You pasted an API key into the extension and want to know precisely where it lives and who can reach it.
Bring your own key means what it says. On the free and Sync plans your API key is stored in chrome.storage.local on your machine. It is deliberately not stored in chrome.storage.sync, which would replicate the credential into your Google account.
Nothing to configure: the storage choice is made for you, on purpose. If you ever want a key gone, remove or rotate it at the provider and re-add the replacement in Omni; keys are validated on save, so a revoked or mistyped key is caught the next time you save it.