NINOX / PRODUCT GUIDES
Privacy & limitations
What is shielded, what stays public and what Ninox and its AI provider receive.
Updated 6 October 2026 · Unaudited beta
What the pool shields
Ninox's BNB pool uses zero-knowledge proofs and encrypted notes. Your device constructs the proof and holds the spending keys. The design hides note ownership and internal transfer values; it does not hide the existence of pool transactions.
Deposits expose sender and amount. Withdrawals expose recipient and amount. Timing, exact amounts, a small anonymity set, repeated addresses and outside information may link activity. Privacy is not guaranteed.
Fresh wallets are public wallets
Shielded funding reduces a direct funding link to the original deposit wallet. Subsequent transactions from an action wallet are ordinary public BNB Chain transactions. Observers can see token holdings, approvals, contract calls and launch details. Reusing a wallet links its actions together.
Flap funding and launching are separate transactions. A bridge does not automatically carry Ninox privacy to another chain. USDT and USDC in action wallets are not shielded balances.
What services receive
| Party | Visible information |
|---|---|
| BNB Chain | Deposit/withdrawal amounts and addresses, commitments, public wallets and their actions. |
| Ninox service | Requests needed for relay, research, credit metering and broadcast, including submitted public addresses/data. Service operation does not make network activity invisible. |
| MiniMax | Prompts and tool results sent under Ninox's provider account. MiniMax's data policy applies; Ninox does not promise zero retention. |
| Flap / IPFS | Uploaded token names, logos, descriptions and social links, plus public launch activity. |
Local saved conversations are encrypted in the vault. A message still reaches the provider when you ask the AI to process it. Never include recovery words, private keys or unnecessary personal details in a prompt.
Lawful use and screening
The hosted service screens visible counterparties against its configured sanctions-address data. It cannot interpret every permission, hidden recipient or arbitrary contract behavior, and it does not certify compliance with all laws. Use correct app parameters and only actions you understand and are authorized to perform.