Privacy model

Hide the pick, not the truth about the system.

Before reveal

A production deployment should hide allocation weights and asset choices while exposing only the minimum data needed to admit one entry and enforce the deadline.

After reveal

The round policy may publish portfolios, scores, and a result digest. Account identity, network metadata, and off-chain logs remain separate privacy surfaces.

Scaffold warning

The runnable demo uses an encoded local payload, not encryption. It is deliberately marked unsafe and cannot be selected by production configuration.

Never collect

Identity secrets, seed phrases, plaintext picks before reveal, invitation tokens in analytics, or full wallet addresses in behavior events.