Wouldn't users be able to tamper with their own data? Seems like another attack vector.
Even with a server side DB, they could lie about their results or hack the game to do better.
If that were a part of the conventions, or even if it isn't, services could sign their own versions of data in legal states – as with signed/encrypted cookies. Then out-of-agreement edits could be detected, and possibly rejected as errors, rather than causing other surprises. (This could make for some ugly partial-failure/unexpected-state cases, though.)