Your grant strategy, application drafts, and organizational data are sensitive. Omnavar treats them that way.
Everything. By default, no data leaves your computer. There is no account creation, no cloud storage, no server to sync with, and no analytics. The application works entirely offline for all core features.
All stored data is encrypted with AES-256-GCM:
A random 256-bit key encrypts your data. On the Windows desktop app it is held in your operating system's secure credential storage (Windows Credential Manager, or the Secret Service keyring on Linux), not in a plain file. In the browser version, where there is no operating-system keystore, that key is never written in the clear: it is wrapped with a key derived from a passphrase you set (PBKDF2 with AES-256-GCM) and unwrapped into memory only after you enter that passphrase, so your browser storage holds ciphertext, not a usable key. Either way the key never leaves your machine.
When you search for grants, your search terms are sent to federal data sources such as Grants.gov, some through a Veydrin relay that adds no key of yours and keeps no logs. Only your search terms are sent. No organizational data is included in the request.
Off by default. If you opt in and list your organization, only the details you choose (name, focus areas, state, city, and a contact you provide) are published to a public directory so other nonprofits can find you. The listing is signed with a key generated on your device, and you can delist it at any time. You do not have to list to search the directory.
If you configure a writing provider (Claude, ChatGPT, or Gemini), draft requests are sent to that provider's API with your organization profile and grant details for context. If you enable vault access in Settings, document content may also be included. You control which provider receives this data. Omnavar does not proxy, cache, or log any of this traffic.
When a grant is awarded, you can optionally contribute an anonymous record to a public aggregate. Only the rounded amount and funder type are submitted, signed by a local anonymous key that identifies no one. No organization name, EIN, grant name, or funder name is ever sent. The record is Ed25519-signed and committed to a public git repository, and the dialog explains exactly what will be submitted before you send it. Separately, you can register as a supporter and rate the app; both are anonymous, optional, and send nothing but your rating and a single count.
Omnavar is open source under AGPL-3.0. The full source code is at codeberg.org/veydrin/omnavar. Read every line, build it yourself, and confirm that it does exactly what this page says.