1019
Avast fined $16.5 million for ‘privacy’ software that actually sold users’ browsing data
(www.theverge.com)
This is a most excellent place for technology news and articles.
The great thing about open source is that anyone can read the code. Even if you don't read every line yourself there are others who will. In popular projects it's pretty much a guarantee any suspicious or malicious changes get caught almost immediately due to the visibility of everything.
As for local-only I trust Bitwarden and their encryption schemes enough that I use their cloud sync, but you can always self host it in a Docker container with no Internet access if you're concerned about it.