OrgNav does not collect, transmit, or store your data.
OrgNav runs entirely in your browser. It has no server, no account, and no analytics, and it never sends anything to OrgNav or any third party.
To do its job it reads two things from the Salesforce tab you have open: the page's URL (to work out which org and record you're on), and — using your own existing Salesforce login — the org data you ask it for. That includes metadata such as objects, fields, flows and Apex, and it also includes records: Easy Query runs the SOQL you write, Record Fields shows the fields of the record you're viewing, and Find can look up users. Some of that is inevitably personal information, such as a colleague's name, username or email address.
All of it is fetched with your own Salesforce permissions, displayed in the side panel, and then discarded. You never see anything Salesforce wouldn't already show you, and none of it is transmitted anywhere.
The only things OrgNav keeps are your own settings, saved in your browser's local storage on your machine: your saved orgs, quick-nav tiles, and bundles. You can clear them at any time by removing the extension.