Save the replacement before replacing the original
Temporary files and backups make small local databases much more tolerant of crashes and interrupted writes.
Writing directly over the only copy of an index is wonderfully simple right up to the moment the device restarts halfway through. Then the new file is incomplete and the old one is already gone.
For small local stores, a safer sequence is: write a temporary file, verify it can be read, preserve the last good copy, then replace the primary file. On startup, try the primary, then the backup, then a clean empty state. It is not glamorous architecture, but neither is explaining why every saved item vanished.