Exact claim
Privacy model
VeilPass protects the Stellar wallet address from the host dApp during the login flow.
What is hidden
The host verification service does not receive the Stellar wallet address or public balance, and neither host nor browser receives the user's credential secret. The host's POST /api/verify route and its request infrastructure do receive the raw proof and public inputs, including credential commitment/root, private app ID, revocation hash, one-time nullifier, challenge binding, origin, and timestamps. These values are omitted from the successful result but remain sensitive transient request data: disable body logging and trace capture and do not persist or forward them.
What is not hidden
The enrollment issuer sees the address. VeilPass does not hide IP address, browser fingerprint, timing, device state, or later on-chain actions. It is not a network anonymity system.