
Which Stock
The market id is inside the hash. Nobody can tell whether you are about to trade NVIDIA, Tesla or the S&P 500.
Four things a watcher can see. None of them is your order while the batch is taking orders.
Deposits and withdrawals are plain transfers, so a watcher can guess your intent. The order stays sealed.
A commitment and its 1 USDG bond are public: anyone can see an address will trade, but not what.
Between reveal and settlement, about a minute, your order is readable on-chain: version 1's main limit.
Settlement emits every fill with its price, so what you traded and at what price becomes public.
While a batch takes orders, these four never touch the chain. They live in your browser, inside a hash.

The market id is inside the hash. Nobody can tell whether you are about to trade NVIDIA, Tesla or the S&P 500.

Both sides post the same bond from the same USDG balance, so a commitment looks identical whichever way you trade.

Nothing is taken from your vault until you reveal, so a commitment says nothing about how much you hold or want.

Sealed with a 32-byte salt only you hold, so nobody can find it by hashing every plausible market, side and round number.
Version 1 is live. Version 2 is designed to close its leaks, and is written into the roadmap, not into the contract you use today.
What the chain cannot see while the batch takes orders.
About three minutes, every batch
What anyone can read, and when it becomes readable.
Revealed orders, until settlement
Balances move into a shielded note tree. Planned, not live.
Each proof verified on-chain
Removes the public reveal window. Further away.
Decrypted only inside settlement
Straight answers about what leaks. If something is not listed as guaranteed, do not assume it.
Not while the batch takes orders: there is nothing to read but a hash. Once revealed, a large imbalance is visible for about a minute; the price guard limits how far anyone can push the settlement price in that time.
Without it, an order has few possible values: a watcher could hash every market, side and round size and find yours. 32 random bytes make that impossible.
No. The hash is computed in your browser and the preimage stays in its storage until you reveal it on-chain yourself. You can save it as a file.
It can hint. Depositing a large amount right before committing tells watchers something is coming. Proof of funds in zero knowledge, planned for version 2, is designed to close this.
No. It is a written plan. The roadmap marks an item done only when it is deployed.