Privacy by default
A privacy system is strongest when ordinary use does not create a visibly weaker transaction class.
Sovereign money
Financial privacy is not concealment for its own sake. It is control over who can map your identity, balances, relationships, and behavior.
Primary reading
This page is an original synthesis of the book, not a replacement for it. The book's text is licensed CC BY-NC-SA 4.0. No cover art or book illustrations are reproduced here.
Read the original PDFFirst principles
A privacy system is strongest when ordinary use does not create a visibly weaker transaction class.
Money works better when equal units remain interchangeable instead of inheriting public transaction histories.
Control follows the private spend authority. Backups and recovery are therefore part of the security model.
Open code, independently checked software, and a validated node path reduce hidden third-party assumptions.
Privacy stack
Ring signatures obscure which eligible output was actually spent, providing plausible deniability for the source.
One-time stealth addresses prevent a published receiving address from appearing directly on the blockchain.
Ring Confidential Transactions conceal values while allowing the network to verify balance and prevent inflation.
Dandelion++ helps at the node layer, but it is not complete IP protection. Stronger network privacy requires an intentional Tor or I2P path.
Trust boundaries
The mnemonic or private spend key can recreate spending control. Keep it offline, private, and recoverable.
A private view key reveals incoming transaction visibility. Treat disclosure as a deliberate privacy decision.
A remote node cannot spend funds, but it can observe connection metadata and affect availability. A validated local node reduces that reliance.
2026 correction layer
Operating rules
Reading path