# Accounts and private balances in Tempo Zones

Tempo Zones keep your balance and account activity private from other users. RPC requests authenticate your Tempo account, and contract execution restricts which balances and allowances that caller can read.

An account signs an authorization token for account-scoped RPC access. The RPC sends contract calls from that account. At the token contract, balance reads require the balance owner; allowance reads require the owner or spender.

The RPC scopes transactions and event logs to your account and blocks raw storage reads such as `eth_getStorageAt`. Contract-level caller checks prevent an `eth_call` from exposing another account's balance. See [RPC access control](https://tempo.xyz/developers/docs/protocol/zones/rpc) for authentication and method-specific rules.

## Private balances

On Tempo Mainnet, anyone can read any account's balance. On a Tempo Zone, `balanceOf(address)` enforces caller restrictions for TIP-20s:

* If `msg.sender == account`, the call succeeds and returns the balance.
* Otherwise, the call reverts with `Unauthorized()`.

These checks also apply to sequencer-signed getter calls. The Zone operator can still inspect the underlying node state; account privacy does not hide balances from your operator. A contract on the Tempo Zone cannot read and emit another account's balance.

## Private allowances

The `allowance(owner, spender)` function is similarly restricted:

* If `msg.sender == owner` or `msg.sender == spender`, the call succeeds.
* Otherwise, the call reverts with `Unauthorized()`.

A non-zero allowance reveals a relationship between `owner` and `spender`. Restricting reads to those two parties preserves TIP-20 approval flows without exposing the allowance to other accounts.

## Other account reads

Public views like `totalSupply()`, `name()`, `symbol()`, and `decimals()` remain unrestricted. Account-specific permit nonces, `NonceManager` nonces, and `AccountKeychain` key and spending-limit reads are restricted to their account owner.

<span id="related-specifications" />

## Related execution rules

The current implementation rejects public TIP-20 transfer calls with `Unauthorized()`; token movement uses the inbox and outbox. Approval and permit calls remain available. Tempo Zones also charge fixed gas costs for selected TIP-20 operations to prevent gas-based side channels. See [Execution & Gas](https://tempo.xyz/developers/docs/protocol/zones/execution#fixed-gas-costs) for details.

Tempo Zones currently disable contract creation (`CREATE` and `CREATE2`). See [Execution & Gas](https://tempo.xyz/developers/docs/protocol/zones/execution#contract-creation-disabled) for details.
