What stays on your machine

Everything. By default, no data leaves your computer. There is no account creation, no cloud storage, no server to sync with, and no analytics. The application works entirely offline for all core features.

Encryption

All stored data is encrypted with AES-256-GCM:

A random 256-bit key encrypts your data. On the Windows desktop app it is held in your operating system's secure credential storage (Windows Credential Manager, or the Secret Service keyring on Linux), not in a plain file. In the browser version, where there is no operating-system keystore, that key is never written in the clear: it is wrapped with a key derived from a passphrase you set (PBKDF2 with AES-256-GCM) and unwrapped into memory only after you enter that passphrase, so your browser storage holds ciphertext, not a usable key. Either way the key never leaves your machine.

What can leave your machine (only if you choose)

Grant search

When you search for grants, your search terms are sent to federal data sources such as Grants.gov, some through a Veydrin relay that adds no key of yours and keeps no logs. Only your search terms are sent. No organizational data is included in the request.

Partner directory (optional)

Off by default. If you opt in and list your organization, only the details you choose (name, focus areas, state, city, and a contact you provide) are published to a public directory so other nonprofits can find you. The listing is signed with a key generated on your device, and you can delist it at any time. You do not have to list to search the directory.

Writing assistance

If you configure a writing provider (Claude, ChatGPT, or Gemini), draft requests are sent to that provider's API with your organization profile and grant details for context. If you enable vault access in Settings, document content may also be included. You control which provider receives this data. Omnavar does not proxy, cache, or log any of this traffic.

Community impact and ratings (optional)

When a grant is awarded, you can optionally contribute an anonymous record to a public aggregate. Only the rounded amount and funder type are submitted, signed by a local anonymous key that identifies no one. No organization name, EIN, grant name, or funder name is ever sent. The record is Ed25519-signed and committed to a public git repository, and the dialog explains exactly what will be submitted before you send it. Separately, you can register as a supporter and rate the app; both are anonymous, optional, and send nothing but your rating and a single count.

What Omnavar does not do

Verify it yourself

Omnavar is open source under AGPL-3.0. The full source code is at codeberg.org/veydrin/omnavar. Read every line, build it yourself, and confirm that it does exactly what this page says.