Wan Family OS
Wan Family OS

Wan Family OS Privacy Policy

Last updated: Aug 24, 2026

Scope Wan Family OS (web, iOS app and macOS app) is operated by Wan Family Office Limited as an internal collaboration platform for invited members only; public sign-up is not available. This policy explains how we collect, use and protect your personal data.

Data We Collect Account information: name, email, sign-in credentials; Collaboration data: accounts, transactions, ledger entries, budgets and other business content entered or imported by members; Receipt photos: images captured or uploaded as bookkeeping evidence; Security logs: audit records of sign-ins and sensitive operations.

Network proxy client (WFVPN) The organization provides WFVPN, an internal network client that connects members' devices to the organization's own network nodes. We do not record which sites you visit through it — connection destinations stay on your own device, where you can read them in the app, and are never uploaded to any server. What is sent to the organization's server is limited to: connection status events (connect requested, connected, failure reason); latency measurements to the organization's own nodes; traffic totals (bytes and connection counts, with no destinations); device name, device model and OS version, and app version; and the name of a trusted Wi-Fi network that triggers auto-pause (a list the administrator configures in the first place). Personal routing rules you set are stored on the organization's server. This data is used only to operate and troubleshoot the network, is read by the organization's administrator, and is never used for advertising, profiling or cross-app tracking. Proxy traffic is carried by the organization's own servers; we do not sell or provide any of this data to any third party. Operational logs are deleted automatically after 90 days by default, and an administrator can shorten that window. On macOS: the system names the current Wi-Fi network only to an app that holds location permission, so the macOS app asks for it once on first launch. That permission is used solely to ask the system for a network name — the app does not read, record or upload any location. Pausing on a trusted Wi-Fi is carried out by the system against the administrator's list of networks and does not depend on it.

Content filtering (optional, iOS only) WFVPN offers optional content filtering, which filters content and tracking requests according to rule sets the organization maintains centrally. It is off by default and you turn it on yourself. Turning it on requires installing and trusting a root certificate. That certificate is generated locally by your device; its private key is held only in this device's keychain, is never uploaded and never leaves the device — the organization cannot sign anything with it. The certificate carries a name constraint, so it is usable only for hosts on the rule list. While filtering is on, only hosts named by the rules are decrypted on your device and processed against them; every other connection is left untouched. Decrypted content is handled in memory only — never written to disk, never uploaded, and visible to no one, including the organization's administrators. What reaches the organization's servers about filtering is limited to: whether it is enabled, how many entries the list holds, the certificate's trust state and fingerprint, and counts of how often rules matched. It never includes which addresses you visited, or the content of any request or response. The rules themselves are delivered by the organization's server; the client only reads them and never reports back what matched. You can turn the feature off in the app at any time, and remove the certificate under Settings → General → VPN & Device Management; filtering stops the moment it is removed. The macOS app does not provide content filtering: it installs no certificate and decrypts nothing.

How We Use Data To provide family-office collaboration features; to extract structured data from receipts and statements (processed by contractually bound AI providers, never used for model training); and to keep accounts and data secure.

Storage & Security Data is stored on servers and enterprise cloud drives owned by Wan Family Office Limited; all transport is TLS-encrypted; access is governed by role- and scope-based permissions; audit logs are immutable.

Data Sharing We do not sell personal data, serve ads, or perform cross-app tracking. Data is transferred only to contractually bound processors (such as document-recognition and email-delivery services) when necessary to provide functionality.

Data Retention Business data is retained per internal policy; you may request deletion of personal data after account deactivation; audit logs are retained as required for security compliance.

Your Rights You may access, correct, or request deletion of your personal data by contacting privacy@wan.family.

Children This platform is not directed at anyone under 16.

Changes Updates to this policy are published on this page; material changes are additionally announced to members.

Contact The data controller is Wan Family Office Limited. For any privacy question, contact privacy@wan.family.