Estimated reading time : 3 min · Published October 5, 2026
Explain where data stays
localStorage retains data for an origin across sessions; sessionStorage belongs to a page session in a tab. An origin distinguishes protocol, host and port. Data stored on an HTTP version does not automatically appear on its HTTPS version.
The word ‘local’ does not guarantee encryption or isolation from scripts on the same origin. Describe the exact data retained and avoid storing secrets. On shared devices, provide a clearing action and explain its scope.
Plan for unavailable or lost storage
Browser settings, quotas, deliberate clearing and some private contexts can prevent retention or remove a copy. Rules vary by browser and API. A theoretical quota does not guarantee storage on a visitor’s device.
Handle read and write failures. If persistence fails, preserve active input where possible and clearly report that work remains usable in this page but persistent retention is unconfirmed. Do not announce ‘saved’ before an actual successful write.
Provide a documented export
For an important log or configuration, offer an export containing format, version, date and stable item identifiers. Recovery should not depend on the current visual order of rows. Avoid automatically collecting device details or unrelated information.
Requesting a download does not prove that the visitor kept the file. Phrase feedback accordingly and explain how to retain it. An export is not a secure sharing space: the person distributing it remains responsible for its contents.
Validate the whole import before applying it
Check size, format, version, types, expected fields, lengths, known identifiers and duplicates. Prepare the result in memory, then replace visible data after every check succeeds. A rejection must not leave half an imported log.
Display notes as text without interpreting HTML. Try an empty file, truncated JSON, an older format and strings containing special characters. When site changes alter an observation’s meaning, request a fresh review rather than automatically trusting a previous ‘passed’ result.
Test clearing and recovery
Check what each action clears: active input, one tool’s stored key or an entire account. Clearing one tool should not unnecessarily remove all site preferences. Previously downloaded exports remain independent copies.
This site’s budget and acceptance tools can be used without an account. The acceptance log exports to resume a review; directory selections retain browsing preferences when storage is available. Check each tool’s behaviour instead of assuming they all retain the same data.
Reference documents
Content updated on October 5, 2026
