goaldrift
Back

Local-first software, explained for people who just want their data

3 March 2026 By goaldrift 5 min read

A small brass key lying on a plain wooden table.

Most software you use keeps your work on somebody else's computer. You type, it goes to a server, and what you see is a view of something held elsewhere.

That arrangement is so normal it's invisible, and it has consequences people only notice when something goes wrong — the service is down, the company is sold, the free tier changes, the export button produces a format nothing else reads.

Local-first is the other arrangement. The copy on your machine is the real one.

What it actually means

Three properties, and the first is the definition.

Your data lives on your device by default. Not cached there, not synced there — that is where it is. If the internet goes, or the company does, the thing you made is still on your computer and still opens.

Nothing needs to be sent anywhere for the software to work. Syncing, if it exists, is something you opt into rather than the mechanism the app runs on.

And you can get it out in a form that's still useful. Not a proprietary archive that only reimports into the same product, but a file you could read, or move somewhere else, or keep.

That's it. It's a straightforward idea with a slightly technical name.

Worth saying what it isn't. It isn't a claim that servers are bad, or that everything should work this way. It also isn't the same as end-to-end encryption, which is about the server holding your data in a form it can't read — a good property, and a different one. Local-first is about where the authoritative copy lives, which determines what you're left with when things change.

What it protects you from

Not hackers, mostly. Four more ordinary things.

The service disappearing. Small tools shut down constantly, and when a cloud-based one does, whatever you kept in it goes with it — sometimes with thirty days' notice, sometimes less. Local-first software that stops being maintained leaves you with a file that still opens.

The terms changing. A free tier becomes paid, a limit appears, a feature moves behind a subscription. If your data is on their servers, your leverage in that conversation is zero. If it's on your machine, the worst case is that you stop getting updates.

Being offline. Trains, planes, bad signal, a flaky connection in a rented flat. Software that needs a server has a bad day; software that doesn't, doesn't notice.

And the quiet accumulation of your record somewhere else. This one matters more for some things than others. A goal list with notes about what you're avoiding and why is a fairly personal document, and there's a reasonable position that it doesn't need to exist on anyone else's hardware.

What it costs you

The honest section, because local-first is usually written about by enthusiasts.

Sync is genuinely hard, and local-first apps do it worse. If two devices both change something while offline, somebody has to decide which wins, and there's no server holding the authoritative answer. Cloud apps solved this by having one true copy. Local-first apps either add complexity or accept limitations, and most accept limitations.

You become responsible for backups. A file on your laptop is exactly as safe as your laptop. Services that hold your data also protect it from your own hardware, and that's a real service that people undervalue until a drive fails.

Collaboration is harder. Multiple people editing the same thing in real time is what centralised architecture is good at, and if that's what you need, local-first is the wrong choice rather than a brave one.

And the convenience is worse in small ways. Log in on a new machine and there's nothing there. Browser data can be cleared by the browser. It's not free.

That last one deserves emphasis, since it's the failure people actually meet. Browser storage is not permanent storage — clearing site data, some privacy settings, and certain cleanup tools will remove it, quietly and without asking. Any local-first app that lives in a browser needs an export you actually use, and treating that export as optional is how people lose things.

Where the balance falls

Which is why this isn't a universal argument. It depends on the shape of the thing.

Collaborative work with many people, live, across devices — centralised, and that's fine. Documents shared with a team, project tools, anything where the point is other people.

Personal records that mostly sit still — local-first fits well. A journal, a goal list, notes to yourself. One person, one set of eyes, low collaboration, high sensitivity, and long-lived: you want to be able to read this in ten years, which is longer than most companies last.

The question worth asking of any tool: if this company vanished on Friday, what would I still have? For some tools the answer doesn't matter much. For the ones holding a record of your own life, it does.

There's a second question that's nearly as useful: could I move this somewhere else without retyping it? A tool that answers yes to both is one you can commit to without much risk. A tool that answers no to both is one you're renting your own records from.

Where the goals live

goaldrift keeps your goals in your browser. That's the real copy, and nothing is sent anywhere for the app to work.

There's no sync yet. When it arrives it will be the trade made explicit rather than assumed: a choice you make when you want your goals on a second device, rather than the price of entry.

Either way you can save everything to a file and load it elsewhere. That file never contains your API key.

The AI feature runs on your own key, held in your browser, which is why it costs nothing to run and why the quantity of your notes held on anyone else's hardware is zero. Not encrypted, not anonymised — absent.

The bit that isn't about privacy

There's a version of this argument that's entirely about surveillance, and it undersells the practical case.

The more mundane reason to care is duration. A record of what you've been avoiding, and why, and when you came back to it, is worth most when it's ten years long. That's a length of time over which products get acquired, pivot, shut down, or simply stop being what they were.

Something on your own machine, in a format you can export, has a fair chance of surviving that. Something on a server has whatever chance the company has.

For most software it isn't worth thinking about. For the thing holding the record of what you've been trying to do with your life, it seems worth a moment.

None of which requires anyone to care about the architecture. The reasonable version of this position is entirely practical: keep the important records in a form you hold, in a format you can read, and worry less about who's running what.


Related: What we left out of goaldrift, and why · AI can't want it for you · Notes as evidence: reading your own record six months later

Share: