What a valid draw means, precisely
No hand-waving. These are the rules the engine enforces, and the source code that enforces them ships with the site.
Guarantees
- One-to-one. Every person gives exactly once and receives exactly once; the assignment is a bijection over the names you entered.
- No self-draws. A person never draws themselves.
- Mutual exclusions. If you mark A and B, neither draws the other.
- Randomness. Shuffles use the browser’s cryptographic random source; the engine reshuffles with fresh randomness up to 250 times until the rules are satisfied.
- Honest failure. If no valid draw is found, you get an error — never a draw with a quietly dropped rule.
The receipt
At shuffle time the full assignment is serialized, sorted, and hashed into a single SHA-256 Merkle root — the receipt. Each participant link carries one leaf of that tree plus its sibling path, so a link can prove membership in the commitment without exposing any other pairing. Verification is public on /verify/.
Limits (stated plainly)
- The receipt proves the committed draw; it cannot prove the organizer delivered every link.
- Links are obfuscated, not encrypted — hold the link, hold that one pairing.
- The organizer sees the full draw by design (someone has to hand out links).