MarblePrivacy

Documentation

MarblePrivacy is a workspace for your wallet, your data, and what you choose to reveal. It has four tools and one rule: it describes what it does, and nothing more. This page says what each tool does, what it stores, where requests go, and where each protection ends.

Overview

ToolWhat it doesWhere the data comes from
Wallet InspectorReads a public address, a transaction, a call you are about to sign, or an approval. Read-only except for revoking an approval you choose to revoke.Live data: JSON-RPC through this site’s relay, plus an explorer index for history and tokens
Notes VaultPrivate notes, optionally about an address or a transaction, encrypted with a passphrase.Local only: this browser’s IndexedDB
Screen PrivacyConceals balances, addresses, hashes and amounts in the interface.Local only: a preference in this browser
Stealth AddressesERC-5564 on Robinhood Chain: derive keys, register, send to and receive at one-time addresses.Live data: the Announcer and Registry contracts on chain 4663

Privacy explanation

Every piece of information in this product lives in one of four places. Which one decides who can see it.

PlaceWhat is thereWho can see it
Public on-chainAddresses, balances, transfers with their amounts and times, token approvals, contract calls, stealth announcements and registrations.Everyone, permanently. Nothing in MarblePrivacy changes that.
Stored in this browserThe vault (ciphertext, plus its salt, IVs and sizes), preferences, the local activity log, a cache of public stealth announcements, the wallet connector’s last state.Whoever has this browser profile. Notes are unreadable without the passphrase.
Sent to providersWhat you look up: an address, a transaction hash, calldata, a contract address, a 4-byte selector. A stealth withdrawal you signed.This site’s server, then the RPC provider, the explorer index, Sourcify or the selector database. They see the query and the server’s address, not yours — unless you set your own RPC, which then sees you directly.
Hidden only on screenWhatever Screen Privacy conceals.Not the person looking at your screen. Everyone listed above sees what they saw before.

What this does not make private

What is never claimed

Anonymity, untraceability, zero-knowledge protection, mixing, private execution or private trading. None of them is implemented, so none of them is offered. The single on-chain privacy mechanism is stealth addresses, and its guarantee is narrow: see below.

Hosting

A hosting provider keeps ordinary access logs (IP address, time, path) like any web host. Address lookups for history and tokens travel in the request body, not in the path. The application adds no identifiers, sets no cookies and loads no analytics or third-party scripts.

Wallet Inspector

Address

Recent activity and token balances

Plain JSON-RPC cannot list an account’s history or the tokens it holds, so these come from an explorer index when one answers: the newest 25 transactions the address sent or received, and its ERC-20 balances. This is partial by construction — internal transfers, token movements inside other contracts’ transactions and older history are not listed — and the panel names its source and the time of the answer. When no index answers, the panel says which one was asked and why it failed; nothing is shown in its place.

Transaction, proposed call, allowances

Notes Vault

Key hierarchy

passphrase ──PBKDF2-HMAC-SHA-256 (600,000 iterations, 128-bit random salt)──▶ KEK
KEK        ──AES-256-GCM (96-bit random IV, AAD = vault header)──▶ wraps the 256-bit vault key
vault key  ──AES-256-GCM (fresh 96-bit random IV per save, AAD = record id)──▶ one note per record

What you must know

Limits: 160 characters per title, 60,000 characters per note (256 KB sealed), plain text only. Note text is always rendered as text, never as markup.

Backup format

An export is a JSON document (*.marblevault.json) holding exactly what IndexedDB holds, base64-encoded. It can be exported while the vault is locked, because it is ciphertext. Only the passphrase opens it.

{
  "format": "marbleprivacy-vault-backup",
  "version": 1,
  "exportedAt": "ISO-8601",
  "vault": {
    "vaultId": "uuid",
    "createdAt": "ISO-8601",
    "kdf":    { "name": "PBKDF2", "hash": "SHA-256", "iterations": 600000, "salt": "base64 (16 bytes)" },
    "cipher": { "name": "AES-GCM", "keyLength": 256, "ivLength": 96, "tagLength": 128 },
    "wrappedKey": { "iv": "base64 (12 bytes)", "data": "base64 (32 + 16 bytes)" }
  },
  "notes": [
    { "id": "uuid", "order": 1,
      "sealed": { "iv": "base64", "data": "base64 — AES-GCM(JSON{title,body,ref,tag,createdAt,updatedAt})" },
      "ciphertextBytes": 345 }
  ]
}

An imported file is treated as untrusted. Before any key derivation: format id and version, vault id shape, KDF name and hash, iterations within 100,000–5,000,000, salt 16–64 bytes, cipher parameters, IV lengths, ciphertext sizes, duplicate ids, at most 5,000 notes and 96 MB. Then the passphrase must unwrap the key and every note must authenticate and decode — with each field type-checked and length-capped — before the current vault is replaced, in one transaction.

