Leave straight into Zodl.
Unshield to a unified u1… address. A one-purpose forwarder can only pay the swap solver; real shielded ZEC lands on Zcash in minutes.
Every swap, every payment, every balance sits in a ledger any stranger can read — indexed, searchable, permanent. nullvisor gives your funds somewhere to disappear: provable to the contract, invisible to everyone else, and one step away from Zcash.
The same private payment, from both sides of the visor. The explorer gets a relayer and a proof. You keep the rest.
Sign once to unlock your shielded account, then deposit ETH or USDG. It becomes an encrypted note only your keys can open.
Pay any nvs1… address with an encrypted memo. A relayer posts the proof — your address never touches it.
Leave in waves: withdrawals gather and go out together, shuffled, so timing gives nothing away.
Unshield to a unified u1… address. A one-purpose forwarder can only pay the swap solver; real shielded ZEC lands on Zcash in minutes.
Pay a QR in ZEC and it arrives here as a private dollar note. A one-off claim key signs the shield, so nobody who sees it can redirect it.
Spend key → nullifier key → address. Hand an auditor a viewing key that sees everything and spends nothing.
Every note carries a fixed-size encrypted memo — readable by one person, invisible to everyone else.
Privacy that depends on an operator behaving is a promise. These are properties of the code.
Derived from a wallet signature, held in memory only. The server never sees them and cannot read your balance.
The pool is not a proxy. Nobody can swap its logic; only a valid proof moves pooled funds.
The guardian can only cap new deposits. Unshielding always works — even if this site disappears.
Notes are private, totals are not. In minus out equals the contract balance, per asset, for anyone to check.
Privacy isn't hiding. It's deciding who gets to look.