This is mentioned in that blog post, but data is separated by a tuple of: (scheme e.g. HTTP or HTTPS, domain, port). Any page from one such set cannot access cookies, local storage, indexeddb, or cache from a page with a different set. The new feature simply adds one more attribute, so even if pages share scheme, domain, and port, they will not be able to read data from a site with a different userContextId.