Excalidraw, for example, does an amazing job keeping your information locally without needing to log in. However, saving data to their cloud requires log in. There is another option: generate a shareable link, which does not require a log in. I wonder how they defend against DDoS attacks or spam when it's so easy for a non-authenticated user to generate a shareable link (which involves securing a couple megabytes of data and creating an endpoint). How do you prevent bad actors from consuming the resources of a central server without a log in? Honestly curious, not trying to start a flame war :)