Living Document Notice
Published 2026-09-16. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.
Digging Through Desktop App Caches
Summary
Extracting unencrypted LevelDB key-value pairs and local SQLite files left on disk by Electron desktop apps.
This technical dispatch explores the underlying architecture, data structures, and concrete implementation boundaries required for local-first data sovereignty.
The Client Cache as an Unguarded Local Replica
Modern desktop productivity applications are rarely native binaries. Most are packaged Chromium runtimes (Electron, CEF, or WebView2) that communicate with cloud servers via WebSocket streams and REST APIs. To ensure responsive UI rendering and offline usability, these applications sync full document representations to local disk.
While cloud servers restrict user access with rate limiters, captchas, and expiring session tokens, local storage directories contain unencrypted data tables accessible by the operating system user account.
Common Cache Paths Across Desktop OS:
Windows: %APPDATA%/<AppVendor>/Local Storage/leveldb/
macOS: ~/Library/Application Support/<AppVendor>/IndexedDB/
Linux: ~/.config/<AppVendor>/databases/
Inside these directories live standard storage backends: Google LevelDB (.ldb, .log), Chromium IndexedDB files, and SQLite databases. By reading these files directly from disk, an engineer can extract complete document histories, message archives, and graph links without firing a single HTTP network packet.
Parsing LevelDB Records and Snappy-Compressed Blocks
LevelDB stores data as sorted byte arrays organized into SSTables (Sorted String Tables) and write-ahead logs (WAL). Records are ordered lexicographically by key, with values compressed using Google’s Snappy compression algorithm.
A major challenge during live extraction is LevelDB file locking. When the official desktop client is open, it acquires an exclusive LOCK file on the directory:
# LevelDB Directory Structure
drwxr-xr-x current/
-rw-r--r-- 000124.ldb # Immutable SSTable containing compressed data
-rw-r--r-- 000125.log # Active write-ahead log
-rw-r--r-- CURRENT # Manifest pointer
-rw-r--r-- LOCK # Exclusive advisory lock
-rw-r--r-- LOG # Diagnostic operational log
-rw-r--r-- MANIFEST-000123 # Table metadata and compaction descriptorsTo extract records safely without causing application crashes, copy the cache folder to a staging directory before acquiring a read-only database handle.
The table below catalogs storage formats used by popular desktop application architectures:
| Application Architecture | Local Database Technology | Compression Method | Record Key Schema |
|---|---|---|---|
| Chromium IndexedDB | LevelDB (.ldb chunks) | Snappy frame compression | Prefixed object store IDs (_id@version) |
| Electron App State | SQLite (app.db, Cookies) | Uncompressed B-trees | Opaque string IDs, JSON payload column |
| Local Web Storage | LevelDB (Local Storage/) | Raw UTF-16LE / UTF-8 | Plaintext domain prefix + variable key |
| Legacy Workspaces | Embedded NeDB / JSONL | None (Newline text) | Sequential line records |
Extracting JSON Records with Python and Plyvel
The following Python extraction script demonstrates how to bypass directory locks, traverse SSTable records, decompress Snappy blocks, and filter records by entity prefix:
import os
import shutil
import json
import plyvel
SOURCE_DIR = os.path.expandvars(r"%APPDATA%/VendorApp/Local Storage/leveldb")
STAGE_DIR = r"c:/temp/cache_stage"
# Copy cache files to bypass active LOCK handles
if os.path.exists(STAGE_DIR):
shutil.rmtree(STAGE_DIR)
shutil.copytree(SOURCE_DIR, STAGE_DIR, ignore=shutil.ignore_patterns("LOCK"))
# Open LevelDB instance in read-only mode
db = plyvel.DB(STAGE_DIR, create_if_missing=False)
extracted_documents = []
try:
for key, value in db.iterator():
if key.startswith(b"doc_record:"):
clean_payload = value[1:] if value[0] == 1 else value
record = json.loads(clean_payload.decode("utf-8"))
extracted_documents.append(record)
finally:
db.close()
shutil.rmtree(STAGE_DIR)
assert len(extracted_documents) > 0, "No records recovered from local LevelDB SSTable"
print(f"Extraction verified: recovered {len(extracted_documents)} records.")- Directus Target: freemydata
- Garden Source Reference: DAT-1001 - The Export Illusion, OUT-1001 - Zero Dependency Sandboxing for Autonomous Coding Agents, MOC - Data Liberation Workbenches, MOC - The Plain-Text Longevity Standard, MOC - Bosun PKM Tools