Wai B2B · Privacy Policy

Last updated: September 11, 2026 · Applies to Wai B2B 1.1 and later

Wai B2B is an invitation-only corporate VPN client operated by WaiWai, LLC. Your organization arranges access under a separate agreement and controls the servers assigned to you.

Account and administration

WAI stores your employee name, organization, activation credentials, access permissions, activation status and app settings to provide access. Organization administrators can view and manage their own employees. Administrator accounts additionally use an email address and a securely hashed password. We record who changes administrative settings and the result.

VPN traffic

The app uses the operating system's VPN permission. Traffic selected for the VPN travels through an encrypted tunnel to an assigned exit server. Traffic covered by bypass settings connects directly. Encryption beyond the exit server depends on the destination service, such as HTTPS.

VPN servers process IP addresses and destination addresses to route connections. We do not intentionally record browsing content, browsing history or DNS query histories in diagnostic uploads. The service is not an anonymity guarantee: your organization controls access and destinations receive the exit server's IP address.

Diagnostics and your choice

Before the first VPN connection in this version, the app explains diagnostic processing and asks for agreement. Diagnostic uploads start after agreement. You can leave the disclosure screen without enabling the VPN.

The app first sends WAI filtered technical events: app version, platform, connection method, network type, timing measurements and error categories. Diagnostic bodies exclude account and device identifiers, activation tokens, VPN configurations, arbitrary log messages and traffic contents. Access tokens authenticate requests to WAI separately from the diagnostic body.

WAI forwards filtered error categories to Sentry for error monitoring. The app does not connect directly to Sentry. The server removes request URLs, headers, account information, local variables and arbitrary exception messages before forwarding errors. No advertising SDKs are included.

On your device

Your activation and preferences remain on the device so access survives updates. Technical logs can remain in the app's local diagnostic storage. If you explicitly export or share a diagnostic file, review it before sending it: local files can contain more detail than automatic uploads.

The camera is used only when you choose to scan an activation QR code. Camera images are not stored or uploaded by Wai B2B.

Storage and retention

WAI operates the account and diagnostic servers and uses Kamatera for VPN infrastructure. Internet requests to the panel use HTTPS with certificate validation. Administrator password and invitation storage are protected with hashing; administrator sessions expire.

Automatic diagnostic files on WAI servers are removed after 30 days. Account data is kept while access is provided. Administrative records may be retained as required for the organization's agreement, security and applicable obligations. Old app versions can have different diagnostic behavior; update to Wai B2B.

Access and deletion requests

Ask your organization administrator to disable your access. To request a copy, correction or deletion of personal data, contact privacy@waiwai.llc and identify your organization. Do not email your access token or password. We verify the request and explain any records that must be retained.

Changes and contact

We update this policy when processing changes. Contact WaiWai, LLC at privacy@waiwai.llc with privacy questions.