The Storage Manager API reveals an origin's storage budget
Modern websites save more than a few preferences. An offline map may cache tiles. A document editor may keep drafts in IndexedDB. A media app may store files for the next journey. Before adding another large object, the site needs to know whether the browser has room for it.
The Storage Manager API gives a web origin an estimate of what it already uses and the quota the browser may allow. It can also ask for persistent storage, which receives stronger protection from automatic eviction. These features make web apps more reliable, but the browser deliberately avoids turning them into a precise disk-space probe.
What navigator.storage provides
A supporting browser exposes navigator.storage as a StorageManager object. The MDN StorageManager reference lists four central methods: estimate(), persist(), persisted(), and getDirectory().
estimate() returns approximate usage and quota numbers for the current origin. Usage is the space attributed to that site. Quota is a conservative estimate of the maximum the browser is prepared to let the origin hold. The difference helps an application decide whether it can cache another file or should clean up first.
persisted() reports whether the origin's storage already has persistent protection. persist() asks the browser to grant that status. getDirectory() opens the origin private file system, an isolated area that a site can use without receiving a handle to an ordinary folder on the user's computer.
Storage belongs to an origin, not the whole web
The web's basic storage boundary is the origin: scheme, host, and port. Data for one origin is kept separate from data for another. The Storage Manager API therefore does not return a list of files or databases belonging to other websites.
This boundary also matters when a site is embedded inside another site. Browsers increasingly partition third-party storage by the top-level context to prevent a single embedded service from carrying one identifier everywhere. Our guide to why browsers partition website storage explains the logic.
The estimate may cover data managed through IndexedDB, the Cache API, and other browser storage systems. It is not a general inventory of the user's drive. A site cannot call the method and learn the names of personal documents, the contents of another application's folder, or every byte stored by the browser.
Why the numbers are intentionally rough
The WHATWG Storage Standard calls usage an implementation-defined rough estimate. Compression, deduplication, and shared resources make exact accounting difficult. The standard also says quota must not be a direct function of the device's available storage space.
That last rule is a privacy protection. A highly precise free-space value could contribute to fingerprinting or reveal changes outside the site's own storage. Combined with memory, screen, language, graphics, and network signals, an unusual disk profile could help distinguish one device from another.
This is the same cumulative problem discussed in how websites fingerprint browsers without cookies. One coarse value is rarely decisive. Many stable values together can become a recognizable pattern.
Best effort and persistent storage
Most site data begins as best-effort storage. The browser tries to keep it, but it may evict the data when space is tight. Eviction policy varies. Browsers can consider factors such as how recently or frequently the site was used.
Persistent storage receives stronger protection. The standard says a persistent bucket cannot be cleared by the browser's ordinary storage-pressure process without involvement from the origin or the user. That matters for work a person created locally or resources they explicitly need offline.
Persistence is not an unlimited reservation. The browser remains in charge of quota and permission. Some browsers may grant the request based on engagement signals; others may prompt or decline. A responsible app explains why it needs durable local data before asking, then remains functional if the request is denied.
What privacy-conscious applications should do
Local storage can reduce data sent to servers, but “local” does not mean “temporary” or “invisible.” A large cache remains on the device until the browser, site, or user removes it. Sensitive drafts require the same care as server-side data: minimize collection, encrypt where appropriate, and provide a clear delete control.
Applications should also separate essential offline material from disposable performance caches. A Quran reader might preserve the text and a chosen translation while allowing artwork thumbnails to be recreated. A document tool should prioritize unsynchronized edits over assets that can be downloaded again.
Clearing browser data can remove an origin's storage as a unit. Persistent status may require more explicit user involvement, depending on the browser and clearing action. See what clearing browser data actually removes before treating a cache as permanent.
A practical checklist for users
- Review site data in browser settings when storage use grows unexpectedly.
- Keep irreplaceable work backed up outside a single web app's local storage.
- Grant persistent storage only to sites you trust and genuinely use offline.
- Remember that private windows usually use a temporary, separate storage session.
- Remove data for abandoned web apps instead of assuming the browser has already done it.
Private browsing is useful for separation, not permanence. Temporary site storage normally disappears when the private session closes, while network observers and websites can still see activity during the session. Our article on private browsing data sets out those limits.
Good storage design makes deletion ordinary
The Storage Manager API solves a practical reliability problem. Web apps need enough information to avoid failed downloads and lost offline work. They do not need a precise window into the user's entire disk.
Approximate quotas, origin separation, browser-controlled persistence, and clear deletion paths keep that balance intact. The best application stores only what earns its place, explains durable storage plainly, and behaves well when the answer is no.
Browse with more intention
Noorani brings prayer times, Qibla, tracker blocking, and privacy into one calm desktop browser built for how Muslims live online.
