Lesson 14 / 25

Storing Data on the Device

AsyncStorage, SecureStore and SQLite.

Pick storage by sensitivity and shape

AsyncStorage (@react-native-async-storage/async-storage) is an asynchronous, unencrypted key-value store for small, non-sensitive data such as settings and cached preferences; values are strings, so you serialise JSON. expo-secure-store stores small secrets such as access and refresh tokens in the iOS Keychain and in Android storage encrypted with the Keystore; it has value size limits, so keep entries small. For structured or larger data that you query, use a database: expo-sqlite provides SQLite, and libraries such as Drizzle or WatermelonDB build on it. Faster synchronous key-value stores such as react-native-mmkv also exist. Never put tokens or personal secrets in AsyncStorage.

Settings in AsyncStorage, tokens in SecureStore

Two storage layers with different guarantees.

import AsyncStorage from "@react-native-async-storage/async-storage";
import * as SecureStore from "expo-secure-store";

// non-sensitive preferences
export async function saveSettings(settings: { theme: "light" | "dark" }) {
  await AsyncStorage.setItem("settings", JSON.stringify(settings));
}
export async function loadSettings() {
  const raw = await AsyncStorage.getItem("settings");
  return raw ? JSON.parse(raw) : { theme: "light" };
}

// secrets: Keychain on iOS, Keystore-backed storage on Android
export async function saveToken(token: string) {
  await SecureStore.setItemAsync("accessToken", token);
}
export async function getToken() {
  return SecureStore.getItemAsync("accessToken");   // null if missing
}
export async function signOut() {
  await SecureStore.deleteItemAsync("accessToken");
}

A notice board and a safe

AsyncStorage is a notice board in your room: handy, but anyone who gets in can read it. SecureStore is the safe for keys you cannot afford to lose.

Quick check: Where should an access token be stored?

  • In the app bundle at build time
  • In AsyncStorage as plain text
  • In a global JavaScript variable only
  • In secure storage such as expo-secure-store (Keychain/Keystore)
Answer

In secure storage such as expo-secure-store (Keychain/Keystore) — Secrets belong in OS-protected storage.