Depplo Team | World News Desk
“Free” Has Always Meant Something Else
There is an old saying in the technology world, usually invoked around free apps and services: if you are not paying for the product, you are the product. Nowhere does that saying apply more directly than in the crowded, chaotic world of free VPN applications. Year after year, security researchers publish fresh findings on the app stores’ free VPN category, and year after year, the results paint a strikingly consistent picture — one that should give any privacy-conscious user real pause.
This week, Depplo’s research desk revisited the landscape of free VPN offerings across major mobile app stores, drawing on published academic research, independent security lab findings, and our own testing methodology, to understand exactly what’s changed and what hasn’t.
The Business Model Problem
Running a genuine VPN service is expensive. Server infrastructure, bandwidth costs, encryption overhead, staffing, legal compliance, and periodic security audits all add up to a real and substantial ongoing cost per user. A paid VPN service covers those costs through subscription revenue. A free VPN service, by definition, has to cover those same costs some other way — and that “some other way” is where the trouble consistently lives.
Historically, the most common alternative revenue models found among free VPN apps include:
- Selling or sharing user bandwidth, effectively turning a user’s free VPN connection into a node in a larger proxy network used by paying commercial customers, often for purposes the original free user never consented to or was even aware of.
- Embedding advertising SDKs that collect far more behavioral data than the VPN functionality itself would ever require, and that share this data with third-party advertising networks.
- Selling aggregated or “anonymized” browsing data to data brokers — a practice that repeated research has shown can often be de-anonymized when combined with other available datasets.
- Injecting affiliate links or ads directly into browsing sessions, a practice that not only undermines privacy but can introduce genuine security vulnerabilities by modifying page content in transit.
What Independent Testing Keeps Finding
Academic and independent security research into free VPN Android apps has, across multiple studies conducted in recent years, turned up a remarkably consistent set of problems: a meaningful percentage of tested apps contained embedded tracking libraries, a smaller but still significant percentage failed to properly encrypt traffic in at least some circumstances, and a subset requested permissions — such as access to contacts, precise location, or device identifiers — that have no plausible legitimate connection to VPN functionality at all.
Beyond permissions and tracking, researchers have also repeatedly identified more fundamental technical failures among free VPN offerings: DNS leaks that expose the websites a user visits even while “protected,” IPv6 leaks on networks where the app only accounts for IPv4 traffic, and weak or outdated encryption implementations that would fail a basic security audit. Perhaps most concerning, ownership investigations into some popular free VPN apps have revealed connections to holding companies registered in jurisdictions with minimal corporate transparency requirements, making it genuinely difficult for a user to know who is actually operating the service processing their traffic.
It’s Not Only About Malice — Sometimes It’s Just Incompetence
To be fair to the industry, not every problem with free VPN apps stems from deliberate bad faith. Building a properly engineered VPN client is a genuinely difficult software engineering task, and smaller teams operating on minimal budgets frequently ship apps with security flaws that come from inexperience or under-resourcing rather than intentional data harvesting. A poorly implemented kill switch, a DNS leak nobody caught in testing, or an outdated encryption library that never got patched are all common failure modes that have nothing to do with malicious intent and everything to do with the economics of building free software.
That distinction matters for how users should think about the risk, but it doesn’t really change the practical advice: whether a free VPN’s shortcomings come from greed or incompetence, the end result for the user’s privacy and security is largely the same.
Are There Exceptions?
Yes — and it’s important to say so clearly, because blanket condemnation of anything labeled “free” would be its own kind of oversimplification. A small number of reputable paid VPN providers offer genuinely limited free tiers as a form of lead generation, typically capping data usage, server selection, or speed rather than compromising on the underlying security architecture. These “freemium” offerings generally use the exact same encryption, no-logs infrastructure, and audit history as the provider’s paid product — the free tier is simply a smaller slice of the same trustworthy service, not a fundamentally different and less secure product. The difference between this model and the free-only VPN app category is significant, and Depplo’s testing consistently finds the freemium tiers of established paid providers to be far more trustworthy than dedicated “always free” VPN apps.
