A lot of modern software is a thin window onto someone else's server. Your notes, your documents and your history live in a data center, and the app on your device is a viewer. It works well until the connection drops, the company changes its pricing, or the service shuts down, taking your work with it.
Local-first software turns that around. Your data lives on your device, the app works fully without a connection, and anything that leaves the device, like a backup or a sync, is an addition you control. It's become our default way to build.
It's faster
When data is on the device, there's no round trip to a server before something appears. Search is instant, opening is instant, saving is instant. People rarely say "this app is local-first", but they do say "this app feels fast", and this is often why.
It's more private
Data that never reaches a server can't leak from one. There's no database to breach, no employee access to audit, and no pile of user content to protect for years. For personal apps, like journals, notes and chat archives, this is the single biggest privacy decision a team can make.
The safest server is the one you never had to run.
It lasts
An app that keeps its data locally keeps working even if the company behind it changes direction. People can export their data in open formats and take it elsewhere. We think software should be built to outlive its business model, and local-first makes that possible.
What it asks of us
Local-first isn't free. It moves responsibility onto the product's design:
- Backups become essential. If data lives in one place, losing that place is serious. We build backup and export in from the first version, and make the basic backup free.
- Encryption matters on the device too. Phones and laptops get lost. We use the platform's data protection and, for backups, strong encryption under a passphrase only the user knows.
- Data models need care. Without a server to fix things centrally, migrations between app versions must be tested thoroughly so no one's data is left behind.
- Honesty about trade-offs. If we can't recover lost data, we say so, clearly and early, and give people the tools to protect themselves.
When a server is the right answer
Local-first is a default, not a religion. Collaboration in real time, large shared datasets and some AI tasks genuinely need servers. When they do, we design the server part to hold as little as possible, for as short a time as possible, and we say exactly what goes there.
What we avoid is reaching for a server out of habit, for things the device in someone's pocket can now do perfectly well on its own.
The result
The apps that come out of this approach tend to be quick, calm and trustworthy. They work on a plane, they don't need an account, and their privacy policies are short. Those are qualities people notice, even if they never hear the term local-first.