shield. Your browser deposits ETH from any wallet into the Sigilo pool, as a private note only your phrase can spend.
  2. Invoice. Sigilo prices your credit in ETH at the median of public exchange rates and holds that price for 15 minutes.
  3. Pay. Your browser proves a private transfer to Sigilo's receive address. The proof is bound to that one invoice, so it can never be replayed against another. A relay submits it and pays the gas from a fee inside the proof, so your wallet never appears.
  4. Credit. Sigilo's server checks, with its viewing key, that the payment really pays its address, relays it, and credits your pass once the network confirms. The link from the invoice to your pass is then erased.

A pass is a secret derived from your phrase. The server stores only its SHA-256 hash and the balance. Each reply costs the provider's reported price plus 15%, held before the answer and settled to the actual cost after. If a model fails before answering, nothing is charged. Credit cannot be converted back to ETH.

Recovery, with or without Sigilo

Your 24-word phrase derives everything: the keys to your private ETH, your credit pass and the key to your saved conversations. Restore it in Sigilo on any device to get all of it back (conversations are stored per browser, so they come back only on a device that holds them, or from an encrypted backup file).

The pool contract has no owner and no upgrade path. The app ships its proving files and contract list, so with your phrase and any public Robinhood Chain node you can rescan your notes and withdraw your ETH without any Sigilo server. Unspent credit lives on Sigilo's service and does not survive the service.

$SIGILO and the holder allowance

$SIGILO launches on PONS V2 on Robinhood Chain. Its PONS creator fees are split: half funds the monthly holder allowance, half pays for model credit, relay gas and servers.

Each month Sigilo publishes a budget and a snapshot block. A wallet's allowance is budget × holding at the snapshot ÷ circulating supply, capped per wallet, with a minimum holding so dust is skipped. You claim it in the app by signing a message with the holding wallet; the allowance lands in a separate allowance pass. Because you signed, that allowance is linked to your wallet. Your private credit is not.

You never need $SIGILO to use Sigilo. Holding it gives no share of revenue beyond the allowance, no governance and no promise of price.

Acceptable use

Use Sigilo lawfully. Every request goes to a model provider whose own safety rules apply; the provider refuses what breaks them. Privacy here protects ordinary people from having their questions tied to their money; it is not a shield for abuse.

Contracts and code

The Sigilo pool runs the same contract code as Veilport's live pool on Robinhood Chain, renamed. It reuses that deployment's Groth16 verifier, Poseidon hashers and WETH, all ownerless; the deploy script checks the verifier's bytecode against the proving key and the hashers against a reference implementation before trusting them. The trusted setup record is published here.

The pool's only role, a deposit guardian, can change how much new ETH the pool accepts. It can never touch notes already inside. The contracts have not had an independent audit.