Hi Bryan,
Thanks for your input.
>That's a neat trick. What about not using OP_RETURN at all, and just
publishing on a tor hidden service that other wallets check? Alice
wouldn't have to expose on-chain that she is a sender of a private
payment.
This can be done (Tor keys can even be derived from master keys) but it's an off-chain solution, not very different from Bitmessage notifications in BIP47. As Ruben said, it won't work in an offline regime.
Alfred