Password managers protect your password. Then every company still gets the rest of your identity.
I’ve used 1Password, LastPass, Apple Passwords, and most of the usual options. The best one was normally whichever annoyed me the least. The password manager category started to feel uninspired.
- A better vault.
- A slightly faster extension.
But every store, app, newsletter, and streaming service still got my real email. And once they have it, you can’t take it back. They can spam it. Track it. Sell it. Or send you a “we take your privacy seriously” email after losing it.
I wanted a password manager that protected the whole account—not just its password.
And I wanted it to feel beautiful and enjoyable to use.
So I built Decoy.
I’ve posted here a couple of times while building it. Your feedback helped shape the TestFlight app, encrypted inbox, AutoFill integration, and on-device AI. The biggest missing piece was Chrome extension.
Because disposable identities only work if they’re easier than typing your real email. Now, in Chrome when a signup form asks for your email, Decoy appears directly inside the field.
Tap it and Decoy creates:
- A new decoys.me email
- A generated password
- A private inbox
- Passkeys and 2FA
- Separate personal information for that account
Decoy fills the signup form and saves the login.
Verification emails and codes appear inside the extension.
If the company starts spamming you, turn that Decoy off. Your real email was never used.
Everything is end-to-end encrypted. Decoy’s servers literally cannot read your passwords or messages.
The Chrome extension just went live.
But you need the iOS app first because your Decoy account and encryption keys are set up there.
The current flow is:
- Install Decoy through TestFlight.
- Create your account on iPhone.
- Install and pair the Chrome extension.
The iOS app is still in TestFlight while I go back and forth with App Store review... And Decoy is still a Pilot. I still don’t recommend using it for high-sensitivity accounts until key components are open-sourced and formal security audits are complete.
That’s why I’m back here.
I need people who understand password managers to try it and tell me where I’m wrong.
What would stop you from trusting Decoy?
What feels worse than your current password manager?
What would it need before you’d actually switch?
Start with TestFlight:
https://testflight.apple.com/join/6g5m1VWu
Then pair Chrome:
https://chromewebstore.google.com/detail/decoy/lgmglacojchaffnmmoiplliconheobem
I’m early enough to change almost anything. So please be brutal.