Screen Privacy

Stealth addresses (ERC-5564)

The one on-chain privacy mechanism here. The ERC-5564 Announcer (0x55649E01B5Df198D18D95b5cc5051630cfD45564) and the ERC-6538 Registry (0x6538E6bf4B0eBd30A8Ea093027Ac2422ce5d6538) have code on Robinhood Chain (4663) since block 8,283,577; the Announcer bytecode is byte-identical to the Ethereum and Arbitrum deployments and both contracts are a Sourcify match on chain 4663.

It hidesIt does not hide
Who received a payment: each one goes to a fresh address derived from the recipient’s published keys, and that two payments went to the same person.The sender, the amount, the time, the one-time address and the announcement. A withdrawal to an address already known to be yours links the payment to you.

Shielded pools and private trading

Status: integration required (checked 2026-10-02). No verified shielded-pool or private-execution protocol exists on chain 4663: Privacy Pools (0xbow), RAILGUN, Robinhood Chain ecosystem listings, Privacy Hood (self-described zk pool), VeiledHood (self-described shielded vault) were checked against their own documentation. The Stealth Addresses page probes the candidate addresses live (eth_getCode plus Sourcify) and lists the 6 things a legitimate integration needs. No pool deposit, withdrawal or private-swap control exists in this build, and no custody contract of our own.

Networks and providers

NetworkChain idRPC endpoints the relay triesIndex
Robinhood Chain4663rpc.mainnet.chain.robinhood.com, robinhood-rpc.publicnode.com, robinhood.drpc.orgrobinhoodchain.blockscout.com (Blockscout API v2); api.etherscan.io (API v2, needs a key)
Robinhood Chain Testnet46630rpc.testnet.chain.robinhood.comexplorer.testnet.chain.robinhood.com (Blockscout API v2)
Ethereum1ethereum-rpc.publicnode.com, eth.drpc.org, cloudflare-eth.cometh.blockscout.com (Blockscout API v2); api.etherscan.io (API v2, needs a key)
Arbitrum One42161arbitrum-one-rpc.publicnode.com, arb1.arbitrum.io, arbitrum.drpc.orgarbitrum.blockscout.com (Blockscout API v2); api.etherscan.io (API v2, needs a key)

Local data

DataWhereForm
Vault headerIndexedDBKDF parameters and salt in clear; the vault key encrypted
NotesIndexedDBAES-256-GCM ciphertext only
Activity logIndexedDBEvent kinds, counts, times, inspected transaction hashes and shortened addresses in clear; note titles sealed under the vault key
Stealth announcement cacheIndexedDBPublic on-chain data, copied
PreferenceslocalStorageClear (nothing secret): auto-lock, motion, network, Screen Privacy, RPC overrides
Wallet connector statelocalStorage (wagmi)Which connector was used last

The Privacy Panel lists what is actually stored, with sizes, and “Clear all local data” removes all of it after a typed confirmation. It cannot remove anything from a blockchain.

$MARBLE

$MARBLE is the token of MarblePrivacy. Its contract address on Robinhood Chain (chain 4663) is 0x1e9B57B1986142ddAf11E0a116D4B4A83D34eB2F (Blockscout). The token section of the landing page shows what that contract itself answers (name, symbol, decimals, total supply), read through the relay.

The address is published in one place by a script that first reads the contract on-chain, so the site never shows an address nobody checked. Every tool here works without the token, and holding it changes nothing about what a public chain shows. Official account: X @MarblePrivacy.

Setup and deployment

pnpm install
pnpm dev            # http://localhost:21700
pnpm test           # vitest: vault crypto and format, inspector parsing, decoder, stealth vectors
pnpm test:fork      # Anvil fork of Robinhood Chain: the stealth flow against the real bytecode
pnpm typecheck && pnpm lint && pnpm build
pnpm smoke          # routes, headers, relay allow-list, lookups — against a running server
pnpm e2e:browser    # headless Chrome: vault, inspector, screen privacy, wallet, mobile, reduced motion

Environment variables are optional and server-side only: ROBINHOOD_RPC_URL, ROBINHOOD_TESTNET_RPC_URL, ETHEREUM_RPC_URL, ARBITRUM_RPC_URL (private RPC endpoints tried before the public ones), ETHERSCAN_API_KEY (address history where the key-free index is unavailable) and RESOLVE_OVERRIDE (DNS pins for developer machines). NEXT_PUBLIC_SITE_URL is the only public variable and only feeds metadata. There are no secrets in the browser bundle. The Content-Security-Policy is nonce-based and set per request, so every page renders dynamically. The project is a standard Next.js application and deploys to Vercel as is.

Limits

Documentation · MarblePrivacy