One account can hold several projects, and signing in gets you into the account, not into a particular project.
An email address can only be registered once, and with one method. You cannot end up with a Google account and a password account on the same address.
Passwords, encryption, and what signing out clears
Closing the browser or quitting the installed app keeps you signed in. Clicking Sign out signs you out and clears the encryption keys held in that browser — clearing the site's cookies or storage does the same thing. Nothing is lost either way: the encrypted copy on the server re-syncs when you sign back in.
- By default, the password you log in with is also the one your project's encryption key is derived from. Resetting it through Forgot your password? re-encrypts those projects to the new password — but only for projects that were already open on the device you run the reset from. Run it where you last used the project.
- If you set a separate Project Password, resetting your login password does not recover it, and there is no server-side reset — nobody at Capitally can decrypt the project for you. While you are still signed in somewhere, you can change it in Settings → Encryption.
- Keep me signed in on the login form, and Remember on this device when unlocking a project, store the derived key in that browser so you don't retype it. That is convenient, and it also means anyone with access to your browser profile can open your portfolio.
The three encryption modes and the trade-offs between them are covered in Is my data safe? and in What happens if I forget my password?.
Keep an export
End-to-end encryption means a lost password is a lost project — there is no copy we can read on your behalf. A periodic full export from Settings → Export turns that from a loss into an inconvenience. See Exporting Data.
Two-factor authentication
Capitally has no built-in second factor today. Two things close most of the gap: sign in with Google, and the account inherits whatever two-factor method you have on your Google account; and set a Project Password, so getting into the account is not the same as being able to read the data.
Those two pull in opposite directions. A Google account has no Capitally password to derive a key from, so new projects on it default to the server-side With Remote Key encryption mode — convenient, because you cannot lock yourself out, but the key is fetched from our side rather than derived only on your device. Choosing With a Project Password instead puts key derivation back on your device and keeps the second factor.
Changing your account email
There is no self-service email change. Support changes the address for you, and your project, history and subscription stay attached to the same account: no new sign-up, no re-import.
Email support@mycapitally.com with three things:
- Your current account email address.
- The new address you want to use.
- A separate confirmation email sent from the new address, so the team can see you control it.
The same process applies if you sign in with Google and want to move to a different Google account.
The community forum still shows my old email
The community forum authenticates with your Capitally account, so it picks up the new address on your next sign-in. Log out of the forum and log back in — it will read the updated email automatically. There is no separate email setting inside the forum to change.
Deleting your account
Account deletion is Delete my account, in the Danger zone at the bottom of Settings → Your Profile. It is permanent: the account and every project on it are removed, with nothing to restore from. Export anything you want to keep first — because your data is end-to-end encrypted, Capitally holds no readable copy of it on any server.
- Cancel an active subscription first. With a paid subscription still running, the app blocks deletion and asks you to cancel before you try again. To delete before the paid period expires, write to support@mycapitally.com.
- Export first. A full JSON backup from Settings → Export, or any table to CSV or Excel. See Exporting Data.
- You don't need to delete the account to stop paying. The 14-day trial takes no card and does not auto-bill — it simply ends, and the account goes inactive. Details in Subscription and billing.
- Leaving without deleting keeps the door open. Encrypted data is retained for at least 6 months after a trial or subscription ends, so coming back restores the full history with nothing to rebuild.
- "I want to start over" is a different action. Delete the project, not the account — the account, subscription and login stay intact and you begin with a clean project. See Projects.