Skip to content
FIELD GUIDE V6

Protocol / Privacy & trust

Privacy & trust

Private selections, public commitments, explicit limits.

Collector v6 · Robinhood testnet planned · No production addresses

Website waitlist

Joining the tok.fun waitlist stores your email address, signup time, and the version of this notice. The list is used for launch updates. Signup does not create a wallet, reserve tokens, or authorize a transaction. You can use the demo and documentation without joining.

Waitlist records are stored with Cloudflare D1. Cloudflare Turnstile processes browser and network information to protect the form from automated submissions. Email addresses and verification tokens are not included in application logs.

What sealing hides

Sealing publishes a commitment, candidate universe, previous and next inventory roots, payment context, archive digest, and a zero-knowledge proof. Actual selected assets, quantities, and grades are private witness values. All collector tokens remain in shared inventory custody; sealing does not transfer the selected tokens.

The proof checks membership, distinct selections, lane mix, exact quantities, sequential token-specific serials, cumulative inventory limits, artwork version and the manifest commitment. It derives rarity from the deployment’s committed secret key and the request’s single oracle result using fixed rejection sampling and published basis-point odds.

The selected asset order is committed before the oracle request. Neither it nor the rarity draw can be replaced. If a selected token becomes ineligible, the request expires and the full payment is refundable. The proof does not prove operator candidate completeness or unbiased asset sampling. Operators can still withhold service; the local oracle is a test fixture, not production randomness.

What can be inferred

Candidates, trades, burns, other openings, and aggregate disclosures are public. They can narrow possibilities or reveal information by elimination. This is accepted speculative gameplay, not a guarantee of anonymity.

The backend knows sealed contents and stores encrypted archives. Operators must preserve the manifests and private ledger recovery data. The proof prevents changing committed claims; it does not make a lost manifest recover itself.

The one-time accounting dependency

Graduation snapshots a private cumulative inventory root. To initialize exact earnings, someone must publish the token’s quantity, weight, salt, and Merkle path against that root. Anyone may submit a valid witness, but the service initially possesses it.

This is an additional one-time backend dependency beyond opening sealed packs. Graduation and trading proceed without it; collector quote fees queue until active weight is known. Finalized earnings claims do not need the witness again. Shutdown requires all aggregate witnesses to be disclosed before service closure.