Docs · Setup & everyday use
PasswordCoded
PasswordCoded is a local-first password and secrets vault included with Gattaca Plus alongside CodonTerminal's Plan and Second opinion. It encrypts the vault on your device, installs as a PWA, and supports encrypted multi-device sync.
Set it up
Open PasswordCoded
Open the hosted app in a modern browser. There is no installer to download and no API key to paste. Activate a new vault with your Gattaca Plus account, the same subscription that includes CodonTerminal's Plan and Second opinion. Your existing local vault and encrypted backups remain accessible offline.
Open PasswordCoded →Create a master password
Choose a unique master password you can remember. It encrypts and unlocks the vault on your device. Gattaca never receives it and cannot reset, recover, or override it. Resetting your Gattaca account password does not reset the vault master password.
Save the recovery kit
PasswordCoded offers a recovery kit immediately after vault creation. Download the encrypted backup and keep it somewhere separate from the device. The printable sheet leaves the master-password line blank for you to write by hand, so the app never sends the plaintext password through a printer.
Install it if you want an app icon
Installing is optional—the same vault works in a browser tab. Installed, PasswordCoded gets its own icon, opens full screen and works offline. Step-by-step instructions for iPhone, iPad, Android and computers are under “Install it like an app” below. PasswordCoded is still completing its real-device iOS and Android validation during early access.
Sign in when you want sync
Open Sync & account and continue with Gattaca. Plus adds an encrypted cloud copy, realtime updates, and multiple devices. PasswordCoded uses the shared account session; the Gattaca API key shown elsewhere in your account is only for Codon MCP.
Open your Gattaca account →
Install it like an app
iPhone and iPad
Safari
- Open passwordcoded.gattaca.software in Safari.
- Tap the Share button: the square with an arrow pointing up.
- Scroll down the list and tap Add to Home Screen.
- Tap Add, then open PasswordCoded from its new icon.
Android
Chrome
- Open passwordcoded.gattaca.software in Chrome.
- Tap the ⋮ menu at the top right.
- Tap Install app. Some phones call it Add to Home screen.
- Tap Install, then open PasswordCoded from its new icon.
Windows and Mac
Chrome or Edge
- Open passwordcoded.gattaca.software in Chrome or Edge.
- Click the install icon at the right end of the address bar, or open the browser menu and choose Install.
- Click Install. PasswordCoded opens in its own window, with its own Start menu or Dock icon.
- Installing is optional. The same vault works in a browser tab, and the installed app opens full screen and works offline once it has been opened.
- On iPhone and iPad, the home-screen app keeps its own storage, separate from Safari. Open it from the icon before you create your vault, or bring your vault in by signing in to sync with Plus or restoring your encrypted backup.
- On Android and computers, the installed app shares the browser's storage, so a vault you already made there is waiting for you.
Everyday use
What stays private
Encryption and decryption happen on your device. The sync service receives an encrypted envelope, not the master password or readable vault entries. While the vault is unlocked, the key lives only in memory and the app locks again after inactivity.
Add and organize entries
- Store account logins, passwords, secret phrases, notes, and other sensitive records.
- Search the vault, group entries by category, and use the built-in generator when you need a new password.
- Import entries from a supported CSV export, review every row before it is saved, and keep an encrypted backup before removing the old copy. See “Moving in from another password manager” below.
Moving in from another password manager
Export a CSV from your old manager and hand it to Smart Import. Nothing is written to the vault until you have seen it: every row arrives in a review screen with a suggested category you can change, likely duplicates already flagged, and a checkbox for anything you would rather not bring across. Duplicate flagging needs two matching signals — the same site and username, title and username, or title and site — because one alone is usually a coincidence rather than a duplicate. Delete the CSV export afterwards: it is a plaintext copy of your passwords, which is why the old manager warns you about it too.
- Most exports need no thought: the field names run across the top row, one account per row beneath. If you have nothing to export from, Download CSV template hands you a file already in that shape.
- A single-account file with the field names down the first column instead is reshaped for you, but only where there is no doubt — every label has to be one it recognises, no field may appear twice, and there must be at least three of them including both something identifying (a title or a website) and a credential (a username or password). Anything short of that is refused, with the expected layout spelled out. Quietly guessing at the shape of a file full of credentials is worse than asking.
- Sorting entries into categories needs no download and no AI — the built-in rules organizer runs instantly, on your device.
- You can optionally turn on on-device AI organization for better category suggestions. It downloads a ~220 MB open model (EmbeddingGemma 300M) once, caches it, and runs it inside your browser — not on our servers, and not on anyone else's.
- The AI is shown three things about each entry and nothing else: its title, the website's hostname, and the category it already had.
- It is never shown passwords, usernames, notes, other secrets, or the raw CSV. That is enforced by the shape of the data it can receive, by the code that builds it, and again by the worker that receives it — three independent checks, so no single mistake can open it.
- Even the website address is reduced to a bare hostname first, which drops the path, the query string and any credentials embedded in the link — all three are places a secret genuinely turns up in real exports.
- The import itself makes no off-device request at all. Two automated tests assert exactly that on every release, and a third puts a marked value in every secret-bearing field and fails if it appears anywhere in what the AI receives.
Set up or remove the on-device AI in advance
The AI organizer can be downloaded before you need it, from Smart Import AI in the menu, rather than part-way through an import. The screen says whether the model is already stored, reports how much free space the device has before it offers the download, and can remove the files again afterwards.
- Doing it in advance is the calmer path. The alternative is a ~220 MB download arriving in front of you after you have already chosen a file and committed to the import.
- Removing the files never touches the vault. Quick organize keeps working without them, and the model can be downloaded again later.
- The setup screen shows the model nothing at all — no entries, no metadata, not even a file. It only fetches and stores the model, so preparing it commits you to nothing.
Use more than one device
With Plus active, sign in with the same Gattaca account on the second device and download the encrypted vault. Unlock it with the same master password. Changes sync entry by entry, including deletions, and an open editor is not replaced underneath you.
Backups and recovery
- Export an encrypted backup after important changes and keep at least one copy away from the device.
- If you forget the master password, support cannot open the vault. Restore a backup only if you still know the password that encrypted it.
- If there is no usable backup and the master password is lost, the local vault can be erased so you can start again; the old encrypted data remains unreadable.
Biometric unlock
Supported devices can enroll biometric unlock after the vault is working. It is a convenience for that device, not a replacement for the master password or recovery kit. If the browser or authenticator does not support the required WebAuthn feature, the normal master-password path remains available.
If Plus ends
Your local vault and encrypted exports remain available. Uploading new cloud changes and realtime cloud writes pause when paid access ends, while the existing encrypted cloud copy remains available for you to read, download, or delete. Billing never takes away the local copy or the ability to export it. Re-enable Plus to resume cloud writes.
Early-access limits
Cross-site autofill is not included yet. PasswordCoded is also completing real-device validation and an external security review. Until that work is signed off, keep an encrypted backup and do not make it the only copy of credentials you cannot afford to lose.
When something isn't working
The Help page lists common PasswordCoded problems with the fix for each. Search it for the words on your screen. If you are still stuck, the contact details are at the bottom of that page.
PasswordCoded help →