How we draw
Nobody picks your card. Not you, not us. Here is how that works, and how to check any pull yourself.
The pool is frozen first
Every pack draws from a published pool version: each card, its N01 value and its weight.
The version is frozen when it goes live, and its fingerprint (a SHA-256 hash) is printed on the pack page. To change a pool we publish a new version; an old one never changes.
You can download any version as it was hashed, and hash it yourself.
Your opening gets a receipt
When you open a pack, we sign a receipt that names the pool version, your seed and a public random round a few seconds in the future, and we log it before that round exists.
So when the receipt is signed, nobody knows the card yet, us included.
The public log holds only what a check needs. It never names you: each seed period has a random code of its own, a pull that shows your name in the latest pulls has a period to itself, a new period starts whenever you switch Anonymous on or off, and receipts carry no price or payment. Your pack is in it only as a fingerprint that your own pack ID matches.
A public random number decides
The round comes from drand, a public randomness beacon run by independent organisations, which publishes a signed number every three seconds.
Your card is worked out from the receipt and that number, with a published method. Anyone can repeat the maths and land on the same card.
About drandCheck any pull
Every pull has a receipt ID.
Paste it into the checker and your browser recomputes the result from the public inputs: the pool version, the receipt and the random round. It says whether they match.
What we publish
Every card in every pack with its chance. Each card in a pool shows "1 in N"; its exact percentage is in the card's pop-up, and the band table gives each value band's share of packs.
We also publish the time the values were frozen and the pool file behind the fingerprint. There are no secret cards and no hidden weights.
We earn a fixed service fee per pack, the same whichever card you pull, so we have nothing to gain from one result over another.
The log, day by day
Every day we publish the public log's latest entry and its hash. Each entry's hash covers every entry before it, so no past receipt or result can change without breaking these.
| Day | Entry | Hash |
|---|---|---|
| 2026-10-05 | #8 | |
| 2026-10-04 | #4 |
Read a pool, then open a pack.
See the packs