Who pays for privacy? The real cost of building aligned apps by Lefteris Karapetsas || ESP 2025
Ethereum Cypherpunk Congress·Fri, Jan 9, 2026, 12:00 AM
Speaker
Lefterin Karapetsas, founder of Rotki, explains how whenever something is labeled as free, users pay with their data and how apps that are Aligned with users respect data, dont track, run locally and respect privacy. Then he uses Rotki as a exmaple and showcases many guides and tips for users and builders aswell. Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/
Transcript
Hola.
Um, I'll be talking about privacy and who pays for it. It's a talk about money. Uh, a little bit about me first if you don't know me because lots of time has passed. There's many new faces which is great. My name is Lees.
I've been Ethereum since 2014. worked in the solidity compiler and the C++ client that no longer exists. I created along with Christoph and Socket the DAO and helped in the cleanup afterwards. Um I worked in uh payment channels uh basically if you know the lightning network for Bitcoin. We had the Ryen network uh for um Ethereum but that didn't really catch on.
And I'm the founder of Rodkkey. I'm going to mention Rodkkey a bit um in the talk. So um in crypto we have a paradox. We talk a lot. We talk about big big big words like decentralization, privacy, cipher bank, um data sovereignty, but in reality more than more than half, let's not really actually figure out how much is just cloud applications.
We we saw it like two days ago, Cloudflare outage, everything stops working. AWS outage two weeks ago, Azour, like in the end everything is hosted in a cloud and all of your data flows upstream. Not everybody actually that hosts a cloud app has bad intentions, of course, but many of them just take your data and use it against you because they just have it at some point. There is no other um no other way for them. Everything flows up.
Um, you've heard of it many times. I guess everybody knows if it's free then you are the product. If a product is free then you are paying for it with your data. A free product always hides a data tax. We know it, you hear it, but yet everybody still just uses free products.
So how can we fix that? Um we should um swap in this data tax, introduce privacy and realize as users that privacy has an explicit cost and that explicit cost is monetary and should be paid by someone. Um I've mentioned many times in uh the past the term of an aligned application and many people liked it. I think because it doesn't uh mean alignment with something uh vague. It's not alignment with I don't know cypher punk values very vague decentralization um data sovereignty.
It's alignment with with you or you or any any one of you. It's alignment with what the user needs. So respecting the user data, applications that uh do not track you, uh applications that can run locally and keep everything uh all of the data of the user locally and applications that can survive their creators because if the creator uh has an accident or like god forbid dies and the the whole thing stops working, then that's not really something that you should want to use. Aligned applications create a beneficial user value stack because you as users get ownership of your data. Um you get offline access and resilience and you can also um inspect the code because it has to be either open source or source available.
I'm not going to go into this uh um uh debate at all. Just so long as you can inspect the code and verify that what uh the application claims to do is true, then this is this is something really useful. And aligned apps also give you a user value stack that um gives composibility between various other local tools. This is all great and nice for the user, but on the builder side that has a very very uh explicit cost. It's not only monetary but it's also difficult to build because you don't have analytics, you don't have telemetry.
That means that you do not know much about your users. Um it's very very much harder to build from an engineering point of view. You create a local app, you create binaries, you have to distribute them. Um you do not store the data of the user somewhere in a centralized server, but the user stores it himself on uh his machine. That means that it's a local database.
It has encryption. um if you do it correctly then you have to upgrade it, migrate it when you make new versions. All of that happens on the user machine and you can't fix it. If something goes wrong, you are screwed. Um and monetization is not tied to data.
You have to tie monetization to something else. So from the builder point of view, building such things is hard. No wonder that uh people just make a software as a service product or make a SAS product. It's easier. you control it, you can uh lock down access to it and this is what a user pays for.
It's it's very clear. Um so as a case study uh I I'm building with my team ROKI which is a local first portfolio management tool. That means that it's a self-hosted application. I started it at first because I wanted to do my taxes and the only thing that existed back then was bitcoin.tax tax and they were asking for my addresses and I was like no no no no no no no no way and having something that is local and keeps all of your uh sensitive financial data local was like just made sense to me we are still the only local tool that does it which is still insane to me I don't understand how people use I don't know the coin list or the coin writings of the world what roy does is that it gives um like it can integrate all your EVM chains, Bitcoin, Substrate, uh, Solana, put in exchanges, um, integrate with Stratfi like with your bank and give you a dashboard that gives a overall bird's eye view of your entire portfolio.
So your history, you can do accounting, you can export a specific year. Um, it's a very useful tool and it all runs locally. When you run it locally, I don't know what you have. I don't care. It's all hosted on your own machine.
We have no tracking and we fund the development by premium subscriptions. For the devs here, the architecture is is um not very simple because it's a local application. It has a local encrypted database. It's SQL cipher which is basically an encrypted version of SQL light. Um we have a back end that runs locally.
