Uncork

What Uncork sends from your Mac, and where

Updated 29 September 2026 · checked against version 0.16.3

Short version: Uncork contacts our server for access and updates and sends your Mac's fingerprint, the app version and an access token; the server sees your IP address, as any server does. Game names, how long you play, files, Steam passwords and the list of programs on your Mac are not sent to us. The app has no third-party analytics and sends no crash reports, but our server keeps its own count of steps: that the app checked in, that a driver key was issued, that a sign-in was started. The rest of its traffic is downloads from other people's servers: installers and components by your buttons, covers and the purchased-games list in the background.

What goes to the Uncork server

The app talks to uncork.win, and if that address is not reachable on your network, to the fallback name of the same server, uncork.62-60-217-121.sslip.io (a name from the public sslip.io service, whose DNS servers see the lookup of that name). Every request carries a header with the app name and version; as on any server, the request address, the time and your IP address are logged with us, and how long the log is kept is stated in the privacy policy. The app makes no other connections to our server; you start sign-in with a button in the app and confirm it in your browser on the site, and payment does not go through the app but through Telegram or TON.

WhenWhat is sentWhy
You press "Sign in"your Mac's fingerprint and the app version; then, while it waits (ten minutes at most), with a two-second pause, a one-time sign-in secretto get a short code and to learn that you confirmed the sign-in in the browser
You sign in with an "UNCK-…" codethe code, the nickname and name you typed, the Mac fingerprint and the versionto bind access to your Mac
Your access is about to expire, or you press "Renew"the access token, the Mac fingerprint and the versionto renew access
App start or a game launch, only if there is no key, it is over 20 hours old, it is about to expire or the Mac's clock is behind; the "Renew key", "Get key", "Already paid" buttons and "Check" in the clock banner, "D3D11 test" in settings and in the first-run wizard; right after sign-inthe access token, the Mac fingerprint, the version and the reason for the request: launch (app or game start) or pairing (sign-in); no game name is sentto get the driver key
App start and the "Check" button in settings ask at once; in the background at most once every six hoursthe version and the Mac fingerprint in the request addressto learn whether a new version is out
You agreed to an updatean ordinary file requestto download the new version's disk image; before installing, the app checks the checksum and the signature: it must belong to the same developer as the installed version, and if the installed copy is signed without a developer (ad hoc), a signature from any developer is accepted

The Mac fingerprint is a short string: a SHA-256 hash of your Mac's hardware identifier (not its serial number) with a fixed salt string built into the app. The identifier practically cannot be recovered from it, but it is always the same, which is how the server recognises the same Mac.

The server notes that the app checked in (from the update check) and that a driver key was issued, each at most once a day per Mac; these marks are stored with the Mac fingerprint, not with an account, and are linked to one only through the licence, and "checked in" appears even before you sign in. It also notes that you started signing in in the app (each time you press "Sign in") and that you confirmed it, and on every renewal and key issue it remembers the time of the request and the app version. The marks carry no game name and cannot tell the server whether you played: opening the app asks for the key too. What else the server stores is in the privacy policy.

What is downloaded from other servers

The app downloads installers and components when you press your own setup buttons, and covers and the purchased-games list in the background; everything goes directly, bypassing our server, and that server sees your IP address, as with any download. The addresses below are the ones written in the code; downloads may be redirected to content delivery networks (CDNs) these services use, and their addresses are not listed here.

WhatFrom which serverWhen
The Windows Steam installercdn.cloudflare.steamstatic.com, fallback cdn.akamai.steamstatic.comwhen Steam is installed into a bottle (a separate environment for Windows games)
The compatibility layer and graphics librariesgithub.com: the Sikarugir-App and Gcenx repositoriesat first setup, by your buttons
The alternative graphics layer DXMTgithub.com: releases of the DXMT projectwhen Assetto Corsa is prepared, or with the "Install DXMT" button in bottle settings
Windows components for Assetto Corsa: .NET Framework, DirectX, the shader compilerdownload.microsoft.com, download.visualstudio.microsoft.com, raw.githubusercontent.com (the Mozilla repository)when Assetto Corsa is prepared
Content Manager for Assetto Corsaacstuff.clubwhen Assetto Corsa is prepared
The Epic Games installerlauncher-public-service-prod06.ol.epicgames.comif you chose this store when creating the bottle, or later with "Install a store"
The Ubisoft Connect installerstatic3.cdn.ubi.comif you chose this store
The EA app installerorigin-a.akamaihd.netif you chose this store
The Battle.net installerwww.battle.netif you chose this store
The GOG Galaxy installerwebinstallers.gog.comif you chose this store
The Rockstar Games Launcher installergamedownloads-rockstargames-com.akamaized.netif you chose this store
Rosetta 2Apple's servers, through the system softwareupdate toolif you pressed "Install Rosetta"
Epic game coverssubdomains of epicgames.com; the address comes from Epic's own catalog on your diskin the background, if Epic games are installed in a bottle
The list of purchased Steam games and coversapi.steampowered.com and shared.steamstatic.comin the background and only if you added your own Steam Web API key: Steam receives the key and the SteamID of the bottle's accounts (covers are requested for purchased but not installed games), and the key itself stays in your Mac's keychain and never reaches us

Steam, the stores, Content Manager and the games talk to their own servers as usual: Uncork does not intercept or read that traffic. These components belong to their authors and come under their own terms; Uncork does not put them in its own disk image but downloads them directly (the image holds only our driver bundle with the SDL libraries and three fonts), and is not affiliated with their authors; what they are and their licences are shown in the app: Settings → Help → Component licences. macOS itself may also send crash reports to Apple if you allowed it in system settings. Links from the menu and settings open in your browser only when you click them.

What the app does not send

Which permissions macOS asks for, and what Uncork does with them

How to check it yourself

A network monitor, such as LuLu or Little Snitch, will show the same addresses for Uncork itself and, during downloads, the delivery networks they redirect to. Steam and the games are separate processes: the monitor will show many other addresses for them, and that is their own traffic. Without third-party tools you can list the app's open connections this minute in Terminal:

lsof -nP -i -a -c Uncork

The requests are short, so the list is usually empty when the app is idle: on 29 September 2026 the running app, version 0.16.3, had no connections without a game. Right after launch the update check and the key renewal run, so the list may not be empty; downloads run not in Uncork itself but in a separate curl process, which will not appear in this list. To catch rare requests you need a network monitor.

What runs inside Steam and the games

Our libraries run inside the game processes: mouse reading, even frames, Dock names and the overlay panel, and our variant of the window driver. There is no Uncork network code in them; an automatic build check looks in the sources of these parts for typical network calls. The sources of the part of the driver that derives from the open compatibility layer are sent on written request, and where to write is stated in the licences in the app: Settings → Help → Component licences.

What happens without a connection to our server

Without a connection to our server, games keep starting until the driver key expires: up to a week, but never beyond the paid time plus one hour. The server can withdraw access, for example for breaking the terms; a withdrawal reaches the app the next time it contacts the server (usually within a day of use), and until then the key issued earlier keeps working.

If this changes

If the app starts sending something new or contacting a new address, we will update this page and the release notes before that version is released; the date at the top shows when the list was last checked. An automatic check compares the addresses in the code with this page and does not let the version build finish if they disagree. It cannot see what exactly goes to those addresses, so we check such changes by hand and note them in the release notes.

Read next

Get access

← Back to the main page