Commitment, nullifier, proof
Three words that make a deposit and a withdrawal impossible to pair.
You can read the pages before this one and understand the product without this page. This one is for the people who want to see the machinery.
Commitment
A one-way fingerprint of your receipt, published when you deposit. Given the receipt you can produce the commitment in an instant; given the commitment, nobody can produce the receipt. The chain therefore holds proof that a deposit was made, and no clue about who made it.
The tree
Every commitment is added to a Merkle tree: a way of summarising thousands of numbers as one short number, the root, such that you can prove a particular number is in there without listing the rest. The program keeps only the root. Your withdrawal proves membership against it, and membership is all it proves — never which leaf.
The proof
A zero-knowledge proof is a statement you can check without learning why it is true. Yours says, in effect: I know the receipt behind one of the commitments in this tree, and I want the money sent here. The program can verify that in a few milliseconds. It learns the destination, the amount and nothing else — not which commitment, not who deposited it, not when.
Nullifier
A second fingerprint, derived from the other half of your receipt and published with the withdrawal. The program keeps a list of the ones it has seen. Present the same deposit twice and the same nullifier comes out, the program finds it on the list, and the second withdrawal fails. The nullifier cannot be matched back to a commitment, so it spends the deposit without naming it.
Where the trust goes
Proof systems of this kind need a set-up: a proving key and a verifying key, generated once. If a single party generates them alone, that party keeps the ability to forge proofs, and forged proofs drain a pool. The answer is a ceremony with many independent participants, where a single honest one is enough. That ceremony has not happened.