§7. Privacy as Private Money
Copy/paste (plain text):
Jason St George. "§7. Privacy as Private Money" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v3.2. /v/3.2/read/part-ii/7-privacy-as-private-money/ Privacy as Private Money
Cash used to be default private money: anonymous, bearer, final on receipt. In a world of KYC’d banks, programmable payments, and networked surveillance, that role has decayed. At the same time, the repression playbook (negative real rates + capital controls) makes bearer-like savings economically necessary, not ideologically optional.
“Privacy” in this thesis is not romantic opacity; it is the ability to hold and move value without chokepoints, plus the option to disclose on your own terms.
Interiority has a history.
The capacity this chapter argues for has a five-hundred-year arc behind it, and the arc is worth naming because it reframes what is being defended. The private interior self is not a natural constant that technology is eroding; it is, on the account of the orality-literacy literature [Ong 1982], substantially a product of a technology: sustained silent reading, a practice individuals had to acquire, that only became mass practice with print. Interiority was an externality of a medium, and it has since been mistaken for the default state of persons. On that reading, surveillance does not violate a natural privacy so much as withdraw a subsidy that a particular medium had been paying, quietly, for centuries. The implication for this chapter is not that the case for private settlement strengthens — the repression economics stand on their own — but that the loss is larger than it looks: what is being unbuilt is not an amenity but a specific, technology-dependent form of the person that took centuries to build and that no one planned. Defending it is therefore also not an amenity.
Concretely:
Bearer-like holding:
Keys, not accounts, define control. Custodians may exist, but custody is an optional service, not a mandatory chokepoint.
Non-custodial settlement:
Cross-asset flows (BTCXMR today; BTCshielded-ZEC when a corridor exists, §20: Layer 5: Value & Settlement) execute as atomic swaps or corridor protocols; neither side needs to trust a centralized intermediary.
Auditable by consent:
Viewing keys and structured receipts allow specific flows to be disclosed to auditors without exposing the entire graph.
When these properties hold, private settlement capacity itself starts to behave like a monetary asset:
-
A treasurer facing capital controls is not just asking “what’s the yield?” but rather, “can I still get value to my people next year if on-/off-ramps are throttled?”
-
A dissident journalist or NGO cares less about upside and more about “will this still be here and spendable if my local banks freeze?”
Blockchain may be waiting for its SSL moment. The analogy is suggestive: in 1994, putting credit card information on the Web seemed reckless until SSL made encrypted commerce viable. E-commerce grew into a multi-trillion-dollar industry once confidentiality became default. Today, most public blockchains are “public by default” the way HTTP was—every transaction visible, every address linkable. Privacy is plausibly the bottleneck for mass institutional adoption.
The institutional version is straightforward: no enterprise wants payroll, vendor rates, or treasury operations visible by default. The unlock is one-click, non-custodial BTCXMR (and BTCshielded-ZEC once that corridor exists) with refund-safe UX and clear settlement analytics—privacy as a product, not a promise.
In that environment:
-
The rails (privacy corridors, shielded pools) earn fees for providing unseizable, auditable settlement capacity.
-
The claims on those rails (e.g., corridor LP positions and Work Credits) are service, operating, or derivative claims. They may be held, but are not presumed stores of value.
You can think of Private Money as:
“Rights to future, censorship-resistant, auditable settlement capacity.”
The SoV properties from §3: First Principles: What a SoV Must Survive map naturally:
-
Credible scarcity. Capacity is constrained by bandwidth, cryptographic verification costs, and capital at risk.
-
Cheap public verification. Anyone can verify that a transaction was correctly formed, swapped, or refunded.
-
Censorship-resistance & portability. Flows ride over non-custodial corridors; exit options span multiple assets and jurisdictions.
-
Neutrality & permissionlessness. Adversarially diverse relays, routers, and LPs; public metrics on concentration.
-
Native demand. Demand is created by repression itself.
-
Lawful privacy. Viewing keys + PIDL receipts mean regulated entities can prove compliance without deanonymizing entire networks.
-
Duration-neutrality. Claims participate in fee flows and scarcity premiums, not fixed coupons.
-
Asset-level value capture. Fees, collateral, and settlement are denominated in the base asset, so consuming the service touches the asset rather than bypassing it (§10: Work Credits: Energy-Anchored Claims).
-
Agency preservation. Selective disclosure and non-custodial settlement equip the holder rather than managing them (§3: First Principles: What a SoV Must Survive).
The ninth requirement carries a capability reading the eighth does not, and the distinction matters because a ledger can satisfy the formal properties while failing the practical one. Formal access — a valid balance, a working key, a legal right to transact — is not the same as capability: command over the necessities of an independent life. A perfectly accurate ledger can faithfully preserve an unequal starting state; making claims harder to alter does not broaden who can acquire them (“The Vibecession Was Real” [Green 2026e]). The requirement as enforced (§23: Extended Telemetry) therefore reads on both layers: the Agency Preservation Board tracks non-custodial usage share and disclosure scope — the formal layer — and the participation telemetry of §2: The World Forces New Monetary Primitives tracks whether users can in practice acquire and hold meaningful claims through wages rather than inheritance or incumbency — the capability layer. A stack that passes the first and fails the second has hardened the incumbent distribution more efficiently than fiat did.
On a balance sheet, Private Money can coexist with BTC and fiat, but it plays a different role:
-
BTC: thermodynamic base, global risk asset, macro hedge.
-
Fiat: near-term unit of account, legal tender, credit medium.
-
Private Money: repression-hedged rail, a way to ensure you can still pay and be paid without being fully seen.
New here? Start with the one-minute version.
Tip: hover a heading to reveal its permalink symbol for copying.