Drag to read
One interchange, five linesEvery app on one line.
One stop to sign in.
Phocod replaces the separate apps you'd otherwise install — messaging, a professional profile and job search, a local marketplace, and more — with a single account. Nothing is pooled between them: each app keeps its own database, its own line, its own destination.
Five lines. Each one a real product.
Open any app below and you're already signed in — nothing here is a placeholder screen waiting to be built.
Phocod Chat
Real-time messaging with optional end-to-end encryption you can turn on per conversation.
- Groups, channels, communities & bots
- Reactions, replies, editing & forwarding
- Search, starring & optional end-to-end encryption
Phocod Professional
Your professional presence — profile, network, and job search in one place.
- Public profile, posts & feed
- Connections, follows & recommendations
- Companies, job listings & applications
Phocod Marketplace
Local listings without a separate marketplace app — currently in development.
- Item listings & local browsing
- Same account as Chat & Professional
- Its own isolated database, nothing shared
Phocod Entertainment
Async, turn-based games and leaderboards — in development.
- Games & leaderboards
- Same account as every other app
Phocod Intelligent
AI agent monitoring and notifications — in development.
- Agent status & event history
- Notification routing into the app you're already using
One app, both platforms.
Native app for Android today, same account as the web. iOS is coming soon.
Android live · iOS coming soon
One sign-in, three stops
Verified independently by each app you open — no app ever touches Phocod's database directly.
Sign in once
Create your Phocod account or log in — your password is checked and hashed here, nowhere else.
Open any app
That app asks Phocod for a short-lived identity token on your behalf.
It signs you in
The token is verified, a session is minted, and the token is discarded — unusable again.
Private by design, in plain terms
No vague "bank-level security" claims — here's exactly what's implemented, so you know who can (and can't) see your data.
Messages only you and the recipient can read
Chat can be end-to-end encrypted device-to-device (ECDH key exchange, AES-256-GCM) — once you turn it on, not even Phocod can read the message.
Nothing pooled across apps
Chat, Professional, and Marketplace each keep their own database. Nobody can cross-reference your messages, profile, and listings without your say-so.
Passwords, hashed properly
Hashed with scrypt, a memory-hard algorithm built into Node's own crypto — not stored, not reversible, not shared with any other Phocod app.
Tokens that only work once
Valid for 30 days, but usable exactly once — replaying it a second time is rejected outright.
Rate-limited by design
Login and signup are rate-limited per account, so repeated password-guessing is slowed down automatically.
Cookies your browser's JS can't read
Session cookies are httpOnly and same-site — invisible to page scripts, sent only to the app that issued them.
Compared to the apps you already use
Named, checkable facts about the apps Phocod is meant to replace — not a generic "us vs. them."
| Telegram | FB Marketplace / OLX | Phocod | |||
|---|---|---|---|---|---|
| Messaging & communities | Yes | Yes | — | — | Yes |
| Group chats | Yes | Yes | — | — | Yes |
| Broadcast channels | Yes | Yes | — | — | Yes |
| Bots & automation | Yes | Yes | — | — | Yes |
| Message deletion | Yes | Yes | — | — | Yes |
| Message editing | Yes | Yes | — | — | Yes |
| Message reactions | Yes | Yes | — | — | Yes |
| Reply / quote messages | Yes | Yes | — | — | Yes |
| Message forwarding | Yes | Yes | — | — | Yes |
| Starred / saved messages | Yes | Yes | — | — | Yes |
| In-chat message search | Yes | Yes | — | — | Yes |
| Typing indicators | Yes | Yes | — | — | Yes |
| Read receipts | Yes | Yes | — | — | Yes |
| Grouped communities | Yes | Yes | — | — | Yes |
| Multi-device support | Yes | Yes | — | — | Yes |
| End-to-end encryption | Default | Opt-in, 1:1 only | — | — | Opt-in, 1:1 only |
| Voice & video calls | Yes | Yes | — | — | Not yet |
| Blocking & reporting | Yes | Yes | Yes | Yes | Yes |
| Professional network & job search | — | — | Yes | — | Yes |
| Public profile with headline & bio | — | — | Yes | — | Yes |
| Posts & feed | — | — | Yes | — | Yes |
| Comments & likes on posts | — | — | Yes | — | Yes |
| Follow other users | — | — | Yes | — | Yes |
| Connections & job recommendations | — | — | Yes | — | Yes |
| Company & employer pages | — | — | Yes | — | Yes |
| Job applications & hiring pipeline | — | — | Yes | — | Yes |
| People, company & job search | — | — | Yes | — | Yes |
| Local buy & sell marketplace | — | — | — | Yes | In development |
| Item categories & local search | — | — | — | Yes | Not yet |
| Native mobile app | Yes | Yes | Yes | Yes | Android |
| Ads shown to users | — | Yes | Yes | Yes | — |
| Monthly cost | Free | Free | $29.99+ | Free | Free |
| One account covers all of the above | — | — | — | — | Yes |
Frequently asked questions
Is my password shared with Chat, Professional, or the other apps?
No. Your password is hashed and stored only by Phocod (this app). Other apps never see it — they receive a short-lived, single-use token proving you're signed in, not your credentials.
What happens if a token leaks?
Identity tokens are single-use — each app rejects a token it's already seen once, even before it expires 30 days later. A leaked token that's already been used is rejected outright.
Why not just use a third-party login provider?
Phocod's apps are independent codebases with their own databases, sharing only identity. Running our own identity service keeps that boundary explicit and means no user data ever needs to leave the platform.
Can Phocod read my messages?
Not if you turn on encryption for a conversation — it uses device-to-device key exchange (ECDH) and AES-256-GCM, so only your device and the recipient's hold the key. Encryption is opt-in per conversation, not on by default yet.
Is Phocod finished?
No — it's in active development. The identity and single sign-on flow described here is real and working today; some linked apps are still being built out.