FAQ

Short answers to common questions, with links to the detail.

Can anyone see how much I was paid?

No. A confidential transfer publishes the sender and recipient addresses, but the amount field is ciphertext. Only the sender, the recipient and the auditor key bound to their accounts can open it. See Confidential tokens.

What does a donor learn?

The total sent from the declared lanes inside the declared window, and how many transfers it covers. Not any single amount, and not who received what. See The aggregate proof.

Does the donor need any of the payer's secrets?

No. The donor makes their own disclosure key and nonce, and the proof is sealed to them. The payer's viewing key is never shared.

Can the payer leave a payment out?

Not from the declared lanes inside the window. Every confidential transfer publishes its sender, so the verifier lists the round's transfers from the chain itself. A withheld transfer shows up as one the proof does not cover. See Completeness.

Does the total cover everything the payer spent?

No. It covers transfers from the accounts declared before the round, not the payer's total spend. A payer can run other accounts that were never declared.

Does Tally prove that recipients are independent of the payer?

No. The proof shows what amounts moved, not who controls the receiving accounts. See Roadmap.

Why does a round need at least 5 transfers?

A total over one transfer is that transfer's amount, and a total over two is one subtraction away from it. The circuit refuses to prove below 5 and publishes the count. See Minimum group size.

What happens after about seven days?

Stellar's RPC keeps about seven days of events. After that the published round can no longer be listed from RPC, and tally verify exits with code 3 instead of reporting a failed proof. A durable archive is designed, not built.

Is Tally on mainnet? Is it audited?

No to both. Everything runs on Stellar testnet, on OpenZeppelin's Confidential Tokens developer preview, which is itself unaudited and on an untagged branch.

Who holds the auditor key?

In the testnet deployment, one key generated by the deploy script and stored outside the repository. In the planned operator service, the key would be split two-of-three between the issuer, Tally and an independent custodian. That service is designed, not built. See Key handling.

How many transfers fit in one transaction?

Four from one sender, through a batching contract, measured on testnet. The demo still sends one per transaction. See Measurements.

Does anyone use Tally?

No. Tally has no users, integrations or partners today.

Can I check the published round myself?

Yes, while it is inside the RPC window: clone the repository, run pnpm install, then pnpm verify:evidence. See Quickstart.