> For the complete documentation index, see [llms.txt](https://docs.redacted.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.redacted.money/using-redacted/faq.md).

# FAQ

## What do I need to get started?

A wallet you already have, such as Keplr, MetaMask, Rabby or Trust. Connect it, tap the ghost icon and sign one message. Registration is sponsored, so you can start without sending anything. See [Getting started](/using-redacted/getting-started.md).

## Do I need a new seed phrase?

No. Your private account is derived from a signature of your existing wallet, and one backup file makes it independent even of that wallet. There is nothing new to write down.

## Do I need to sign up or verify my identity?

No. There is no sign-up, no KYC and no identity check, and anyone with a wallet can use Redacted. You connect, sign one message and you are in. See [Compliance](/protocol/compliance.md).

## What does "tx-less" mean?

After you sign in, your wallet doesn't sign another transaction. Your browser authorizes each action with a zero-knowledge proof, and a relayer submits it on-chain and pays the gas, so you get real on-chain execution without wallet popups. The one signature that remains is the deposit from your public wallet, because in that step your public wallet is the one acting.

## Do I need gas?

No. The relayer pays network fees and is reimbursed through the [Privacy fee](/using-redacted/fees.md) that you see in every quote, so there is nothing to top up.

## Can the relayer touch my funds?

No. Every action is sealed by a proof that binds the destination, the amounts, the fee, the submitter and the expiry. The relayer can deliver your sealed action or decline to, but it can't open it, edit it or write its own. See [Relayer](/protocol/relayer.md).

## Who runs the relayers?

In upcoming updates, relaying moves to a network of independent operators who post a bond and follow public rules that the contract applies to everyone. The same nodes approve deposits, and their votes, rather than a company's, decide whether a deposit is sent back. The app picks a node at random for each action, and if no node is live for 7 days you can submit your own withdrawal. After the token relaunch, token holders decide who runs nodes by staking behind them and through governance. See [How the node network works](/node-network/node-network.md) and [Who decides what](/protocol/system-overview.md#who-decides-what).

## Does the Reserve ever fill up or slow down?

No. The note tree holds 4.3 billion entries, which is enough for a million private actions a year for two thousand years, and the math has a constant cost, so the last note is as cheap and as fast as the first. Growth doesn't degrade anything and instead strengthens the crowd you blend in with. If capacity ever mattered, a new tree could stand beside the old one with the same math and the same one-signature access, so capacity is a parameter of the design. See [Architecture](/protocol/architecture.md).

## Why SNARKs and not STARKs?

Because the design optimizes for what your actions cost today. A Groth16 SNARK proof is about 200 bytes and verifies in a fixed, small amount of math, which is why every per-action privacy system in production runs on SNARKs. A STARK that proves the same statement is roughly a thousand times larger, which would turn every click into a heavyweight transaction with heavy verification behind it. STARKs suit cases where one proof covers thousands of actions at once, while privacy that seals each action individually suits SNARKs. The one question SNARKs raise is the trusted setup, and the public [ceremony](/ceremony/ceremony.md) answers it, because the result is sound if even a single participant was honest.

## What about quantum computers?

There are two questions in that one. Your past actions stay safe: Groth16 is perfectly zero-knowledge, so old proofs contain nothing to extract with any computer in any century. The curve math that a far-future machine could attack is the same math that secures every blockchain and every wallet, so the base chains would rotate first and the whole industry would move together.

When that rotation comes, or when the underlying chain ships native STARK verification and makes it cheap, a successor Reserve with a hash-based proof system can stand beside this one. It needs no trusted setup, and it uses the same math elsewhere and the same one-signature access. The Reserve is replaceable by design, and the plan is already written down, which is the same approach as in the capacity answer above.

## Can anyone see my trades?

Your Spending account's activity is on-chain like any smart account's, but it is a fresh identity with no connection to your public wallet. What observers can't look up is whose it is. See [How privacy works](/using-redacted/privacy.md) for how to keep your crowd strong.

