# Apache Maka Data Storage and Control: How the Local-First AI Assistant Differs from Cloud-Hosted Solutions

> Discover how Apache Maka's local-first approach secures your data, unlike cloud AI assistants. Control your prompts and configurations entirely on your machine.

- Repository: [The Apache Software Foundation/maka](https://github.com/apache/maka)
- Tags: deep-dive
- Published: 2026-08-22

---

**Apache Maka operates as a local-first AI coding assistant where all session data, model prompts, and configuration remain exclusively on the user's machine under Electron's `userData` directory, never automatically syncing to cloud services, unlike cloud-hosted alternatives that transmit every interaction to remote servers for processing and storage.**

Apache Maka is an open-source AI coding assistant that prioritizes local data sovereignty over convenient cloud synchronization. Unlike mainstream cloud-hosted coding assistants such as GitHub Copilot or Amazon CodeWhisperer, which stream prompts and generated code to external servers, Apache Maka maintains complete data residency on the local filesystem. This architectural choice fundamentally changes how developers must think about data control, privacy boundaries, and security guarantees when using AI pair programming tools.

## Data Residency and the Local-First Architecture

Apache Maka stores all workspace data exclusively under Electron's `userData` directory, specifically at `<userData>/workspaces/default/` according to the directory layout documented in the README【`README.md#L106-L118`】. This location contains the **runtime state**, **configuration files**, and **credential storage** required for operation.

The main process explicitly sets this path before any store initialization occurs. In [`apps/desktop/src/main/main.ts`](https://github.com/apache/maka/blob/main/apps/desktop/src/main/main.ts), the application configures the Electron `userData` path at lines 44-51, ensuring the workspace location is established prior to database connections or file operations【`main.ts#L44-L51`】.

Unlike cloud-hosted solutions that retain prompts for service improvement and analytics, Apache Maka provides **no built-in cloud synchronization**. Users must manually copy the workspace folder to move or back up data, placing full control of data mobility in the user's hands rather than a third-party service.

## Privacy Controls and the Incognito Mode

Apache Maka implements a **Workspace Privacy Context** that governs whether privacy-sensitive tools may access the network. The `incognitoActive` boolean flag in this context enforces a fail-closed policy: when enabled, tools such as WebSearch cannot execute external requests【`workspace-privacy-context.md#L22-L27`】.

The authority for this privacy state resides exclusively in the **main process**, not the renderer. While the UI can request state changes via IPC calls, the main process validates and maintains the authoritative `incognitoActive` value【`workspace-privacy-context.md#L30-L38`】. This prevents compromised renderer processes from overriding privacy protections.

When `incognitoActive` is true, the system halts execution before any network request occurs, ensuring zero data leakage to external services unless explicitly permitted【`workspace-privacy-context.md#L44-L46`】.

## Security Boundaries and Credential Management

The security model relies on the **OS user account** as the sole load-bearing boundary. All secrets—including API keys and OAuth tokens—reside in [`credential-vault.json`](https://github.com/apache/maka/blob/main/credential-vault.json) with `0o600` file permissions, restricting read access exclusively to the owning operating system account【`SECURITY.md#L106-L110`】.

Cleartext tokens never cross the IPC boundary between the main and renderer processes. The main process masks sensitive credentials before sending data to the renderer, ensuring that even if the renderer process is compromised, cryptographic secrets remain inaccessible【`SECURITY.md#L162-L169`】.

This differs fundamentally from cloud-hosted assistants, which typically store credentials in cloud-managed vaults and often transmit tokens to remote services as part of normal operation.

