Security
Local-first by default
Keys and conversation history are stored on your device. Nothing is uploaded unless you turn on optional sync.
Direct to the provider
Requests go straight from your device to the provider's own API. Omnesly never sits in the middle as a proxy.
No training on your data
We don't use your prompts or responses to train any model. What you send is governed by that provider's own policy.
Encrypted at rest
API keys are stored using your OS's secure credential storage — Keychain, Credential Manager, or Secret Service — never as plain text.
No hidden steps in between.
- Your API keys
- Stored encrypted on-device using OS-level secure storage. Never transmitted to Omnesly's servers.
- Your conversations
- Stored locally by default. Optional cloud sync (Pro) is encrypted in transit and at rest, and only accessible from your own signed-in devices.
- What each provider sees
- Only the messages you send in that conversation — governed by that provider's own data and retention policy, not ours.
- Telemetry
- Basic, anonymous usage analytics — crashes and feature usage — that never include your prompts, responses, or API keys. Optional, and off with one toggle.
Security FAQ
No. Keys are stored encrypted on your device using your operating system's secure credential storage. Our servers never receive them.
Keys stored locally are only as safe as your device — we recommend full-disk encryption (FileVault, BitLocker) and a device passcode. If you've enabled sync, you can revoke a lost device's access from another signed-in device.
No. We don't operate a model ourselves, and we don't use your conversations to train anything.
By default, only you, on your own device. With optional cloud sync enabled, conversations are encrypted and accessible only from your own signed-in devices.
Questions we haven't answered?
Reach the team directly and we'll get back to you.
privacy@omnesly.com