Choose what matters
Start with one thing that would be hard for someone else to understand without you.
Seal your passwords, keys, instructions, and final messages. If you ever stop checking in, Capsulene delivers them — encrypted end-to-end — to the people you trust, exactly when it should.
End-to-end encrypted · Zero-knowledge · No card required to start
Pick the situation that sounds like you — each page shows real examples, what to store, and a setup that works.
Seed phrases & wallets, inheritable — never readable by us.
Company access that survives any one person.
No guessing games — clear instructions when they matter.
Letters and time capsules that arrive exactly on time.
Client continuity without custodial risk.
Embed continuity in your product, zero-knowledge by design.
You already protect your information. Capsulene helps you prepare what happens next.
The future should not depend on uncertainty.
A simple path for what matters to reach the right person, at the right time.
What matters now has a path forward.
Start with one thing that would be hard for someone else to understand without you.
Give that thing a secure continuity path.
Add the access part, instruction, reference, or message that gives it meaning.
Select the person or team who should receive it. Add more than one contact method.
Choose a date, confirmation schedule, grace period, or release condition.
Your Capsule stays active until the conditions you defined are met.
What matters now has a path forward.
Capsulene is designed to avoid rushed, binary release. The goal is structure, review, and controlled delivery.
Payments are handled securely by Stripe as merchant of record — we never see or store your card details.
Disclaimer: Capsulene does not replace legal, financial, or estate planning advice. It provides a digital continuity layer for access-related information and instructions. Please consult with appropriate professionals for comprehensive estate planning.
Your most sensitive capsules are protected with end-to-end encryption and Shamir’s Secret Sharing. Capsulene keeps just one powerless fragment of the key — so not even we can open your vault, and a breach of our servers would reveal nothing.
1 · Encrypted on your device
2 · Key split into 3 shares
3 · Held apart, never pooled
Any two shares rebuild the key; a single share reveals nothing. Because we hold only one, breaching our servers would hand an attacker an encrypted blob and a mathematical dead-end. Your secret stays yours.
A random 256-bit data key seals your secret with authenticated AES-GCM. We store only the sealed envelope — never its contents.
Threshold cryptography over the GF(256) finite field shards the key into three. Two reconstruct it; one is mathematically worthless.
We hold one share and the ciphertext — that's it. No master key, no backdoor, no way for Capsulene to read your data.
Encryption and decryption run in your browser via the Web Crypto API. Plaintext never crosses the network or touches our servers.
The key-splitting behind every key capsule uses Privy's Shamir secret-sharing library — independently audited by Cure53 and Zellic. Shares export as portable SLIP-39 recovery phrases. Capsulene itself hasn't yet had an independent product audit; that's on our roadmap, and we'd rather say so than let you assume otherwise.
Your share, your recipient's share, and ours live in three separate places. Compromising any one of them leaks nothing.
Sign in with your device’s fingerprint, face, or PIN instead of a code. Passkeys are phishing-resistant public-key credentials — nothing typeable exists to steal — and always additive: e-mail codes and Google keep working.
An opt-in TOTP second factor gates sign-in — strict every-login mode or once a day, your choice. Codes live in your authenticator app, never in interceptable SMS.
Eight one-time backup codes, shown exactly once and stored only as hashes. The lost-phone escape hatch that never weakens the lock.
You and your recipient hold the keys that matter — so you stay in control, and only you can ever reveal what’s inside. See the technical details →
A key capsule seals a short secret. Now it can seal files too — documents, a keystore, photos, a video message — under the very same 2-of-3 shares. The difference: the encrypted files never leave your device. Capsulene doesn’t receive them, not even as ciphertext. You store them wherever you trust, and only your capsule’s shares can ever open them.
Your browser encrypts each file with a fresh random key, itself wrapped by your capsule’s key. You get a .capsulene copy of every file.
They’re just encrypted blobs — keep them on a drive, in your cloud, anywhere. Nothing readable, and nothing on our servers to breach or lose.
Your recipient decrypts them on the delivery page with the share you gave them — no account needed. You can too, any time, with your two shares.
We never receive your files. Not the plaintext, not the ciphertext, not the keys. Because they stay with you, the 32 KiB limit on capsule text doesn’t apply — encrypt files as large as your device can handle, and there’s nothing about them for anyone to subpoena, leak, or misplace on our side.
Each file is encrypted with its own random 256-bit key, wrapped by your vault key. Your vault key only ever seals tiny keys — never the file data — so every file stays cryptographically independent.
Large files are encrypted in authenticated chunks, so any tampering, truncation, or reordering is detected on decryption — you either get the exact original back, or a clear failure. Never a silent, corrupted half-file.
The encrypted files are yours — store them in two places, delete the originals once they open. They outlive any subscription, and even outlive Capsulene itself.
There’s a self-contained offline decryptor you can download — one HTML file that opens your .capsulene files and shares with no internet and no Capsulene. Keep it beside your encrypted files. Its format is published and it’s built from the same code as the app, so your files stay openable for decades.
Available on every key capsule — seal files as you create it, or add them later from the Utilities page. See the step-by-step guide →
Start free. Upgrade to a package when you need more active capsules.
Basic continuity, at no cost.