## Local Persistence Format and Database Structure

Apache Maka persists execution state using **SQLite** and **JSON files** rather than proprietary cloud databases. The workspace contains:

- **`runtime.sqlite`**: The primary database storing events, tool results, and session history
- **[`credential-vault.json`](https://github.com/apache/maka/blob/main/credential-vault.json)**: Encrypted storage for API keys and tokens
- **[`settings.json`](https://github.com/apache/maka/blob/main/settings.json)**: User configuration and preferences

The `packages/storage` module provides helpers for interacting with the local SQLite database. Developers can query the runtime database directly using standard SQL:

```typescript
import { openDatabase } from '@maka/storage/sqlite';

const db = openDatabase('runtime.sqlite');
const results = await db.run(
  'SELECT * FROM events WHERE type = ?', 
  ['tool']
);

```

This transparency allows users to inspect, modify, or extract their data using standard database tools rather than proprietary interfaces.

## Control Flow and Authority Architecture

The **main process** maintains absolute authority over privacy and security state. While renderer processes can request configuration changes—such as enabling incognito mode—they cannot directly modify the authoritative state.

For example, enabling incognito mode from the UI requires an IPC invocation handled by the main process:

```tsx
import { ipcRenderer } from 'electron';

function enableIncognito() {
  ipcRenderer.invoke('settings:update', { incognitoActive: true });
}

<button onClick={enableIncognito}>Turn on Incognito</button>

```

The main process validates this request before updating the `WorkspacePrivacyContext`, ensuring that privacy-sensitive settings cannot be manipulated by compromised frontend code【`workspace-privacy-context.md#L36-L38`】.

This architecture inverts the control model of cloud-hosted assistants, where the remote service dictates policy and the client merely forwards requests without local enforcement capability.

## Summary

- **Local-First Storage**: All data lives under Electron's `userData` directory in SQLite and JSON format, with no automatic cloud synchronization【`README.md#L106-L118`】.
- **Privacy-By-Default**: The `incognitoActive` flag provides fail-closed protection, preventing network calls from privacy-sensitive tools when enabled【`workspace-privacy-context.md#L22-L27`】.
- **OS-Level Security**: Credentials reside in [`credential-vault.json`](https://github.com/apache/maka/blob/main/credential-vault.json) with restrictive `0o600` permissions, readable only by the OS user account【`SECURITY.md#L106-L110`】.
- **Main Process Authority**: Privacy state and credential access are controlled exclusively by the main process, with the renderer restricted to request-only interactions【`workspace-privacy-context.md#L30-L38`】.
- **Transparent Data Format**: SQLite and JSON storage enables direct user inspection and backup without requiring proprietary export tools.

## Frequently Asked Questions

### Does Apache Maka store any data in the cloud?

No. Apache Maka maintains a strict local-first architecture where all session data, prompts, and generated code remain exclusively on the user's machine under the Electron `userData` directory. There is no automatic synchronization to cloud services; users must manually copy the workspace folder if they wish to transfer data between machines【`README.md#L106-L118`】.

### How does Apache Maka protect API keys and sensitive credentials?

API keys and OAuth tokens are stored locally in [`credential-vault.json`](https://github.com/apache/maka/blob/main/credential-vault.json) with file permissions set to `0o600`, ensuring only the current operating system user can read the file【`SECURITY.md#L106-L110`】. Additionally, the renderer process never receives cleartext tokens; the main process masks sensitive data before sending information across the IPC boundary【`SECURITY.md#L162-L169`】.

### Can I use Apache Maka completely offline?

Yes. Apache Maka functions without internet connectivity provided local AI models are configured. The `incognitoActive` flag in the Workspace Privacy Context specifically controls whether tools requiring network access (such as WebSearch) may execute, allowing users to guarantee offline operation by enabling this privacy mode【`workspace-privacy-context.md#L22-L27`】.

### What is the process for backing up or migrating Apache Maka workspaces?

Users must manually copy the workspace folder located at `<userData>/workspaces/default/` to create backups or migrate to new machines. This folder contains the `runtime.sqlite` database, [`credential-vault.json`](https://github.com/apache/maka/blob/main/credential-vault.json), and [`settings.json`](https://github.com/apache/maka/blob/main/settings.json) files. Unlike cloud-hosted assistants that provide automatic cross-device synchronization, Apache Maka requires explicit user action for data portability【`README.md#L106-L118`】.