Actually, it's two demons. one in Python which is the original one what I started like seven years ago and now we have also a Rust demon for faster stuff and they both talk to each other and we have a front end that also runs locally it's in Vue.js JS and Typescript. Um, and you can even host it somewhere else. So you can say back at home in Germany, I can self host by Rodki and access it here with my mobile.
So you can also have not really mobile app but you can access it via mobile. You sync every chain with RPCs or indexes of the chain and you can have optional exchanges or other integrations such as Moneriums pay always by user choice. Nothing is imposed on the user. All of this sounds super nice but it's very very very difficult to build. There is a lot of hidden engineering work like you have to build binaries for every different OS Windows, Mac, Linux.
uh as I said before the database migrations then uh I don't know if any of you use Windows then uh there you get this big uh warning that says this application is very bad for you if you pay them money you get a signing key that then you can sign binaries with and then it says this application may be bad for you but it's signed by this key these keys cost money every single signing of a binary costs money just for Windows similar stuff for app and then for Linux you can sign it with like a PGP key or whatever but all of that needs to be integrated in the CI you need to have release cycles you need to get the binaries out to users it's very very difficult to build and you don't have any feedback about errors when an error happens and you're testing without user data all of this in the end for a builder of such an application transl translates into one thing money resources it's much much harder to build good apps. It's much much harder to build local apps. Again, this is why most of the apps that we see today are just software as a service. It's easier. Um UX, oh boy, that's probably even harder to do without having um a software as a service.
You cannot AB test your users. You cannot deploy a different version for one user and a different version for another and then just compare what what works best. The only thing you can do when you have a local application is you can uh dog food it. So your entire team should actually be using you should be using your own tools and then you should love your users. You should really be on them all the time.
Ask them questions, interview them. um when they give you feedback, when they come and say, you know, this sucks. Then you have to take it and go back and say, "Thanks, but please tell me exactly what sucks." You have to go there and say, "Thank you for the feedback, but please tell me exactly what sucks." Like you you have to do a lot of work with your users.
It's difficult, but in the end, it pays uh because users do recognize this. Even the the the the most negative or you know pissed off feedback that a user can give. If you go there back and be kind and open and show to them that you understand their problem and their frustration and you want more from them to understand what you can do better. Um this even the most annoying or the most uh impolite user will appreciate. Um, you should build and design for clarity.
Uh, especially when it's a local application, if if it's if it doesn't make sense, uh, many users, you will just lose them. Uh, and they will never talk to you. They will never tell you that something didn't make sense. It's generally harder to know what works and what doesn't. And this is why you should um talk to users.
So the money question comes in here and says okay so if you if you if it's so difficult to build this then who pays for it? Well then revenue has to be explicit. You you you need to actually pay for an application like this. Um price should make sense and it should really map to whatever value is being delivered by the application to you. A user should accept and understand that they should fund what they want to exist.
You're not just paying for what the aligned app that you're using is today, but you are paying also for what it will be in the future if it keeps growing and if it keeps um going towards the vision that the builders for it have and very very important it is not a cost of hosting. There was a guy who came uh and talked to me in the booth and asked why should I pay for this? I self-hosted. So you have no hosting costs. So you have no costs.
So you're just making profit. I had to very politely explain that seven years of development with six developers translates to a lot of money. Um hosting costs are not the biggest cost of any even a SAS. The hosting costs are not the most expensive uh depending on their scale of course. Uh but the development costs are very very important.
So the cost of building and maintaining is what a user pays for. Um so how can you how can you fund something and respect privacy? I I'm um I'm a fan of premium and uh premium tiers with with various limits. We've experimented with sponsorships. This is actually very good.
Um uh you can give sponsorship opportunities to users or or companies that you are working with. Um please don't do any sponsorships for data. I heard this from someone and I was like, "No, no, no, please, please don't don't do anything like that." Um, you can try grants or donations or integrations by special feature requests from users. So, if you have some maybe high netw worth individual users that want a specific integration, maybe you can arrange something with them.
Others have tried uh merch uh so you create merch with your um logo. Uh you price it higher so you make some money out of that. or if your uh app can be used by enterprise, this is a very good way to of course uh have revenue with enterprise support. Um what we have tried and has so far worked is um we started with grants and donations. Um I wouldn't do that again.
Don't do it today. It won't work. You will run out of money. Really, seriously, do not go down the grants uh path. It's very difficult.
It takes a long time. sometimes you end up getting less money than you have personally invested because your time is money and it's just running out like the whole grants and donations things doesn't work anymore. Uh later we introduced uh premium tiers and subscriptions so to get actually revenue from our users themselves and we've recently added referrals and NFT sponsorship so people can sponsor uh roti releases today. So a combination of all this gives us predictable and recurring revenue. We haven't solved this yet.
We are still working for us towards something that will work. But the idea is you want predictable and recurring revenue from your users. You should not rely on grants and donations. Don't do that. You will suffer both as a company but also personally.
It's it's painful. Just don't don't go that way. Believe me, I've tried. Um so in such a system who pays and what do they pay for? Every part of the ecosystem ends up paying a bit because users should pay for with money for good products with good privacy standards and products that give you ownership of your data.
