Security at Uurly
How Uurly keeps your wallet and your data safe — and what it can't do for you.
Your keys never leave your computer. Uurly is non-custodial: the app trades from your own wallet, on your own machine. The Uurly server holds no wallet and cannot trade.
1. Two parts, one rule
Uurly has two parts. Our server picks up new coins on Solana, Robinhood and Arc and measures each one. Your app, on your Mac or Windows computer, judges every coin with your own settings and — only with a paid license — buys and sells from your wallet.
The rule between them: data about coins flows from the server to your app; your keys and your trades' signatures never flow the other way. The server has no wallet of its own, by design, so even a fully compromised server could not move your funds.
2. Your private keys
- Wallet keys, seed phrases and API keys you enter are stored encrypted in the app's own data folder on your computer (Fernet: AES-128 encryption with an HMAC integrity check).
- The key that decrypts them sits in the same folder, readable only by your own user account. This protects against casual exposure — a shared screen, a synced folder, someone browsing your files. It does not protect against someone who controls your whole computer and user account.
- Keys are never sent to Uurly, never logged, and never included when you export your settings.
- Transactions are signed on your computer and sent straight to the blockchain.
3. What our server sees
| Data | Why |
|---|---|
| Your license key (we store only a hash of it), a device fingerprint (a hash, never the raw hardware identifiers), app version, IP address | Checking your license and the one-device limit |
| Your email address and sign-in codes (codes stored only as a hash, valid 10 minutes) | Signing you in |
| With the dashboard on: your trades, positions, balances and public wallet addresses | Showing them on your personal dashboard — held only to relay them, not stored |
Never: private keys, seed phrases, or anything that could sign a transaction. Full details are in the Privacy Policy.
4. Signed answers
Every license check is answered with a digital signature (Ed25519) that the app verifies with a public key built into it. An edited settings file or a fake server can't unlock live trading, extra features or themes.
5. Sign-in and downloads
- No passwords: you sign in with a 6-digit code sent to your email. Sessions use secure, HTTP-only cookies.
- Our sign-in and registration forms are protected against bots and rate-limited.
- The app can only be downloaded after you sign in. Your account page shows the SHA-256 fingerprint of every download, so you can check that the file you have is the one we published.
- The app is not yet signed by Apple and Microsoft, so your computer warns you the first time you open it. Code signing and Apple notarization follow as soon as our company registration is complete.
6. What you should do
- Use a separate trading wallet with only the funds you are prepared to lose — never your main wallet.
- Keep your computer and operating system up to date, and use a strong login password.
- Never share your private key, seed phrase or license key. The Uurly team will never ask for them and will never DM you first.
- Only download Uurly from your account page on uurly.io.
7. Report a security issue
Found something? Tell the Uurly team privately — via a direct message to a Team member on our Discord — rather than posting it in public. We look at every report.