Privacy

Updated

No sign-up, no login, no profile.

LOKA Pay has no accounts. There is nothing to sign up for or log in to, and we keep no profile of you.

LOKA Pay is a sandbox prototype built at the Hacklanta II hackathon. It uses test tokens on Solana devnet that have no monetary value. "We" means the LOKA Pay team.

The iPhone app

The iPhone app keeps its keys on the phone. Messages, photos and voice notes travel end-to-end encrypted to the person you send them to, over Bluetooth or a local Wi-Fi network, and are stored on the phones involved. The app does not send them to us.

The app asks for these permissions, each only for the feature named: Bluetooth (to reach nearby phones), camera (to scan codes and take photos for messages), microphone (to record voice notes), contacts (to find a name for a phone number you type; contacts stay on the phone and are never uploaded), local network (to reach nearby phones on Wi-Fi) and Face ID (to approve each payment).

This website

This website sets no cookies and runs no analytics or tracking. Its fonts are served from this site's own address.

Three pages make your browser contact another website, and only to read public data: /live connects to Solana's public devnet server (api.devnet.solana.com) to read the program's transactions, /watch connects to the same server to read the one allowance it shows and the transactions that touch it, and /call connects to the same server to watch for the next settled payment, only after you press "Call me when the next payment settles". That site sees your browser's request, as any website does; this site sends it nothing about you, and never your phone number. Every other page makes no request to any other website, except /send below.

/send makes your browser contact our settlement server at api.zerobars.us only after you press its Send button: one request carrying the recipient allowance id and the amount you entered, sent again unchanged while the server answers that the send is pending. The server sees your browser's request, as any website does; nothing else about you is sent.

The /judge, /proof and /trust pages read public data from Solana devnet (api.devnet.solana.com) and GitHub (api.github.com) on our server, not from your browser, and those reads carry nothing about you. /call also reads public payment data from Solana devnet on our server, to find the payment the call reads out.

It is hosted on Vercel. We have not turned on Vercel Web Analytics or Speed Insights.

Phone calls (/call)

If you enter a phone number on /call and press a button, your browser sends it once to our server, in the body of one request. Our server uses it to ask Vonage, the phone company we use, to place one call, and does not store or log it. Vonage keeps a record of the call.

To enforce the call limits, our server's memory keeps a keyed hash of the number (not the number) for up to 24 hours. It is never written to disk and is gone when the server restarts.

Calls need a desk code we give out at the LOKA Pay table. If a request carries a wrong or missing code, our server's memory keeps a keyed hash of your network address (not the address, and made with a random key that changes whenever the server restarts) for up to 10 minutes, to limit guessing. It is never written to disk or logged.

The voice is made by ElevenLabs from public payment details only: the amount, how long ago the payment settled, and that the chain checked the payer's signature. Your number is never sent to ElevenLabs.

The settlement server

The settlement server at api.zerobars.us is running on Solana devnet. It has no accounts and never asks for a person's name, phone number or email; the only name it takes is the shop name a merchant types.

All but the last two rows of the table below are what it stores, read from its code (server/ in the repository); the last two are what the /call page handles. Its log has one line per response, with the method, the route and the status code, and no address, header or body. The /proof and /send pages read its public health check (api.zerobars.us/api/health) from our web server, not from your browser, and that read carries nothing about you.

What we store

FieldWhere it livesWhy
A phone's public key and its hash, its sandbox allowance (cap, offline limit, expiry) and the certificate the server signs for itThe settlement server; on Solana devnet a payer's key and allowance, and a merchant's key hash, are publicTo open the allowance and let the program check that each payment was signed by that phone
A merchant's display name, typed by the merchantThe settlement server, in the merchant's registration and inside its signed certificateSo the certificate shows the same name every time
Counters: how many notes each allowance sent in the current window, and how much each sandbox pool and fee payer spent each dayThe settlement serverTo limit how fast one allowance can settle and how much the sandbox wallets spend in a day
A keyed hash of your network address (not the address), with a count of your recent requestsThe settlement server's memory only: never written to its database or logs, and made with a random key that changes whenever the server restartsTo answer "too many requests" when one network sends a burst
When the server received each payment, the devnet transactions it signs and sends, and their resultsThe settlement server; every transaction is also public on Solana devnetTo send each transaction once, recover after a restart, and sign the confirmation a phone shows
Payment notes and acks: amount, key hashes, signatures and when the merchant received itThe settlement server; each settled payment is also public on Solana devnetTo settle each payment once and show how long it was held offline
Your phone number, if you ask for a call on /callStored nowhere. Our server passes it once to Vonage to place one call; Vonage keeps a record of the callTo place the one call you asked for
The words the call saysSent to ElevenLabs to make the voice: public payment details only (the amount, when it settled, that the signature was checked)To read the payment out loud

Contact

Questions about privacy: team@zerobars.us