Builders of such products pay with their sweat and tears. They pay for their building time, the complexity, the amount of work that goes into a good application. I can't even like explain it in words in English is not my my my my native tongue. If you come by our discord like rokkey discord you we we have public channels where we talk about development. You will see all the problems and what happens while we develop and the community pays for this by you know of course uh attention and support.
So if you like something you can actually help it by giving it your attention uh spreading the word and supporting it. Pricing should really uh match the both the values of the company but also what what value is being delivered. So always keep a free tier. Do not do the thing that like free actually compromises privacy uh or like holds the user data hostage and they have to pay in order to export it. Don't do that.
That's really bad. Look. Um generally charge for higher limits. uh charge for support. Your time matters.
Um and uh make your users happy. Offer discounts for like contributors uh for longtime users. Create referral programs and be very transparent about how you spend your money. If you are not a a public um uh or or grant funded uh company, you you don't need to be transparent. But if you are, users recognize it because the users are not like um they are not your enemies.
They're actually many of them are also entrepreneurs themselves. Many are business owners. They are people. And if you explain to them what you need, where is the money going and what is your vision about the product, they actually open up, they respond. So if you are in a constant loop of talking with your users and what what's the vision and what you want to build for them, they will respond and they will actually want to pay you.
Um product principles that help make users happy is um local first. So self-hosted you will need network of course that is only offline but only when needed. Um have uh don't don't use proprietary formats. Use plane formats that are easy to export and easy to um to work with other tools. Go with minim minimal permissions by default.
There is nothing more annoying for a user than suddenly seeing that they they have shared data with you without them actually realizing it. So um if if you do any analytics or any tracking or anything just uh make it so that they understand that you are um you are doing this and that they're giving you this permission. Give user choices give them customization and be very transparent about what you are going to build and what is the the the road map for the future. Use your community. The word community has been used to death in this field.
You know, tokens, community around it, all that Your community is your users. You do not have a token. You have a product. And your users is your community. When I talk about community, I mean exactly this.
They are really an economic engine. If you if you're transparent and open to them and talk to them, they will lift you up. Use your community. like you can have sponsor slots for for for users. Um have leaderboards of who who gives uh the the most help.
Uh give referral programs of privacy respecting ones. People really like this incentivization and gamification. Um do events um meet your community, do meetups, quests. We have a booth at ROKI here. Come visit us.
Uh we can talk more about the product itself or give you alpha hores and nice stickers and uh some USB data blockers. Um do partnerships, work with other aligned apps, but s out the noise because u you always get something like, hey, can we collab? Can I have 30 minutes of your time? Can we do a partnership? Just work with partners that have similar values.
Ignore everybody else. There's way too much noise in this field. um use open standards when you collaborate and always give the users choice whenever you um integrate with another app. Do not impose anything on them. So coming to practical things that you as builders of applications should do from the very beginning define um the data life cycle and where is data stored.
you really should make sure that your data uh that the user data stays in the user machine or at least is always under their control. Define a profile for your users. Think who your ideal users are and build for them. Relentlessly iterate, talk to the users, iterate the profile and build for them. Find business model early.
Don't build for free. Um this is a mistake that I have done. Learn from my mistakes. Never ever give something out for free. Don't build stuff for free.
You deserve a lot more. And your users should not get used to the idea that something is free because they it's very very difficult to get out of this. Even users that love you at some point they will say, "Hey, that was free. Why do I have to pay for it now?" Even if they love you, even if they love what you're building, it's it's psychological.
From the very beginning, make your users understand that they need to pay for your work. Uh do not sell yourself do not sell yourself short sort price high. You are worth a lot more and your product is worth a lot more than you think. So price it accordingly. For users ask where your data lives.
Um for every single application that you are using. Think where where does the data get stored. Demand that you can you can export your data. Do not accept anything less. If uh let's say you use coinly or coin tracking or whatever um make sure that um one app could work offline, they don't.
But also that you can access it if they um if they just go bust. If someone flips a switch, can you actually use uh the accounting data or the the hours, days, weeks of work that you put to create this data? I can answer this for you. For all of these SAS applications, you can't. If they flip a switch, it has happened to many people in this field, it's gone.
All of the work that you have put into it. A good app, an aligned app keeps all your data local. And even if the company goes bust, which happens, you can still access it and run the latest version and just just work with your data. If an app actually uh ticks all these boxes, then by all means support it. uh like lift it up um use it and make sure that it thrives.
So the vision is a network of applications like that not just three huge uh SAS providers um creating an app that uh um are uh just uh the only thing that we use the users become in control. It's a continuous feedback loop of happy users supporting applications then the applications get enough money they make the users happier etc. The privacy and data sovereignty should be default in this case. So remember building aligned apps is punk. It's a rebellion against having only three um cloud service providers essentially controlling everything in this field and giving us free apps that essentially mine all of your data in order to um to survive.
That's all. Thank you so Thank you so much.
Automatic transcript — names and jargon may be misspelled.