▸ the local standard
Your data, your machine.
CosmoDev keeps your profile - favorites, settings, history - entirely in this browser. Nothing personal ever reaches our servers. You can export an encrypted backup and import it on any machine. This is the spec for how it works, in plain language.
no accounts · no server-side personal data · portable · open
The idea
Most sites store your data on their servers and hand you a login. The Local Standard inverts that: your profile lives in your browser's local storage, under your control. We deliver static pages; the only thing that runs on our edge is an anonymous tool-use counter. There is no server-side database of who you are or what you like - because we never receive it.
What's stored, and where
One key in your browser's localStorage, named cosmodev:profile. It holds:
- Identity - an optional display name and an avatar color. No email, no password, no identifier.
- Favorites - the tools you've starred (★).
- Preferences - theme, code font, syntax color scheme, reduced-motion.
- Stats & recents - optional, per-tool local counts and recent values.
Inspect it yourself: open your browser devtools → Application → Local Storage → this site. It's a plain JSON object. You can read it, edit it, or delete it.
What we actually collect
One thing only: an anonymous, running count of how many times each tool is used(the “12 uses” number under the reactions). That count is global - it is not tied to you, your profile, your browser, or any identifier. We cannot and do not link it back to anyone.
- ✓ No accounts, no logins, no emails.
- ✓ No cross-site tracking, no analytics fingerprinting.
- ✓ Your favorites, name, and settings never leave your device.
Portability
From your account menu → Data, you can Export a single.json file containing your whole profile, and Import it on any other browser or machine. On import you choose:
- Merge favorites - adds the backup's stars to your current ones.
- Replace all - overwrites your current profile with the backup (confirmed).
Security - honestly
Two layers, and it's worth being precise about what each protects:
- The export file. Every export carries a SHA-256 checksum(tamper/corruption detection, always on). Add a passphrase and the contents are encrypted withAES-GCM-256, keyed by PBKDF2-SHA256 at 600,000 iterationsfrom your passphrase. This protects a backup at rest - e.g. a laptop theft or a cloud-sync folder. The key never leaves your head; carry the passphrase to the new machine to restore.
- The live profile. By default, your profile in
localStorageisplaintext by design. That's the point: it's yours, on your machine, inspectable and editable. If you share the device, Settings offers opt-in at-rest encryption: it guards the stored profile against other users of this device and local malware — but a forgotten passphrase cannot be recovered, and no in-browser lock protects against someone who controls the device while it's unlocked. Treat your browser profile like you treat any local file - lock your device.
Delete it
Account menu → Data → Clear profile, or your browser's “clear site data.” Either way it's gone for good - there's no server copy to delete because there was never a server copy.
Want this for your own project?
The Local Standard is a pattern, not a walled garden - a composition of browser storage, a checksummed/encrypted envelope, and a tiny reactive store. We're extracting it as an openCosmoKit recipe.
← Back to the tools