> For the complete documentation index, see [llms.txt](https://docs.sectoral.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sectoral.xyz/getting-started/anatomy-of-a-transfer.md).

# How a Transfer Works

Every Sectoral account combines two pieces: a Robinhood Chain smart account that you custody yourself, and confidential token contracts that keep each payment's amount secret. You hold the keys. Settlement is final in a fraction of a second. The amount is encrypted on your device before anything is sent.

The parties to a payment are always visible. The amount never is.

***

## From tap to settlement

```
You compose the transfer in the app
        ↓
The Privacy Engine generates a ZK proof on your own device
        ↓
Ciphertext and proof go to Robinhood Chain
  as a confidential token transfer
        ↓
The verifier contract checks the proof and updates both encrypted balances
        ↓
Both addresses are written to the public record.
  No observer can read the amount.
        ↓
Sender and recipient each decrypt it using keys only they control
        ↓
About 100ms later, the payment shows in both activity feeds
```

The proof shows three things: the encrypted amount is well-formed, it is not negative, and the sender's balance can cover it. It is built entirely on the client. No Sectoral server ever receives your plaintext balance or the amounts you send, whether while you are typing, in transit, or at rest.

***

## What goes on-chain

A transfer produces one Robinhood Chain transaction containing:

* The sender's address
* The recipient's address
* An ElGamal ciphertext in place of the amount
* A zero-knowledge proof of validity
* The block number and timestamp

All of these can be looked up by anyone using the block explorer. Anyone can verify the payment happened; nobody else can see how much it was for. Everyone can audit it, but only two parties can read it.

***

## Where the boundaries sit

**Visible to all:** the two addresses, which token was used, and the simple fact that a transfer happened.

**Encrypted:** how much was sent and the balances that follow.

**Never available to Sectoral:** your plaintext balance, your plaintext amounts, and your decrypted history. The only exception is a disclosure you choose to create for a counterparty or a regulator.

Sectoral's servers relay requests, render the interface, and monitor chain events. They hold none of your keys and no readable version of your balance. That is guaranteed by how the system is built, not by a promise in a policy.

***

## Real-time updates

An indexer run by Sectoral tracks contract events and keeps the app's view up to date, so nobody needs to poll the chain. Status changes, such as a transfer going from submitted to settled, are pushed over a WebSocket as soon as the block is produced.

***

## Read on

* [Account Types](/getting-started/choosing-an-account.md): find the account type that suits your use
* [How Amounts Stay Encrypted](/privacy-and-cryptography/encrypted-amounts.md): the full cryptographic picture


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.sectoral.xyz/getting-started/anatomy-of-a-transfer.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
