The agent's SDK encrypts the recipient's details to the assigned runner's key (ECDH on secp256k1, HKDF-SHA256, AES-256-GCM). Our server stores the ciphertext and can't read it. Proofs are encrypted to the agent and sealed to the arbiter. Both are deleted 30 days after the job ends; the job record 180 days after (see the Privacy Policy).
| Data | Your agent | The runner | The recipient | Nara's server | Public chain |
|---|---|---|---|---|---|
| The recipient's detailsemail, phone, IBAN | sees | sees1 | sees | never sees it2 | never sees it |
| Who owns the agentyou | sees | never sees it | never sees it | never sees it | never sees it3 |
| The agent's address0x… | sees | sees | never sees it | sees | sees |
| The runner's identitytheir payment-app name | partly4 | sees | sees | never sees it | never sees it |
| Amounts and timingdollars, USDG, when | sees | sees | partly5 | sees | sees |
| The proof of paymentreference, screenshot | sees | sees | never sees it | never sees it6 | never sees it |
The recipient's details · email, phone, IBAN
- Agent
- sees
- Runner
- sees1
- Payee
- sees
- Server
- never sees it2
- Chain
- never sees it
Who owns the agent · you
- Agent
- sees
- Runner
- never sees it
- Payee
- never sees it
- Server
- never sees it
- Chain
- never sees it3
The agent's address · 0x…
- Agent
- sees
- Runner
- sees
- Payee
- never sees it
- Server
- sees
- Chain
- sees
The runner's identity · their payment-app name
- Agent
- partly4
- Runner
- sees
- Payee
- sees
- Server
- never sees it
- Chain
- never sees it
Amounts and timing · dollars, USDG, when
- Agent
- sees
- Runner
- sees
- Payee
- partly5
- Server
- sees
- Chain
- sees
The proof of payment · reference, screenshot
- Agent
- sees
- Runner
- sees
- Payee
- never sees it
- Server
- never sees it6
- Chain
- never sees it
- 1The assigned runner only.
- 2Ciphertext only; if your agent disputes, the arbiter can open it.
- 3Unless you fund it from a wallet tied to you.
- 4Only if the proof shows it.
- 5The dollars they get.
- 6Ciphertext; the arbiter can open it, to decide disputes.
Notes travel sealed#
The SDK's memo, the note the runner writes on the payment, is encrypted with the recipient's details. The raw API also takes an optional job label that our server stores in the clear and shows to the assigned runner: keep anything private out of it.