Free forever
No card required
More capsules, for everything that matters.
or €79.90 / year
Cancel anytime
Secure payment by Stripe
Serious capacity for a whole digital estate.
or €199.90 / year
Cancel anytime
Secure payment by Stripe
Capsules you create on the free tier stay yours — any future changes to the free tier apply to new sign-ups only. Each capsule uses a slot of its type (text or key), and package slots add on top of the free tier's own allowance. Custom check-in timing, SMS, and login-required check-ins are plan features — a one-time payment can also cover a single capsule. Applicable taxes are calculated at checkout. Payments and invoices are handled securely by Stripe — we never store your card details.
No. Capsulene is for continuity — storing context, instructions, or access shards that point to where your real assets live. You can also encrypt whole files with a key capsule, but they stay on your device — we never receive them.
Yes. A key capsule can encrypt files — documents, a keystore, photos, a video message — with the same 2-of-3 shares that protect your secret. It happens entirely in your browser, and the encrypted files never reach us, not even as ciphertext: you store them wherever you like, and only your shares can open them. Because they stay on your device, the 32 KiB limit on capsule text doesn't apply. Seal files while you create the capsule, or add more later from the Utilities page; your recipient decrypts them on the delivery page with no account needed.
Yes. From the Utilities page you can download a self-contained offline decryptor: a single HTML file that opens your encrypted files and shares with no internet and no Capsulene. Its format is published and it's built from the same code as the app. Keep it beside your encrypted files and shares, and everything can be recovered even if we're long gone.
We enter a grace period, notify your backup contacts, and attempt to reach you repeatedly before releasing anything.
Yes, you can pause or delete a Capsule at any time as long as it has not been released.
Anyone. Family, friends, lawyers, or co-founders. You just need their email and ideally a phone number.
No. Capsulene provides digital continuity, not legal estate planning. Use it alongside your will or trust.
Sign-in uses one-time email codes, Google, or a passkey — there is no reusable Capsulene password to leak. A passkey lets you sign in with your device’s fingerprint, face, or PIN: phishing-resistant, and always an addition (email codes and Google keep working; add up to five under Account → Security). On top of any of these you can enable two-factor authentication with any authenticator app (Google Authenticator, Authy, 1Password, …): choose a code at every login or once a day, and keep eight single-use recovery codes as the lost-phone escape hatch — a passkey never skips the second factor.
Add a backup email under Account → Security — it is the only way back into your account, because support can never restore access, no matter who asks. Recovery through the backup address is deliberately slow and loud: without two-factor authentication it opens a 48-hour waiting window and alerts your usual address, which can cancel the attempt with one click; with two-factor on, your authenticator code still applies, so sign-in through the backup works right away. Set it up before you need it — and answer the occasional “is this still your address?” check so it stays active.
You can permanently delete your account from Account → Security. It's confirmed with a code we e-mail you (plus your two-factor code if enabled), then enters a short grace period — a few days during which nothing is erased yet. Change your mind? Just sign in again before it ends and your account is kept, exactly as it was. If the window passes, we permanently delete your account and all your capsules — including already-delivered ones, so unopened recipient links stop working — and cancel your subscription; support can't restore any of it. Deletion completes across our backups within about 35 days, and Stripe keeps your past invoices and tax records as required by law. This is separate from cancelling a subscription, which leaves your account intact.
Capsulene is free to start. Paid packages are recurring subscriptions — monthly or yearly — that raise how many text and key capsules you can keep active at the same time, and set which optional features (custom check-in timing, SMS, login-required check-ins) your capsules can use. A one-time payment can also cover a single capsule. Payments are processed by Stripe, which acts as the merchant of record and adds any applicable tax at checkout; we never see or store your card details.
Yes. From your account you can cancel anytime, update your payment method, and view or download your invoices through Stripe's secure billing portal. If you cancel, your package stays active until the end of the period you've already paid for.
A failed payment never silently disarms a capsule. If a renewal fails — which can simply mean your card expired, or that something has happened to you — we don't just stop the timer: we start a check-in and ask you to confirm you're around, with your usual grace period and reminders. Confirm and the capsule unschedules (renew your package to re-arm it); don't respond and it's delivered exactly as intended. You control this per capsule in its advanced settings — separately for a failed payment and for a cancellation — with an option that only accepts a signed-in confirmation for the most sensitive capsules. Capsules on the free tier are unaffected either way.
Be responsible with what matters
Create a Capsule and define what should happen before anyone has to guess.
Your digital life is already modern. Your continuity should be too.
Practical writing on digital continuity, inheritance, and the cryptography that makes it safe.
Platforms memorialize or delete — they rarely grant access. What Google, Apple and Meta actually do, and the gap nobody covers.
Read the post → PlanningThe complete checklist — access, money, documents, people, letters — and why the paper version fails when it’s needed.
Read the post → CryptographyAny two shares unlock it; one alone reveals nothing. The math behind zero-knowledge inheritance, in plain language.
Read the post →Long-form guides on the problems Capsulene exists to solve — worth reading even if you never create a Capsule.
The mechanism behind Capsulene: check-ins, triggers, and why release-on-silence beats handing secrets over up front.
Read the guide → CryptoSelf-custody has no recovery department. Why wills and seed-sharing fail for crypto, and how to pass on Bitcoin and keys safely.
Read the guide → FoundersIf you were unreachable tomorrow, could anyone keep the company running? Access, instructions, and a plan that actually works.
Read the guide → FamiliesHow your family gets into what matters — accounts, documents, last instructions — when you can no longer hand it over yourself.
Read the guide → MessagesMessages that outlive the moment: letters, memories, and words that reach the right people at the right time.
Read the guide → AdvisorsFor estate planners, lawyers, and wealth managers: wills transfer ownership, not access — add continuity to every plan.
Read the guide →