Drag to read

One interchange, five lines

Every app on one line.
One stop to sign in.

Phocod replaces the separate apps you'd otherwise install — messaging, a professional profile and job search, a local marketplace, and more — with a single account. Nothing is pooled between them: each app keeps its own database, its own line, its own destination.

Fig. 1 — identity interchangeVerified independently by each app
YOUChatProfessionalIntelligentMarketplaceEntertainmentONEACCT
ChatMessaging & communities
ProfessionalNetwork & jobs
MarketplaceLocal buy & sell
EntertainmentGames & leaderboards
IntelligentAgent monitoring
2
apps fully built and usable today
1
account across all of them
0
databases shared between apps
33
features compared head-to-head vs. real apps

Five lines. Each one a real product.

Open any app below and you're already signed in — nothing here is a placeholder screen waiting to be built.

One sign-in, three stops

Verified independently by each app you open — no app ever touches Phocod's database directly.

1

Sign in once

Create your Phocod account or log in — your password is checked and hashed here, nowhere else.

2

Open any app

That app asks Phocod for a short-lived identity token on your behalf.

3

It signs you in

The token is verified, a session is minted, and the token is discarded — unusable again.

Private by design, in plain terms

No vague "bank-level security" claims — here's exactly what's implemented, so you know who can (and can't) see your data.

Messages only you and the recipient can read

Chat can be end-to-end encrypted device-to-device (ECDH key exchange, AES-256-GCM) — once you turn it on, not even Phocod can read the message.

Nothing pooled across apps

Chat, Professional, and Marketplace each keep their own database. Nobody can cross-reference your messages, profile, and listings without your say-so.

Passwords, hashed properly

Hashed with scrypt, a memory-hard algorithm built into Node's own crypto — not stored, not reversible, not shared with any other Phocod app.

Tokens that only work once

Valid for 30 days, but usable exactly once — replaying it a second time is rejected outright.

Rate-limited by design

Login and signup are rate-limited per account, so repeated password-guessing is slowed down automatically.

Cookies your browser's JS can't read

Session cookies are httpOnly and same-site — invisible to page scripts, sent only to the app that issued them.

Compared to the apps you already use

Named, checkable facts about the apps Phocod is meant to replace — not a generic "us vs. them."

Feature comparison of Phocod against WhatsApp, Telegram, LinkedIn, Facebook Marketplace, and OLX
 WhatsAppTelegramLinkedInFB Marketplace / OLXPhocod
Messaging & communitiesYesYesYes
Group chatsYesYesYes
Broadcast channelsYesYesYes
Bots & automationYesYesYes
Message deletionYesYesYes
Message editingYesYesYes
Message reactionsYesYesYes
Reply / quote messagesYesYesYes
Message forwardingYesYesYes
Starred / saved messagesYesYesYes
In-chat message searchYesYesYes
Typing indicatorsYesYesYes
Read receiptsYesYesYes
Grouped communitiesYesYesYes
Multi-device supportYesYesYes
End-to-end encryptionDefaultOpt-in, 1:1 onlyOpt-in, 1:1 only
Voice & video callsYesYesNot yet
Blocking & reportingYesYesYesYesYes
Professional network & job searchYesYes
Public profile with headline & bioYesYes
Posts & feedYesYes
Comments & likes on postsYesYes
Follow other usersYesYes
Connections & job recommendationsYesYes
Company & employer pagesYesYes
Job applications & hiring pipelineYesYes
People, company & job searchYesYes
Local buy & sell marketplaceYesIn development
Item categories & local searchYesNot yet
Native mobile appYesYesYesYesAndroid
Ads shown to usersYesYesYes
Monthly costFreeFree$29.99+FreeFree
One account covers all of the aboveYes

Frequently asked questions

Is my password shared with Chat, Professional, or the other apps?

No. Your password is hashed and stored only by Phocod (this app). Other apps never see it — they receive a short-lived, single-use token proving you're signed in, not your credentials.

What happens if a token leaks?

Identity tokens are single-use — each app rejects a token it's already seen once, even before it expires 30 days later. A leaked token that's already been used is rejected outright.

Why not just use a third-party login provider?

Phocod's apps are independent codebases with their own databases, sharing only identity. Running our own identity service keeps that boundary explicit and means no user data ever needs to leave the platform.

Can Phocod read my messages?

Not if you turn on encryption for a conversation — it uses device-to-device key exchange (ECDH) and AES-256-GCM, so only your device and the recipient's hold the key. Encryption is opt-in per conversation, not on by default yet.

Is Phocod finished?

No — it's in active development. The identity and single sign-on flow described here is real and working today; some linked apps are still being built out.

This app is in active development

The sign-in and single sign-on flow above is real and working today. Sign-in for every Phocod app, including this one, routes through here.