← All writing

Local-first changes who you have to trust

The whole thingWhen the real copy is on your disk, nobody has to promise anything.

Local-first is usually sold on speed and offline access. Both are real. Both are the least interesting part.

The real shift is who you are forced to trust. Normally your data sits on someone else's machine and your protection is a policy. Policies hold until an acquisition, a subpoena, a breach, or a quiet terms update. You are protected by intent, and intent expires.

Local-first puts the real copy on your device. Sync happens after, instead of being required. Now the privacy claim is not a promise, it is a fact about where the bytes are. Nobody can leak what they never received.

That is what I am chasing with Echo. An AI assistant is the worst case for the normal setup, because being useful means seeing exactly what you would least like to hand over. The fix is not a better promise. It is making sure the sensitive parts never leave.

The honest cost: you give up what centralisation is good at. Multi-device sync becomes a real problem. Conflicts are yours to handle. Server-side analytics mostly disappear, so you learn much less about how people use your product.

Take that trade on purpose, not because local-first sounds good. For a notes app it is arguable. For credentials, health records, or private messages, it is obvious.

One test. If your privacy page vanished tomorrow, would your users be any more exposed? If yes, you are selling a promise.

Next issueBuilding in public compoundsStrangers correct a public mistake. A private one repeats.