Shared memory capsule
Purchase & Preservation Policy
Last updated:
This policy describes Capsoul’s current product model. A product or lifecycle feature that is unavailable or rollout-gated is not guaranteed until enabled for your account and app release.
1. Scope
This policy applies to Shared Capsoul units, optional one-time purchases and memberships, Personal allowances, media limits, local recovery, refunds, and other preservation rules. Apple’s applicable App Store terms also govern purchases and subscriptions.
2. One unit for a Shared memory
Sealing and sending one new Shared Capsoul uses exactly one Shared Capsoul. That one unit covers one to five recipients and any valid scheduled opening up to five calendar years after trusted server time. The sender uses the unit. Recipients open for free.
Unused purchased or granted Shared Capsouls are not stored cash value and cannot be withdrawn, transferred, or exchanged for money. The server owns the authoritative quote, reservation, balance, and settlement record.
3. One-time purchases
Where offered, Consumable In-App Purchases grant fixed packs of 6, 30, or 100 Shared Capsouls after the exact StoreKit transaction is verified. These packs do not renew. A durably credited Consumable is not granted again through Restore Purchases, although Capsoul may recover and verify unfinished StoreKit transactions.
4. Membership
After each successful verified monthly payment, monthly membership grants 10 Shared Capsouls and allows 10 Personal Capsouls per UTC month while entitled.
Annual membership is paid for one year. It grants 10 Shared Capsouls immediately and 10 at each of the next 11 monthly anniversaries: 120 Shared Capsouls per paid year. While the verified annual entitlement is active, it also provides Unlimited monthly Personal Capsouls.
Unlimited monthly Personal does not mean unlimited storage, media, devices, or backup. Each Personal Capsoul still follows the limits below. A membership binds to the first Capsoul account on which the Apple subscription is successfully verified and cannot be transferred. Cancellation stops a later renewal, but does not remove Shared units already granted or scheduled anniversary grants owed within an already-paid annual period.
5. Free Personal allowance and local storage
A free account may create up to 3 Personal Capsouls per UTC month. A fixed monthly allowance resets at the start of the next UTC month, does not roll over, and is not restored by deleting a Personal Capsoul.
Each Personal Capsoul must open within 30 days and may contain at most 50,000,000 optimized media bytes (decimal 50 MB). Its text and media are encrypted on the device with AES-256-GCM in a local .capsoul document excluded from cloud backup. Capsoul provides no cloud library, synchronization, discovery, or backup for Personal payloads. Necessary allowance, integrity, reservation, entitlement, and wrapped-key metadata may still be processed by the service.
Losing or replacing a device, deleting the app, its data, or the document, losing account access, or losing required key material can make a Personal Capsoul permanently unrecoverable.
6. Shared media and historical compatibility
A newly created Shared Capsoul may contain at most 100,000,000 optimized media bytes (decimal 100 MB) across photos, videos, audio, files, and other attachments.
Eligible historical Shared documents created under the earlier limit may contain up to 500,000,000 bytes (decimal 500 MB). The new-creation limit does not prevent an eligible historical document from being read, opened, claimed, imported, saved locally, or exported.
7. Conditional welcome grant
An eligible trusted registration created at or after the owner-approved activation time may receive one welcome grant of exactly 5 Shared Capsouls. Accounts created before that time, accounts with ambiguous creation evidence, and accounts outside the enabled rollout are not automatically backfilled. The server records an eligible grant once to prevent duplication.
8. Settlement, withdrawal, and Apple management
A Shared unit may be reserved before upload and is committed after successful sealing. An incomplete reservation may be released under the service rules. Withdrawal never returns a committed Shared Capsoul. A local copy already delivered to another person’s device cannot be remotely revoked or deleted.
Apple manages localized prices, taxes, payment approval, subscription renewal and cancellation, subscription management, Restore Purchases eligibility, and refund decisions. After Apple reports a verified refund, Capsoul may remove available units attributable to that transaction or paid period and record any shortfall as a refund adjustment. A refund does not reverse an active reservation, withdraw an already committed Shared Capsoul, or remotely delete a delivered local document.
9. Rollout and availability
One-time products, membership, Personal local capsules, Shared local saving, cloud cleanup, welcome grants, and related lifecycle behavior may be introduced in stages. If a feature or product is unavailable, gated, or disabled, its behavior is not guaranteed until enabled for your account and app release. Displaying this policy does not itself activate a product, grant, or cleanup process.
10. Help
For purchase or preservation help, visit Support or email support@capsoul.chat. Do not send passwords, verification codes, sensitive receipts, JWS payloads, session tokens, private keys, or Apple credentials.