Privacy and Local Storage
MDash stores vault content in the current browser. It has no account system and no note-sync server.
Table of Contents
Privacy at a Glance
[!NOTE] Your vault stays in the current browser unless you deliberately import, export, or share content. Remote images and URL imports contact their source. Analytics excludes note content and shared documents. A share URL contains the document source, so treat the complete link as sensitive. Keep independent backups of important work.
Where Data Lives
| Data | Storage |
|---|---|
| Vault files, folders, and Trash | IndexedDB for the current browser profile and site origin |
| Tabs, expanded folders, Favorites, and Recent files | localStorage |
| Theme, accent, fonts, editor preferences, and panel preferences | localStorage |
| Render caches | Memory for the current session |
| Offline application assets | Browser cache managed by the service worker |
MDash does not keep filesystem handles in localStorage. Installing the Progressive Web App does not move or synchronize the vault. The installed app continues to use storage associated with its browser and site origin.
When the Network Is Used
The core application can work offline after its assets have been cached. Network access may still occur in these situations:
- Opening the site or downloading an application update
- Downloading optional KaTeX, Mermaid, or syntax-highlighting assets that are not cached yet
- Importing a URL or repository selected by the user
- Displaying a remote image referenced by a document
- Sending privacy-respecting analytics from pages other than shared documents
Fetched files become independent vault copies. MDash does not maintain a live connection to the original URL, folder, or repository.
Interface fonts, icons, core application assets, and KaTeX export fonts are self-hosted. Exported HTML embeds the math fonts and rendered diagrams it needs instead of requesting them from a CDN. A remote image remains remote unless you replace its URL yourself.
Analytics
MDash uses self-hosted Umami analytics on regular site pages. Shared-document pages do not load the tracker.
Analytics can record:
- Page paths, page titles, and referrers
- Anonymous visit and session counts
- Browser, operating-system, device, language, screen, and country-level context
- Explicitly named feature events with enum or count values
- Performance measurements enabled by the tracker configuration
Analytics uses no cookies and respects the browser's Do Not Track setting. MDash excludes URL query strings and fragments from analytics so share payloads and other URL parameters are not recorded. Umami may use request information such as an IP address to derive anonymous session and location data, but its documented configuration does not store the address itself.
MDash never sends note text, filenames, vault structure, search text, or shared document content as analytics data.
Share by URL
Share by URL compresses the active document source and places it inside the link. The document is not uploaded to a note-storage service, but the URL itself contains the document.
- Anyone with the complete URL can read its contents.
- The compressed source is limited to approximately 12 KB.
- The recipient receives a read-only view and can copy the source into a vault.
- The maintained MDash server configuration disables access logging for the share route.
Treat a share URL like the document itself. Browsers, browser history, chat services, email systems, CDNs, proxies, screenshots, and recipients can retain or forward it. Do not use Share by URL for secrets or material that requires access control.
Protect Local Storage
Settings shows the approximate encoded size of vault data separately from the browser's total storage estimate for MDash. That estimate can include vault data, preferences, and cached application assets, and available capacity can change with device conditions.
Protect Local Storage asks a supporting browser to reduce the risk of automatic storage eviction. The browser can decline the request, and protection does not guard against manual site-data clearing, profile deletion, device loss, or storage failure.
Keep important backups outside the browser. Import, Export, and Backup explains ZIP copies, full backups, reminders, validation, and restoration.
Delete or Reset Local Data
Moving an editable item to Trash is recoverable. Permanent deletion and Empty Trash are not. A full MDash backup includes Trash, while a ZIP export does not.
Open Settings, choose Reset, and select Reset Vault to remove user-created vault content, Trash, Favorites, Recent files, and open tabs. MDash then restores the bundled README and guides.
If the application cannot open far enough to use Reset Vault, browser developer tools can remove the MDash IndexedDB database and related localStorage entries. That fallback permanently removes local content. Export a current backup first whenever possible.
What MDash Does Not Do
- Require an account or login
- Synchronize a vault between browsers or devices
- Upload note content for storage
- Use analytics cookies
- Track visitors across unrelated sites
- Provide access control for shared URLs