How to Evaluate Any VPN — Free or Paid
Depplo’s research desk recommends a consistent checklist regardless of price:
- Who owns this company, and where are they legally based? If you cannot find a clear answer within a few minutes of searching, treat that as a serious red flag.
- Has an independent third party audited the no-logs claim, and recently? A privacy policy is a promise; an audit is a verification.
- What permissions does the mobile app request, and do they make sense? A VPN app has no legitimate need for your contacts list or precise location history.
- How does the company make money? If a service is entirely free with no paid tier, no advertising, and no clearly disclosed business model, something else is funding it — and it’s usually your data.
- Run your own leak tests. DNS leak and IP leak testing tools are freely available and take only a few minutes to run against any VPN connection.
The Bigger Picture
The persistence of these findings, study after study, year after year, points to a structural issue rather than a series of isolated bad actors. As long as there is strong consumer demand for “free” privacy tools, and as long as app stores continue to make it easy for lightly-vetted developers to publish VPN apps with minimal scrutiny, this category will likely remain a minefield for users who don’t do their homework. Depplo’s ongoing message to readers is straightforward: treat “free VPN” search results with the same skepticism you’d apply to any other too-good-to-be-true offer, and remember that genuine privacy protection is a real, ongoing cost — one that has to be paid by someone, one way or another.
A Closer Look at the App Store Vetting Problem
Part of what allows the free VPN category to remain so problematic, year after year, is the relatively light-touch approach major app store platforms have historically taken toward vetting VPN apps specifically. Unlike categories such as banking or health apps, which frequently face additional review scrutiny given the sensitivity of the data involved, VPN apps — despite handling every single byte of a user’s internet traffic — have not always received a commensurate level of platform-level security review before publication. App stores generally check for basic policy compliance and malware signatures, but rarely perform the kind of deep technical audit of encryption implementation or data-handling practices that would be needed to catch the more subtle issues security researchers routinely uncover after the fact.
This gap between the sensitivity of what a VPN app touches and the depth of pre-publication review it receives is, in Depplo’s assessment, one of the more under-discussed structural problems in the mobile app ecosystem. Some platforms have begun introducing more specific policy requirements for VPN app developers in recent years, including clearer privacy label disclosures, but enforcement and depth of review still vary considerably, and a determined developer with a monetization strategy built around data harvesting can generally still get an app published with a plausible-looking privacy policy that doesn’t reflect actual practice.
Reading a Privacy Policy Like a Skeptic
Because formal app store vetting can only catch so much, the burden of scrutiny inevitably falls partly on the individual user — an unsatisfying reality, but a practical one. Depplo’s research desk suggests a few specific things to look for when reading any VPN provider’s privacy policy, free or paid:
- Vague data-sharing language. Phrases like “may share data with trusted partners” without naming those partners or specifying what data is shared should be treated as a meaningful red flag, not boilerplate.
- Undefined “anonymized” or “aggregated” data claims. These terms have no fixed technical meaning, and a substantial body of research has demonstrated that supposedly anonymized datasets can frequently be re-identified when cross-referenced against other available data.
- Silence on data retention periods. A genuine no-logs provider will typically state clearly and specifically what, if anything, is retained and for how long — not simply assert “we don’t log” without operational detail.
- No mention of RAM-only or diskless infrastructure. While not every trustworthy provider uses this architecture, its absence combined with a bare “no-logs” claim, unsupported by any audit, warrants extra caution.
The Bottom Line for Budget-Conscious Users
None of this is meant to suggest that privacy-conscious users must always pay premium prices to stay safe. Depplo’s testing has consistently found that several established, reputable paid providers offer genuinely affordable long-term plans — often less than the price of a single coffee per month on a multi-year commitment — that provide the full audited, RAM-only, no-logs experience without the compromises typically found in the always-free category. The real distinction worth drawing isn’t “free versus paid” so much as “audited and transparent versus unaudited and opaque,” and it happens that the always-free category disproportionately falls on the wrong side of that line.
Depplo’s security research team continues independent leak and permission testing across both free and paid VPN applications throughout the year.

