Save data in the browser, safely
Safe local-storage layer
For when the answer to “It remembers things after a refresh” is yes.
Kills the 'localStorage is not a database' footgun: versioned schema with forward-only migrations, quota and parse-corruption handling that reports instead of losing data silently, and an export/import backup path.
Built by hand again in 14 of 20 audited projects before this existed. Each rebuild was another chance to make the mistake below.
Skip the rebuild
You do not write this one. It arrives in your project as ordinary source you can read, change and keep, with its audit record and its caveats beside it.
- Download the Playground. It is free and runs on your own machine.
- Start a new app and tick “It remembers things after a refresh”.
- This block is written in, along with anything else you ticked.
The mistake it removes
Rebuilt in ~14/20 projects and repeatedly flagged by DD. The Coaching App FAILED its audit on exactly this: no export, silent failure modes.
What the audit found
Named rather than summarized. The reasoning behind each one ships inside the block, so it travels with the code instead of living on a page you have to trust.
- export() assumes a browser DOM; no-ops meaningfully only where document exists minor · Data durability
- A corrupt-payload copy is kept per failure and never pruned minor · Stress & robustness under extremes
What you still have to do
A copied file cannot own your secrets, your host or your legal obligations. This is the part the block deliberately does not claim.
- A backup your user can actually restore from — a server-side copy, or a prompt that makes them use the export path on a schedule. localStorage is cleared with site data and by storage pressure; versioned migrations keep a save READABLE, they do not keep it alive.
What lands in your project
vanilla
- vanilla/store.js
Plain ES module. No build step, no dependencies.
react
- react/useStore.js
- vanilla/store.js
The hook plus the vanilla core it wraps — both land side by side so `./store.js` resolves.
What you supply
- key — app:save
- version — 1
Licensed MIT. It is a starting point, not a finished product.
Get it
Download the Playground See the other blocks
Nothing here is locked. The files are yours, in your folder, under a permissive license.
Questions
- Is Save data in the browser, safely audited?
- Yes. A full due-diligence audit was run on 2026-07-17 and the verdict was a pass.
- What do I still have to do myself?
- A backup your user can actually restore from — a server-side copy, or a prompt that makes them use the export path on a schedule. localStorage is cleared with site data and by storage pressure; versioned migrations keep a save READABLE, they do not keep it alive.
- How do I get this code?
- Download the Playground, start a new app, and tick “It remembers things after a refresh”. The block is written into your project as ordinary source you can read and edit.
All pre-built code blocks · Learn to build from zero · The coding guide