Omnia Federal LLC operates this service. It reads public procurement notices and helps a company decide which are worth pursuing. This page says what it stores about you, who else can see it, and how long it is kept.
Public notices. Solicitations and events from SAM.gov, Virginia eVA, SBA, the VA VetBiz portal, Grants.gov, SBA SUB-Net and USAspending. This is published government data and is not about you.
What you write here. Your company profile, tasks, agenda points, pipeline entries, meeting notes, the dates you set, the items you hide and any reason you give for hiding them, and the questions you ask about a card along with the answers. This is yours. It is stored in a directory belonging to your account and nothing outside that directory reads it.
Mail and calendar, only if you connect them. Where an account
connects Microsoft 365, the token is granted
Mail.Read and Calendars.Read and nothing else, so
the service physically cannot send, delete, label or move anything. Most
accounts connect neither.
Forwarded notifications, only if you forward them. Where you set up a forwarding rule for vendor-portal digests, those messages are stored as received, in your own directory.
One line per request: the time, your account name, the network address the request arrived from, the path, the response status, and the identifier of the row you acted on. No content is logged -- not the text of a question, a task, an answer or a note -- and query strings are discarded rather than filtered, so nothing can leak through a parameter added later. The row identifier is kept because support is impossible without knowing which row misbehaved.
This log records your use of the product, including how often you sign in. If that is not acceptable to you, do not use the service.
One cookie, and it is the session. Signing in sets
omnia_session, a signed token holding your account name and an
expiry. It is Secure, HttpOnly and
SameSite=Strict, and signing out clears it.
That is the entire list. There are no analytics, advertising or tracking cookies, no third-party scripts, and no pixels — which is why you are not being asked to consent to anything. A cookie strictly necessary to deliver a service the user asked for does not require consent, and a banner asking for it anyway would be theatre.
The board stores two small values in your browser's own
sessionStorage — which column you expanded and where you had
scrolled — so an action that reloads the page does not lose your place.
That never leaves your browser.
That is the whole list. Nothing is sold, nothing is shared with advertisers, and there is no analytics or tracking code on any page.
Each company has its own directory holding its own configuration, data and knowledge. One process serves them, and a request is resolved to a directory by the signed-in account, never by anything in the URL. This is tested on every deployment rather than asserted: the check reads both directories and fails if state either has authored appears in the other.
Your working data is kept until you delete it. Backups are retained 60 days, and a deleted or overwritten backup stays recoverable for 30 days after that. So deletion is not instant: if you ask us to remove your data, it leaves the live service immediately and ages out of backups within 60 days. Raw collector output and the activity log are kept on a rolling window.
Passwords are stored as scrypt hashes with a per-account
salt; the plaintext is never written down and cannot be recovered from the
file. Sessions are signed tokens, checked before the name inside is read.
Cookies are Secure, HttpOnly and
SameSite=Strict. All traffic is over TLS. Failed sign-ins are
rate limited per account and per address.
Two honest limits. There is no multi-factor authentication. And backups live in the same cloud project as the server, so they protect against disk loss and accidental deletion, not against that project being compromised.
Ask and you will get a copy of everything stored for your account, or have the account and its directory deleted. Removing an account takes effect on the next request -- an open session stops working immediately.
contact@omniafederal.com
This service is operated from the United States. It is a business tool and is not intended for personal data beyond the working contact details you choose to put in it.