Docs
Private Park is a privacy layer for AI. You deposit ETH once into a vault on Robinhood Chain, then pay for each request with a zero-knowledge proof instead of an identity.
This page explains how it works, what it protects, where its limits are and what can go wrong. Read it before you deposit.
How a request works
- Deposit. You send ETH to the vault contract. Your balance becomes a private note that only your device can spend.
- Prove. Your browser builds a zero-knowledge proof that a funded note covers the request. The proof does not show which note or which deposit.
- Get a key. The billing server checks the proof and issues a short-lived key with a spending cap. The key lives in your device's memory.
- Ask. Your prompt goes straight from your device to the model provider under that key. The billing server never receives it.
- Settle. When the key expires, only the measured usage is deducted from your note. The rest stays yours.
What is hidden, and what is not
Private Park hides who pays. It does not hide what you write from the model that answers it.
Hidden
- Who paid for a request
- Any payment link between your sessions
- Your prompt, from the billing server
- Your identity, because none is collected
Not hidden
- Your prompt and the response, from the model provider
- Your IP address, unless you use the relay or Tor
- Deposits and withdrawals, which are public on the chain
- $PrivaP trades and holdings, like any token
| Party | Learns | Does not learn |
|---|---|---|
| Billing server | A valid payment exists, and the cost of a session | Who you are, what you asked, which deposit paid |
| Model provider | Your prompt and response | Who paid |
| The public chain | Deposits, closes and withdrawals | What a balance paid for |
Trust model
Private Park is not fully trustless. These are the things you rely on.
- The operator. Private Park runs the billing server, the indexer and the challenge service. The server cannot read prompts or identify you, but it can refuse service.
- The proof setup. The proving keys come from a single-party setup. Whoever ran it must have destroyed the setup secrets. A multi-party ceremony has not been held.
- The signing keys. The server signs balance updates. Those keys must stay secret.
- The vault owner. The owner can pause new activity and change the address that receives fees. The owner cannot move user balances.
- The model provider. It reads the prompts it answers and applies its own data policy.
Known limits
- Crowd size. Payment privacy depends on how many people use the vault. With few users, timing and amounts make guesses easier.
- Network metadata. A provider can try to link sessions by IP address and timing. Use the relay or Tor if that matters to you.
- Prompt content. If you paste personal details, a recognisable writing style or the same documents across sessions, those sessions can be linked by whoever reads the prompts.
- Key reuse. If fresh keys are turned off, one key is reused for up to 60 seconds and the provider can link those requests.
- Not audited. The protocol is experimental. The circuits and contracts have not had an independent audit.
- Not post-quantum. The cryptography used is not resistant to future quantum computers.
- Chain reorganisations. A deposit becomes usable before the block is final. A rare reorganisation can require recovery.
Deposit only what you can afford to lose.
Funds and exits
- Normal withdrawal. You ask the server for clearance, then close your note on the chain. Your remaining balance goes to any address you choose.
- Exit without the server. You can start an exit directly on the vault. It pays out after a 24 hour challenge period.
- Ticket expiry. A note expires 30 days after deposit. Close or renew it before then. An expired note that was never closed can be claimed by the treasury.
- Your note is local. The note lives on your device. If you clear your browser without a backup, the balance cannot be recovered.
Fees and burn
- You pay the model cost of each session plus a 5% service fee.
- Half of the fee buys $PrivaP from the open pool and sends it to the burn address.
- The other half covers running costs.
- Buys run in small batches with a price floor, at most 0.05 ETH every 10 minutes. A single session cannot be traced through a single burn.
- The burn share is fixed in the contract and cannot be lowered. Tokens the contract holds can only be burned.
- The vault owner can point fees at a different address. If that happened, burns from new sessions would stop.
- Burns depend on usage. If nobody uses the park, nothing is burned.
- Your balance is held in ETH, so its dollar value moves with the ETH price.
$PrivaP
| Ticker | $PrivaP |
| Chain | Robinhood Chain, chain ID 4663 |
| Launchpad | pons |
| Supply | 1,000,000,000 fixed |
| Contract | Published on the home page at launch |
- You do not need $PrivaP to use Private Park. You pay with ETH.
- $PrivaP carries no claim on revenue and no promise of value.
- The price can fall to zero. Nothing on this site is investment advice.
- Names and tickers can be copied by anyone. Trust only the contract address published on the home page.
On the way
These features are planned and not live yet. Each one comes with a limit worth knowing.
| Feature | What it does | Limit |
|---|---|---|
| Private agent payments | A local endpoint that speaks the OpenAI API, so an agent can pay from a ticket with no account. | The agent's prompts are still read by the model provider. |
| Crowd counter | Shows the number of active tickets, which is the crowd you hide in. | A small number means weaker payment privacy. |
| Fixed ticket sizes | Deposits come in a few set amounts so they look alike. | Enforced by the app. A deposit made another way can still stand out. |
| Gift a ticket | Hands a funded ticket to someone by link or QR. | The sender keeps a copy until the receiver spends or closes it. |
| Built-in relay | Hides your IP address from the model provider. | The relay sees connection metadata, though not your prompt. |
| Prompt scrubber | Replaces emails, phone numbers, card numbers, wallet addresses and IP addresses on your device before sending. | It works on clear patterns. It does not detect names or writing style. |
| Private Holder Pass | Proves you hold $PrivaP without showing which wallet, for a lower fee. | Joining the holder group is a public transaction. Proofs made afterwards are not linked to it. |
| Private RPC | Pays for chain queries from a ticket. | The RPC provider still sees the queries themselves. |
Status
Private Park is in pre-launch. The dashboard runs in preview mode and is not connected to real funds or models yet. The vault, the token and the burn go live in the order shown on the trail map.
Origin and license
The payment protocol is a fork of zkAPI, an open source project by Open Anonymity and the Ethereum Foundation, used under its MIT license. The original design, ZK API Usage Credits, was published on Ethereum Research by Davide Crapis and Vitalik Buterin.
Private Park is an independent project. It is not affiliated with or endorsed by Robinhood, the Ethereum Foundation, Open Anonymity or pons.