I assumed the relay and the gateway were kept apart by something built into the protocol itself, a wall neither side could see past even if it tried to.
That's close, but not quite it. Each one only holds half of what's needed to identify a request — the relay has the IP, the gateway has the content. Neither can connect a person to a request alone. What I missed is that nothing in the design stops the two of them from comparing notes afterward. The separation holds only for as long as they don't choose to.
I went looking for the part that makes collusion impossible, expecting some cryptographic lock I'd missed somewhere, a step where one operator simply can't reach the other even if both wanted to. There isn't one. OpenGradient calls this a non-collusion guarantee, an odd phrase once you sit with what it actually claims: not this cannot happen, but this works as long as it doesn't. No contract enforces that, no code blocks the conversation between them. It's an assumption the system is built on top of, not a wall built into it.
What shifted for me wasn't the guarantee itself. It was noticing the question had quietly moved from can this be broken to who would have to agree, on the @OpenGradient network, to break it. #OPG $OPG