HTLC routing (demo 14) locked every hop to the same hash. A PTLC locks it to a point T = t·G instead, using a Schnorr adaptor signature: each hop issues a payment as a pre-signature that only becomes valid once the secret scalar t is added, and publishing the finished signature reveals t to the hop behind it. Same idea as a preimage, but it rides inside an ordinary signature: nothing on-chain looks special, and each hop can offset the point so the hops can't be linked. It's what Taproot lets Lightning become.
Both hops are locked to the same point T. Each is a real Schnorr pre-signature: provably completable by whoever knows the matching t, yet invalid until then.
The completed signature verifies with the exact schnorrVerify from demo 11, so the chain can't tell a PTLC from any other spend.
There's no hashlock and no preimage on-chain, just a normal Schnorr signature. The secret t is the difference between the pre-signature and the finished one, so anyone holding the pre-sig recovers it the instant the payment settles.
Each forwarder can lock its outgoing hop to T + y·G for a random y. The points all differ, so an observer can't tie the hops of one payment together. Then the node peels y back off to learn t.
The same primitive powers discreet log contracts, atomic swaps and cross-chain trades: issue a signature "encrypted" under a point, and completing it publishes the point's discrete log. Taproot's Schnorr is what makes it clean.