Zero Knowledge · Zero Knowledge Podcast

Payy and Payy Card, the Undoxable Credit Card

October 15, 2025·1 hr 8 min·5 clips
Sid and Cal from Payy explain why they built an 'undoxable' credit card when private payments were considered unsexy and dangerous in 2023.
1. Zero Knowledge podcast, hosted by Anna Rose with co-host Tarun, interviews Sid and Cal, co-founders of Payy (P-A-Y-Y), a private stablecoin payments company. 2. Sid is the product and company vision lead; Cal is the technical co-founder who previously built a data analytics company at Y Combinator; both are disclosed investors, with Anna Rose investing through ZKV. 3. The episode's core thesis is that true self-sovereign digital cash requires privacy as a non-negotiable component, and that Payy has built the first credit card that disconnects KYC identity from on-chain payment history. 4. Payy consists of three products: Pay Network (an L2 ZK Validium rollup providing compliant private stablecoin transactions), Pay Wallet (a stablecoin bank account), and PayCard (described as the first undoxable non-custodial crypto credit card). 5. Sid frames the project's 2023 start as intentionally contrarian: private stablecoins were 'very unsexy and a little dangerous to work on,' but the team believed privacy was the missing link between Bitcoin's stated vision and practical implementation. 6. Zcash is assessed positively as the best private store of value in the world, but rejected as a payments foundation for three reasons: it is a fluctuating asset unsuitable for payments, its brand became associated with illicit use, and its 2.5-minute block time makes real-world transactions impractical. 7. Cal explains that the entire Pay Network is built around a UTXO-based Merkle tree where each note (representing money) is a hash; spending requires a client-side ZK proof showing inputs equal outputs, with new hashes replacing old ones. 8. Cal states explicitly that any privacy product that does not run the ZK proof on the user's device is not providing real privacy, because the proof must be generated where the private data lives. 9. The Pay Network uses a lineage-visible but amount-and-party-private design: transaction amounts, recipients, and senders are hidden, but the chain of note provenance is traceable — a deliberate compliance choice to prevent abuse by state-level actors like North Korea. 10. PayCard is described as 'undoxable' because, unlike every other non-custodial card (Gnosis Pay, Metamask Card, EtherFi), there is no single entity that holds both the user's KYC information and their on-chain payment history simultaneously. 11. Sid shares an unverified, non-public claim that TRM Labs has developed the ability to fully de-anonymize Railgun using advanced clustering algorithms — a development that, if accurate, would invalidate overlay-privacy approaches on public chains. 12. The PayCard transaction flow requires Polybase Labs (the company behind Payy) to authorize Visa transactions contractually: when a user taps the card, Pay servers execute a ZK proof within the Visa authorization window of approximately one second, placing funds in escrow on the Pay Network. 13. Cal explains that Pay Network achieves 0.7 millisecond proof verification, enabling the full Visa authorization cycle — including on-chain proof execution — to complete before Visa's deadline; actual settlement to Visa occurs a week later. 14. Hidden complexity in the Visa card network is discussed at length: authorization and settlement are separate events, tips can exceed the authorized amount in the US, and partial refunds, completed-vs-in-progress refunds, and chargebacks all require distinct handling logic with a non-custodial immutable system on the other side. 15. The roll-up architecture was chosen not out of preference but necessity: controlling block time was required to meet Visa authorization windows, and the UTXO Merkle tree model is described as an almost inevitable design choice for any ZK privacy system. 16. Sid argues that speculation enables users to tolerate terrible crypto product UX, and that building with stablecoins removes that tolerance, forcing the team to solve real problems accessibly. 17. The episode is technical throughout and moves between high-level product framing and detailed systems discussion; Anna Rose frequently asks clarifying questions about the Visa flow that help less technical listeners follow the architecture. 18. Tarun pushes on edge cases (race conditions, chargebacks, compliance lineage tradeoffs) and the design decisions behind choosing a rollup over other ZK architectures. 19. This episode is best suited for listeners with some crypto background who want to understand how ZK proofs can make private stablecoin payments work at Visa scale. 20. Listeners unfamiliar with ZK cryptography basics, UTXOs, or rollup architecture will likely struggle to follow the technical depth without external context.

As heard by us

A concrete look at private payments where UX, proofs, and Visa rails have to coexist.

Pay's pitch is straightforward to describe and difficult to execute: a private payment product that still has to work inside Visa's remittance system.

Read the full review in PlayNext →

Why you'd press play

You want a private payment product explained as a real flow, not a slogan.

Read the full recommendation in PlayNext →
Listen to the show on