Skip to main content

Morning Overview

Free VPN apps sometimes sell the very traffic they promise to hide

Downloading a free app that promises to encrypt internet traffic and hide browsing activity from an internet provider sounds like a straightforward privacy upgrade, and millions of people install one every year for exactly that reason. Building and running that kind of service costs real money, though, and a number of free options cover those costs by collecting and monetizing the very data users installed the app to protect. The apps that behave this way rarely advertise it, which leaves the burden of figuring out what is actually happening on the person least equipped to check.

What a VPN Is Supposed to Hide

A virtual private network routes a device’s internet traffic through an encrypted tunnel to a server operated by the VPN provider, which then forwards the traffic on to its destination. Done properly, this hides browsing activity from a local internet provider or a public Wi-Fi network, and it can make a connection appear to originate from a different location. That protection shifts trust rather than eliminating it, though, since the VPN provider itself can see everything that was previously visible to the internet provider, which is exactly why the identity and business model of that provider matters as much as the encryption technology it uses.

Free Apps Still Need a Business Model

Running servers, maintaining encryption and supporting an app across multiple platforms all cost money on an ongoing basis, and a free VPN has to cover those costs somehow. Some legitimate providers use a free tier to promote a paid subscription with more features or higher speeds, which is a straightforward and disclosed arrangement. Others fund the service by building advertising into the app itself, or by treating user data as a product to be sold rather than protected, an approach that can be difficult to distinguish from the first type just by reading an app-store listing.

Selling Bandwidth and Browsing Data to Third Parties

Independent research into free VPN apps has repeatedly found examples of exactly that second model, including apps that logged browsing history and sold it to advertisers, and apps that quietly resold spare bandwidth so that other customers’ traffic could be routed through a free user’s own internet connection. In the bandwidth-reselling arrangement, a free VPN user effectively becomes an exit point for someone else’s browsing activity without realizing it, since their own internet connection is being rented out as part of the service’s infrastructure. That arrangement can carry consequences beyond privacy: if the traffic routed through a resold connection is later tied to abuse or illegal activity, it is the original device’s internet connection and IP address that investigators or an internet provider would initially see. Because the entire point of a VPN is to move sensitive traffic through the provider’s infrastructure, a VPN app with a weak privacy policy has a more complete view of a person’s online activity than almost any other kind of app installed on the same phone, including which sites were visited, when, and from what location.

Warning Signs in an App’s Permissions and Privacy Policy

An app that asks for access unrelated to routing internet traffic, such as contacts, precise location or text messages, is worth a second look before installation, since none of those permissions are necessary for a VPN to function. The privacy policy is the other place the business model tends to show up, particularly language describing data sharing with “partners” or “affiliates” for advertising or analytics purposes, language that is often technically disclosed but easy to skip past during setup. A provider unwilling to name its own corporate ownership, or one based in a jurisdiction with no meaningful data-privacy enforcement, adds another layer of risk that no amount of encryption strength can offset. Several popular free VPN apps have also turned out to be owned by the same small handful of parent companies operating under different brand names, a structure that can make it harder for a user comparing apps in a store listing to realize they are actually evaluating the same underlying service and privacy practices twice.

What the FTC Recommends Before Installing One

The Federal Trade Commission has urged consumers to research a VPN provider before installing its app, checking what data it collects, whether it uses strong encryption, and whether its privacy policy discloses any sharing of data with third parties. The agency’s core recommendation is that a VPN’s privacy claims should be verified rather than assumed, since the entire value of the product depends on a provider that a user has no direct way to audit actually doing what its marketing promises. A provider that publishes independent security audits of its own infrastructure, rather than simply asserting a “no-logs” policy in its marketing copy, gives outside researchers a way to check that claim instead of asking users to take it on faith.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview