Before you start
Create the Recovery Key only when you are ready to store it outside Capitelist. The 16 words unlock protected private data such as Held Away details, Safebox notes and Legacy-sensitive instructions. Capitelist cannot show the words again after setup, so this step matters before you add critical private records.
Detailed steps
Open Settings > Keys and check current status
Go to Settings and open Keys. If the Recovery Key says Not created yet, protected data cannot be recovered through this account until you complete setup. If it already says Created, do not create another key; check the checksum and trusted-device section instead.
Start from the Security prompt when protected data is blocked
You may also see the Security prompt when you try to include Held Away or open another protected area. Use Create Recovery Key from that prompt when you need private data to become recoverable. Cancel if you are not ready to store the words properly.
Read what one Recovery Key unlocks
Before generating the words, read the list of protected areas. The same key can unlock Held Away locations, Legacy instructions, final messages, Safebox notes, sensitive documents and future encrypted recovery data. Continue only if you are comfortable with that scope.
Generate the key and copy the 16 words offline
When the words appear, copy them exactly as shown and keep them in order. Do not translate, pluralize, reorder or clean them up. Use a physical copy, a secure offline vault or another storage method that remains available if this device or account is unavailable.
Confirm the 16 words before saving
Type the words into the confirmation box in the same order. Save only when the app confirms all 16 words match. If the match fails, stop and compare the copy before saving. A wrong copy can make protected data impossible to recover later.
Save the key and keep the checksum with your copy
After saving, Capitelist shows created status and a checksum instead of showing the words again. Write the checksum next to your offline copy so you can later confirm you are looking at the right Recovery Key without exposing the full words.
Return to Settings > Keys after setup
Open Settings > Keys again and confirm the Recovery Key says Created. Review the checksum, creation date and Trusted devices section. Trusted devices or passkeys are useful for daily unlocks, but they do not replace the offline Recovery Key.
Unlock protected data only when you need it
Use the Security unlock prompt when you need Held Away, Safebox or Legacy-sensitive data visible in the current session. If you create a passkey, use it only on a trusted device. Hide or lock private data again before screen sharing, exporting or leaving the device unattended.
Field guide
The 16-word offline fallback for protected private data.
Keep the words exact, ordered and outside Capitelist.A short identifier that helps confirm you have the right key without exposing the full words.
Store it with the written copy and compare it in Settings > Keys.The verification box that proves your copy matches before saving.
Do not save until the app confirms all 16 words match.Export options offered during setup so you can store the key outside the browser.
Use the option that fits your storage policy and protect the exported file immediately.Devices or passkeys that can unlock protected data after Recovery Key setup.
Remove devices that are lost, sold, shared or no longer trusted.The modal that makes protected data visible in the current session.
Unlock only when you need the data and hide it again afterward.Decision rules
What it adds
- Provides the controlled recovery path for encrypted private data.
- Reduces the risk that trusted people know records exist but cannot access the instructions.
- Keeps Capitelist from needing to hold readable private secrets.
What it does not do
- Capitelist cannot regenerate a lost Recovery Key for encrypted content.
- A screenshot of the key stored in the same compromised account is not safe storage.
- Support should never ask you to reveal the full Recovery Key.
Common mistakes
What to check
- Store the key offline or in a separate trusted vault.
- Never give the full key to a person who should not access private records.
- Update the recovery plan when trusted people or storage locations change.
- Do not put the key inside Safebox if Safebox depends on that key.
Taking an ordinary screenshot of the 16 words and leaving it in Photos, Downloads or a shared folder.
Sending the Recovery Key through email, chat, support tickets or an advisor message.
Saving the key inside Safebox or another protected area that depends on the same key.
Changing the words, translating them, adding punctuation that changes meaning or reordering them.
Treating a passkey as a replacement for the offline Recovery Key.
Creating the key while screen sharing or while another person can view your screen.
Assuming Capitelist support can recover the words later.
After you save
- Check Settings > Keys and confirm the Recovery Key status is Created.
- Store the checksum with the offline copy so you can identify the key later.
- Decide whether to create a passkey on this device for daily unlocks.
- Test the Security unlock once before adding important Held Away, Safebox or Legacy-sensitive records.
- Hide protected data when you finish reviewing it.
- Update your personal recovery instructions when storage location or trusted people change.
