Frequently asked questions

Support · Last reviewed August 2026

Answers about how the app handles your credentials, what it can and can't automate, and how to get your data out. Where there's a limitation, it's stated rather than buried — this app types your passwords into login forms, so you're entitled to know exactly how that works before you trust it with anything.

Security & privacy

Where are the passwords for my sites stored?

Server-side, encrypted at rest in Supabase Vault. They are not persisted into the app's local state on your device.

That design has a specific consequence worth understanding: a stolen or unlocked phone does not hand someone a copy of your site passwords, because the phone isn't where they live. It also means the app needs a network connection to perform a login.

Can you see my passwords?

The honest answer needs two parts.

In normal operation, no. Your credentials sit encrypted, and are decrypted server-side — momentarily, by a restricted edge function — only at the point a login you initiated needs them. They are never read, shared, or sold. That commitment is in the Privacy Policy.

But to be precise about what that does and doesn't mean: this is not zero-knowledge encryption. Any system that can type your password into a third-party login form must be able to recover that password, so the ability to decrypt necessarily exists on the server. What protects you is that this ability is scoped to performing logins you asked for, not that it's mathematically impossible to exercise.

If your requirement is that literally nobody but you can ever decrypt a credential, that property is fundamentally incompatible with automated form filling, and a zero-knowledge password manager is the right tool for those particular accounts. Our guide on choosing where credentials live covers the trade-off in general terms, without reference to this app.

Should I use this for my most sensitive accounts?

We'd suggest not, and it's worth explaining why rather than just claiming everything is safe.

mySwitchBoard is built for the dashboards you open repeatedly — analytics, reporting, helpdesks, client consoles. The accounts that control everything else (your domain registrar, DNS, primary email, cloud root) are a different category. Those are worth protecting with a hardware key and a bit of deliberate friction, and they're not the accounts where batch login saves you much time anyway, since you sign into them rarely.

Our guide on ranking accounts by blast radius explains how to draw that line for your own setup.

What happens if I lose my phone?

Your site credentials aren't stored on the device, so they don't leave with it. The app also supports a Face ID or fingerprint lock as an extra gate in front of your account, so a signed-in phone isn't the same thing as an unlocked one.

That said, treat it as you would any account on a lost device: change your mySwitchBoard sign-in password from another device, and if you signed in with Google, Facebook, or X, review the active sessions on that provider too. Our guide on sessions and device trust covers what "sign out everywhere" does and doesn't cover.

What data do you collect about me?

Your sign-in identity (email and basic profile from whichever provider you use), the sites and credentials you choose to add, and — because the app is ad-supported — device identifiers and usage data collected by Google AdMob to serve and measure ads. The Privacy Policy is the authoritative version and is short enough to read in full.

Does the app show ads?

Yes. mySwitchBoard is free and supported by ads served through Google AdMob.

How it works

Do I need to write CSS selectors?

No. That's the part the app is specifically designed to remove.

You open the site's login page inside the app and tap the actual username field, the actual password field, and the actual submit button. The app works out how to find them again. No developer tools, no inspecting page source, no hand-written selectors.

What happens when a site changes its login page?

The saved selection can stop matching, and the login will fail to fill correctly. Login pages change without notice and we can't guarantee otherwise — this is stated plainly in the Terms.

The fix is the same short process as the initial setup: open that site's configuration and re-tap the fields on the new page. It takes about as long as logging in manually once.

What are Flows?

A Premium feature for the steps that come after login. You record a sequence of clicks and inputs once — the report you pull every week, the filter you always set, the date range you always change — and replay it in one tap.

How do I sign in to mySwitchBoard itself?

Email and password, or Google, Facebook, or X — whichever account you already trust. This is separate from the credentials you store for your own sites.

Is this a replacement for my password manager?

No, and it isn't trying to be. A password manager is where credentials live for your whole digital life, including the accounts you should never automate. mySwitchBoard does one narrower job: opening a group of dashboards and signing into each one, in sequence, without you retyping anything.

Plenty of people sensibly use both — the manager as the system of record, this for the daily batch.

Site compatibility

Will automated login work on every site?

No, and it's better to know that upfront than to discover it after installing.

Many sites deploy anti-bot and anti-automation protections that are specifically designed to block automated interaction, regardless of whether it's you doing the asking. When a site refuses automated interaction, that's the site's protection working as intended — not a fault in the app. The Terms cover this explicitly.

In practice, ordinary username-and-password dashboards work well. The more security machinery a site puts in front of its login form, the more likely it is to push back.

Why does it use real browser tabs instead of just sending requests?

Because a real browser tab is what most login pages actually expect. Sites depend on their own JavaScript running, on scripts setting cookies, and on the page behaving like a page — a synthetic request often gets rejected by machinery that has nothing to do with your credentials being correct.

Using a genuine WebView tab means you're logging in the same way you would by hand, just without the typing. It's also why each site opens as its own visible tab rather than happening invisibly: you can see exactly what the app did.

Account & data

Which platforms is it available on?

Android, on Google Play now. iOS is in progress and not yet released — the App Store button on this site is deliberately inactive rather than pointing somewhere that doesn't exist yet.

How do I delete a single site without deleting my account?

On the home screen, swipe the saved site and tap delete. That removes the site and the encrypted credential stored for it, and leaves your account and everything else intact.

How do I delete my account and everything in it?

In the app: Settings (the gear icon) → your profile → Danger zone → Delete account. You'll type your email to confirm. Deletion is immediate and cannot be undone.

If you can't sign in any more, email us from the address on the account and we'll do it for you. Full instructions, including exactly what gets removed, are on the Data Deletion page.

How do I get in touch?

Email us: contact us. Questions about a specific site not working are useful — tell us which site and what happened, and it helps us understand where compatibility breaks down.

Related reading