Security at Uurly

How Uurly keeps your wallet and your data safe — and what it can't do for you.

Your keys never leave your computer. Uurly is non-custodial: the app trades from your own wallet, on your own machine. The Uurly server holds no wallet and cannot trade.

1. Two parts, one rule

Uurly has two parts. Our server picks up new coins on Solana, Robinhood and Arc and measures each one. Your app, on your Mac or Windows computer, judges every coin with your own settings and — only with a paid license — buys and sells from your wallet.

The rule between them: data about coins flows from the server to your app; your keys and your trades' signatures never flow the other way. The server has no wallet of its own, by design, so even a fully compromised server could not move your funds.

2. Your private keys

3. What our server sees

DataWhy
Your license key (we store only a hash of it), a device fingerprint (a hash, never the raw hardware identifiers), app version, IP addressChecking your license and the one-device limit
Your email address and sign-in codes (codes stored only as a hash, valid 10 minutes)Signing you in
With the dashboard on: your trades, positions, balances and public wallet addressesShowing them on your personal dashboard — held only to relay them, not stored

Never: private keys, seed phrases, or anything that could sign a transaction. Full details are in the Privacy Policy.

4. Signed answers

Every license check is answered with a digital signature (Ed25519) that the app verifies with a public key built into it. An edited settings file or a fake server can't unlock live trading, extra features or themes.

5. Sign-in and downloads

6. What you should do

7. Report a security issue

Found something? Tell the Uurly team privately — via a direct message to a Team member on our Discord — rather than posting it in public. We look at every report.