## What if I lose my device or wallet?

Restore your encrypted backup from any supported wallet and your balances, positions and history come back, because your account lives on-chain and not on a device. See [Backup and recovery](/using-redacted/backup-and-recovery.md).

## Can I recover with just my address?

Recovery starts with your wallet's signature instead of your address. An address is public knowledge and opens nothing on its own, while a signature from the wallet behind it can only be produced by its holder. So you connect your wallet, sign the usual message and everything is back. The backup file is the second path, for the day that wallet itself is gone.

## Why does it ask me to sign in again?

Private access locks itself after 15 minutes of inactivity, like a banking app, and one signature reopens it. See [Sessions](/using-redacted/sessions.md).

## Is a passkey safer than signing in with my wallet?

It depends on the setting. **Passkey for withdrawals and sends** asks for your passkey before money leaves, even while Private Mode is open, and **Passkey and wallet** asks for it at every unlock on top of your wallet's signature, so both add protection on that device. **Unlock with passkey** sits at about the same level as your device's own lock and saves you wallet popups. Your wallet stays the root of your account whichever you choose, because its signature and your recovery backup open the account on any device, while a passkey guards one device's session. Passkeys arrive with the launch, and [Passkeys](/using-redacted/sessions.md#passkeys) explains each setting.

## Is Redacted compliant?

It is designed to be, and it stays permissionless, with no sign-up, no KYC and no identity checks. With the node network, every deposit is approved by a node, and each node chooses what it checks first. Ozone, the reference screener, works only from public data such as sanctions lists and known hacks. Selective disclosure tools are coming soon, including Proof of Innocence, read-only audit keys and a private self-check on the Ozone page, so you can prove what you choose without exposing everything. Privacy for everyone. A hiding place for no one. See [Compliance](/protocol/compliance.md).

## Who decides what the network accepts, and can the core contributors turn me away?

The nodes decide, by rules that anyone can read, and the core contributors can't turn anyone away. Every deposit is approved by a node, and each node chooses what it checks before it approves. The node software can check the sending address against public lists such as sanctions lists, stablecoin issuer blacklists and known hacks, using Ozone. Sending a deposit back takes at least two nodes, and it only ever goes back to its sender. The core contributors, the DAO and Bōheki can't turn away or send back anyone's money, and no vote or switch applies to withdrawals. Bōheki (once, for about 3 days at most) and node votes can pause all new deposits, but a pause applies to everyone at once and never singles anyone out.

Ozone is the reference screener, built by Redacted's core contributors, and it works only from public data. It is published as open source with the launch. Each node chooses which Ozone instance it trusts, and the node network can decide to use or add other sources. After the token relaunch, token holders decide the screening policy, and the DAO does until then.

See [How the node network works](/node-network/node-network.md) and [Who decides what](/protocol/system-overview.md#who-decides-what).

## Why does new money wait before I can use it privately?

With the node network, new money waits about two hours before it can be used privately. The wait means a deposit can't be matched to what you do with it a few minutes later (see [Why new money waits](/using-redacted/privacy.md#why-new-money-waits)), and it gives the nodes time to send back money they decide not to accept. That money goes back to where it came from, so it never mixes with yours. You can cancel a waiting deposit at any time, and money already in your Reserve is always usable at once.

Your own money coming back from your Spending account is back at once. That covers what came from your Reserve, every gain your positions make in the share you put in, and payments straight from another Redacted user's Reserve. Money someone else sends to your Spending account waits like a deposit, and a mixed return is split, so your part is back at once. Nodes confirm this. You can read more in [New money waits briefly](/node-network/node-network.md#new-money-waits-briefly) and [Returns from Spending](/node-network/node-network.md#returns-from-spending).

## What is the ceremony for?

It creates the public parameters of the proof system, with trust spread across many community participants, and a single honest participant is enough to secure it. It touches parameters only and never funds. See [Ceremony](/ceremony/ceremony.md).
