The app keeps two kinds of local state: tokens in the platform's secure storage, and everything else in shared preferences. Nothing here is synchronized between devices. When you replace a tablet, this list is what has to be redone.
Secure storage
| Key | Holds |
|---|---|
access_token | The current user token |
refresh_token | Used to renew the access token |
Keychain on iOS, Keystore-backed on Android. Cleared on sign-out.
Shared preferences
| Key | Set by | Meaning |
|---|---|---|
user_data | Sign-in | The signed-in user record |
orgId | Sign-in | The organization of the current session |
remembered_org | Sign-in screen | The organization id shown locked on the sign-in screen |
saved_sessions | Sign-in | One-tap accounts: org, email, name, avatar, tokens, last used, expired flag |
userEmail, userPhone | Sign-in | Contact details used by the softphone and inbox |
location_selected_id | Location picker | The business location every operations screen is scoped to |
home_hidden_groups, home_hidden_items | More → Home apps & groups | Tiles and groups hidden on the home screen |
printer_default_address, printer_default_name, printer_default_kind, printer_default_paper_mm | More → Printer | The paired receipt printer and its paper width |
stripe_terminal_reader_serial, stripe_terminal_location_id, stripe_terminal_connection_kind | More → Payments | The paired card reader and its Terminal location |
scanner_ble_device_id | More → Scanner | A paired Bluetooth barcode scanner |
scanner_camera_enabled | More → Scanner | Whether the camera is offered as a scanner |
scanner_hid_capture_enabled | More → Scanner | Whether keyboard-wedge scanners are captured app-wide |
nfc_reader_ble_device_id | More → NFC reader | A paired Bluetooth NFC reader |
| Softphone device id | Softphone | A stable id the device registers with for calls |
| Softphone offline flag | Phone screen | "Go offline" for calls, persisted across restarts |
What survives sign-out
Two keys, and only two: remembered_org and saved_sessions. They are snapshotted before the preference store is cleared and written back afterwards, so a shared device still shows its organization and its one-tap accounts.
Everything else in the table above is wiped, including the things that describe the device rather than the person:
| Lost on sign-out | Consequence |
|---|---|
printer_default_* | The receipt printer is unpaired — printing fails until it is paired again |
stripe_terminal_* | The card reader is unpaired, and its Terminal location forgotten |
scanner_*, nfc_reader_ble_device_id | Scanner and NFC reader pairings and toggles are gone |
location_selected_id | The device no longer has a location; operations screens ask for one |
home_hidden_* | Every hidden tile comes back |
| Softphone offline flag | The device returns to receiving calls |
On a till, a host stand or a door scanner, signing out costs you every pairing and the home layout. That is what quick sign-in is for: staff change, the device does not. Reserve sign-out for handing the hardware to a different organization — and expect to set it up from scratch afterwards.
Deleting the app, or clearing its data, removes all of it including the two survivors.
Per device versus per organization
| Setting | Lives |
|---|---|
| Paired printer, card reader, scanner, NFC reader | Device |
| Selected location | Device |
| Home layout | Device |
| Saved sessions and remembered org | Device |
| Softphone offline state | Device |
| Employee passcodes | Organization (server) |
| Access cards | Organization (server) |
| Quick sign-in mode | Organization (server) |
| Menus, day-parts, 86 list | Organization, per location (server) |
| Receipt templates, workflows, gateways | Organization (server) |
The practical consequence for a rollout: a new tablet needs its hardware paired, a location selected and, if you customized it, the home layout; it inherits everything else the moment someone signs in. The same list is what you redo after anyone signs out on that device.
What the app does not store
There is no local cache of business data and no queue of offline actions. Lists are fetched when a screen opens and on pull-to-refresh; without a connection, screens show an error with a retry rather than stale data. The hive package is declared in the project but unused.