Essays
Why local-first still matters.
Local-first software is usually defended on principle — ownership, independence, distrust of subscriptions. Those arguments are fine and slightly abstract. For a watch collection there is a much narrower one, and it is not philosophical at all.
A collection record is an itemized list of valuable, portable, easily resold objects, with photographs, serial numbers, values, and frequently enough context to work out where they are kept. That document has a second audience whether or not anyone intends it to. Every copy of it that exists somewhere you do not control is a copy somebody else's security failure can expose.
The risk is not that the company is careless
This is the part usually argued badly. The concern is not that a particular provider is negligent. Most are competent, and a well-run service will protect your data better than most people protect their own laptop.
The concern is that competence is not the only variable. Companies get acquired, change policies, pivot, and go out of business. Data gets migrated by people who never wrote the original terms. Breaches happen to careful organisations. None of that requires anyone to behave badly — it requires only time, which every collection has plenty of.
Against a threat that is mostly about duration, the useful question is not "how well is this protected?" but "how many places does it exist?" Local-first answers the second question in a way no amount of diligence answers the first.
Policy, or property
There is a real difference between software that chooses not to transmit and software that cannot. The first is a policy — honoured today, reviewable tomorrow, invisible to you either way. The second is a property of the build.
A setting can be changed in an update you accept without reading. A missing capability cannot be enabled by a policy change, a new owner, or a well-meaning feature request. That distinction is the entire argument, and it is why "offline mode" and "offline by design" are not the same claim.
The honest cost
Local-first is a trade, not a free win, and anyone selling it as costless is selling something.
Nobody else holds a key, so nobody else can give you one back. There is no password reset, no account recovery, no support route that ends with a human restoring your access. Lose both your passphrase and your recovery key and the record is unreadable permanently — by you, by us, by anyone. The same property that makes a stolen laptop survivable makes a forgotten passphrase final.
That trade is worth making for this particular document. It would be a poor trade for a shared shopping list.
Where the software fits — and where it does not
Watch Vault Archive takes the side of this trade rather than splitting the difference, which is why nothing described above has an escape hatch. The cost lands entirely on you: keeping a backup is your obligation, and nobody here can lift it. For what the software does today, see how your data is protected.
One thing worth doing today
Count the places a complete list of your watches currently exists. Include email, phone photo libraries, cloud drives, insurance portals and anything you have shared with a broker.
Most collectors get to four or five and stop counting. That number, not any provider's security posture, is the thing you can actually change.
More essays · How your data is protected · Documenting provenance