How a send works
One approval in the sender's wallet does the send and the keep, in one Stellar transaction.
The sender chooses an amount in USDC and a keep, 10% unless they say otherwise. Sown asks the Aquarius pool what the keep would buy right now, by simulating the pool's ownestimate_swap, and shows the least it may become: that estimate less 1%.
The wallet signs one transaction that calls send on the Sown contract. Inside it, the contract takes the USDC from the sender, swaps the keep on the Aquarius pool, counts the units that actually arrived, and refuses the whole send if they are fewer than the least the sender saw. If anything fails, nothing moves.
The contract authorises the pool to pull exactly the keep from it (authorize_as_current_contract), so the sender's one signature is enough. Both parts then wait in an envelope on the contract, and the send prints a receipt anyone can open.
The sender's browser makes the link's secret. It never goes to Sown's servers; the envelope stores only its public half. The sender shares the link, on WhatsApp or anywhere.
Next: The envelope