Morning Overview

Free VPN apps can harvest the very data they promise to hide

A virtual private network is marketed as a shield: it routes a device’s internet traffic through an encrypted tunnel so that outsiders cannot see where the user goes online. That promise is exactly why free VPN apps are downloaded by the millions. But an app that carries all of a phone’s traffic sits in a position of extraordinary trust, and research into the free end of the market has repeatedly found that many of these apps abuse it, collecting and monetizing the same browsing activity they claim to conceal.

The concern is not hypothetical or limited to a few bad actors. Because a VPN by design carries every byte of a device’s internet traffic, the app holds a uniquely privileged view of its user, and that position is only as safe as the company behind it. Academic researchers who examined the free end of the market found that a striking share of these apps behaved in ways that directly contradicted their marketing, turning a tool sold as protection into a mechanism for surveillance. The gap between the promise and the practice is the heart of the problem.

What a VPN can see once traffic flows through it

By design, a VPN intercepts every packet a device sends and receives. That architecture is what makes the technology useful, because it lets the service encrypt traffic against eavesdroppers on a shared network, and the general mechanics are laid out in reference material on the virtual private network. The same architecture, however, hands the provider a complete view of the user’s online life: the sites visited, the times of day, the apps in use, and in weaker configurations the contents of unencrypted connections. A VPN provider is therefore in a stronger position to surveil a user than the internet provider the user was trying to hide from. Whether that power is used to protect or to profit depends entirely on the operator, and the free tier is where the incentives tilt toward profit.

The academic audit of hundreds of free apps

The most cited investigation of this problem came from a team of researchers at the University of California, Berkeley’s International Computer Science Institute working with the Australian national science agency CSIRO. The group analyzed 283 Android apps that used the system’s VPN permission, drawn from a corpus of more than 1.4 million apps, and published its findings in a study on the privacy and security risks of VPN apps. The results contradicted the category’s core marketing claim. The researchers reported that roughly three-quarters of the apps embedded third-party tracking libraries, and that a large majority requested access to sensitive information such as user contacts and text messages, none of which a genuine privacy tool needs to function.

Tracking libraries and traffic leaks

The study documented failures that ran deeper than aggressive permission requests. It found that a substantial share of the apps leaked traffic outside the supposed tunnel, and that a smaller but meaningful fraction did not encrypt traffic at all, leaving users exposed while believing they were protected. More alarming, the analysis reported that some apps actively injected code into users’ web traffic for advertising and tracking purposes, and that a handful intercepted secure connections. Independent of the study, the presence of tracking libraries is telling on its own: those components exist to record behavior and report it to advertising networks, which is the opposite of the anonymity a VPN is sold to provide. A tool that promises to hide browsing while quietly cataloging it inverts its own purpose.

Why free is the business model, not a discount

Operating a VPN is expensive, because the provider must run servers, pay for bandwidth, and carry the traffic of every user. An app that charges nothing must recover those costs somewhere, and for many operators the answer is the data itself. Browsing histories, device identifiers, and location signals can be aggregated and sold to advertisers and data brokers, turning the user base into the product. This is the same logic that governs much of the free-app economy, but it is especially consequential for a VPN because the app sees everything rather than a slice. A paid, audited service has a direct revenue stream that does not depend on reselling user activity, which is why security researchers consistently warn that a free VPN with no clear funding model should be treated as a data-collection operation until proven otherwise.

How consumers can evaluate a VPN before trusting it

Consumers can reduce the risk by scrutinizing an app before it is granted control of their traffic. Practical checks include reading the privacy policy for language permitting the sale or sharing of data, reviewing the permissions the app requests and rejecting any that have nothing to do with networking, and favoring providers that submit to independent security audits and publish the results. The Federal Trade Commission, which enforces against deceptive privacy claims, maintains guidance on protecting personal data on mobile devices through its consumer protection resources. A provider’s country of incorporation, its ownership, and whether it keeps logs are all relevant, but the simplest filter remains the funding question: an app that carries every byte of a person’s internet activity and asks for nothing in return is being paid some other way.

The trust a tunnel demands

The paradox of the VPN is that it cannot deliver privacy without first demanding total access. A user who installs one is choosing to concentrate all of their online exposure in a single company and to trust that company completely. When that company is reputable and audited, the trade can be sound. When it is an unvetted free app financed by unknown means, the same concentration becomes a liability, because the one entity that can see everything has a commercial reason to look. The research on the free tier is a reminder that the label on a privacy tool is not the same as its behavior, and that the app promising to hide a user’s data may be the party harvesting it.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview