Security

The same stack a privacy VPN runs.

WireGuard tunnels, servers in the EU, keys in the Apple Keychain, no logs kept.

WireGuard on every device

Less code than OpenVPN, so less to go wrong. Proton, Mullvad and Cloudflare all run it.

Nothing written to disk

We store no connection logs, no browsing data and no DNS queries. Our resolvers hold queries in memory and never write them out.

Keys never leave you

Private keys are generated on your device and live in the Apple Keychain. We never see them and could not recover them if asked.

EU servers for the EU

Frankfurt and Amsterdam are our GDPR-jurisdiction exits. London, New York, Sydney and Bangalore exist for content access — pick your exit in the app.

Sandboxed extension

The macOS app runs NetworkExtension under App Sandbox, notarized, distributed through the Mac App Store.

Paid for by subscriptions

Buy once, use on iPhone, iPad and Mac. Subscriptions are our only revenue. There is no ad SDK in the apps.

Locations

Six WireGuard servers, picked for jurisdiction.

🇩🇪
Frankfurt
Germany
DE — GDPR, no mandatory retention
🇳🇱
Amsterdam
Netherlands
NL — EU sovereign, no mandatory retention
🇬🇧
London
United Kingdom
UK — outside the EU since 2020
🇺🇸
New York
United States
US — content access
🇮🇳
Bangalore
India
IN — general purpose (Free tier)
🇦🇺
Sydney
Australia
AU — content access
Transparency

What we log

We store your device's VPN key, how many devices are on the plan, and per-category blocked counts. We don't store browsing history, DNS queries or IP addresses. Category counts tell you a filter fired; they do not tell us, or you, which site it fired on.

Peer config

Public key + IP assignment, for the tunnel to work.

Aggregate counters

How many trackers/ads/threats blocked per device — used in the dashboard.

Browsing history

No URL logs. No DNS query logs tied to identity.

Personal traffic content

Encrypted end to end. We couldn't read it if we tried.

Responsible disclosure

Found a security problem? Tell us.

Tell us before you tell anyone else. If you think you've found a vulnerability in the apps, the API or our infrastructure, report it and we'll work it through with you.

Where to send it
security@familyshield-vpn.com, or the machine-readable security.txt.
What to expect
An acknowledgement within 72 hours and an initial assessment within 7 days.
Our commitment
We will not pursue legal action over good-faith research that respects user privacy, avoids service disruption, and gives us reasonable time to fix the issue before it is made public.
Please avoid
Accessing or modifying other people's data, degrading the service for real families, social engineering, or physical attacks against our staff or hosts.
Support period
Family Shield receives security updates for a minimum of five years from the release of each version, in line with the EU Cyber Resilience Act.

Built for trust. Run by Gosenville.

Want to dig deeper? Read our privacy policy.