Campus e-Rupee Tap & Pay · Android & iOS

Campus payments that work without a signal.

Ghost is an offline-first e-Rupee wallet for Indian university campuses. Students pay at canteens, stationery stalls, fests and transit points with signed transactions that complete on the phone, then settle in one batch when the network returns.

Pays with no network Signed on the device Early access
Load Offline Pocket of e₹ tokens
Pay Signed on the phone, no network
Queue Queued by nonce
Settle One batch when back online
₹500 per offline payment The most a single payment can be while the phone has no network.
₹2,000 unsynced in total The most that can wait on a phone before it has to settle.
Retries never settle twice Each payment carries an idempotency key, and batches settle in nonce order.

The problem

Campus payments fail where students queue.

Canteen counters, stationery stalls, reprographics, student fests and underground transit junctions see cellular congestion, dead zones and UPI server timeouts. A ₹40 payment stalls, and so does the queue behind it.

Ghost is built for universities that want payments to keep working across campus, merchants who need the sale to complete at the counter, and students paying in a basement canteen or a crowded fest.

01

Load the Offline Pocket

While connected, move money from the Online Vault into an Offline Pocket held as numbered e₹ token envelopes from ₹50 to ₹500.

02

Tap & Pay with no network

Ghost picks the tokens, signs the payment with the phone's own key and the next nonce, and completes it on the device.

03

Settle in one batch

Once a connection is confirmed, queued payments go to the bank interface in nonce order as an idempotent batch.

What's in the app

An Android and iOS wallet built for offline first.

Every payment is signed on the phone and kept in a local queue, so the app works the same with or without a network.

Vault and Offline Pocket

Two balances side by side: the bank account, and the e₹ tokens held on the phone to spend offline.

Signed on the device

An Ed25519 key is created on the phone and kept in secure storage. Each payment is signed with its token serials.

Anti-replay nonces

An incrementing nonce in every signed payment stops a captured or re-sent payment from being played back.

Offline limits built in

Tokens are reserved as they are spent, so the same money can't be spent twice on the phone.

Sync status and history

A live sync badge with the queue count, and each payment shown as pending, settled or in conflict.

Conflicts flagged

A payment rejected at settlement, such as a token already spent, is flagged, its tokens are quarantined, and it can be disputed.

Status: early access

A working prototype, opening for campus pilots.

Ghost runs on Android and iOS and is designed around the RBI's two-tier retail e-Rupee (e₹-R) model. Pilots with universities and campus merchants are arranged by conversation with Gander.

Ghost does not issue e-Rupee and is not connected to a live bank or CBDC system. Settlement currently runs against a simulated bank interface used for testing, including fault injection for dropped networks and double spends.

Universities

Keep canteen, stationery, fest and transit payments working where the network doesn't.

Campus merchants

Complete the sale at the counter, with settlement following once the phone is back online.

Students

Pay in a basement canteen or a crowded fest, within clear offline limits.

Student bodies

Help choose the counters and events where a pilot would start.

Early access, by conversation

Pilot Ghost on your campus.

Tell us about your campus, where payments fail today and the counters you would start with. You can also write to hello@gander.co.in.