For derived keys, can the encryption include the derivation path in plaintext? I don't think that's an anonymity breaker if those paths are common well known things.
Discussion
That's kinda what I was trying to go for with the nonce, but the nonce is unique. It's super easy to find the destination key. The path might be better, but we still need to connect the path to a pubkey and the link makes the recipient visible 🤔