After a months-long survey of over 7,000 mobile VPN apps around the world, Proton has found that 85% of those downloaded in the US contain trackers, and around a quarter of those actively track users’ physical location.

Perhaps even more concerning, we also learned that 64 of the 390 VPNs downloaded from the Apple App Store and Google Play in the US are owned by Chinese companies, which are legally bound to share data with their authoritarian government.

Given that most people who use a virtual private network do so specifically to protect their privacy, the risks are obvious. And despite promises to protect the public, Google and Apple allowed these suspect VPNs to be downloaded more than 13.2 million times in June 2026 alone.

Methodology

We examined free-to-pay downloads from the Google Play store. Monthly download counts are estimates from AppTweak for the month of May. For tracker counts, we used data from Exodus Privacy(nieuw venster), an open-source platform that analyzes Android apps to detect the code signatures of analytics, advertising, and profiling trackers.

How VPNs should work

When you use a VPN, you expect privacy. A trustworthy VPN stops websites from seeing your real IP address and prevents your internet service provider (and, by extension, your government) from knowing what you do online.

VPNs have become a part of daily life for as many has 100 million Americans(nieuw venster). Spend just a few minutes on YouTube and you’ll almost certainly encounter an ad for VPNs, which are typically promoted as a vital tool for privacy, security, and bypassing censorship.

For the most reputable services, this claim largely holds up. But this in itself can create a false sense of security for millions of consumers who are tempted by the free VPNs that feature prominently on the app stores, and it hides the fact that many dubious VPNs are doing the exact opposite of what you’d expect from them.

Who owns your VPN?

When it comes to VPNs, transparency is vital.

You should know who owns the company you’re trusting with your privacy. Our analysis has found that dozens of VPNs available in the US are owned by companies based in jurisdictions with intrusive data surveillance laws. Perhaps unsurprisingly, many go to considerable lengths to conceal this fact.

Of the VPNs we studied, 64 are owned by Chinese companies. Under Chinese law, companies are required to make user data available(nieuw venster) to the government upon request. What makes this worse is that 31 of these Chinese-owned VPNs actively hide their real ownership behind shell companies registered in places like Singapore, Hong Kong, and the UK.

Users in the US downloaded these shady Chinese apps more than 3 million times over one month.

Where does your data go?

Even VPNs that aren’t directly owned by companies based in countries known for their mass surveillance practices can endanger users’ privacy.

Our analysis found that 85% of VPNs available in the US contain trackers designed to collect and share highly personal user data. This can include your unique device ID (GAID), device model, network type, mobile carrier name, and more.

Trackers sending data toDownloads in June
China1.5 million
Russia1.4 million
Israel2.6 million
All three800,000
Five Eyes countries4.6 million

Many of these US-owned apps entered commercial agreements with foreign companies, embedding their tracking software as part of the deal. They typically see VPN apps (often purchased as off-the-shelf white-label products) as just another popular app category that, like games, can be monetized thorough advertising.

This is simply how the mobile app industry operates. And in a world where app stores take around 30% of sales revenue, it’s not surprising that app providers might choose to monetize their products though privacy-invasive advertising, rather than up-front paid subscriptions.

But VPN apps are not games. Millions of Americans use them to protect their privacy, not to sell their privacy to ad-tech companies, many of which are based in countries with governments that are hostile to privacy, and, in many cases, also hostile to US interests.

Although it’s difficult to know exactly what’s being done with your data, there are worrying signs. Three of the VPN services we looked at are actually owned by market research companies: ‎Phone Guardian Safe WiFi (Sensor Tower(nieuw venster)), My Mobile Secure VPN (Comscore(nieuw venster)), and Urban VPN (BiScience(nieuw venster), which has been been shown(nieuw venster) to capture user conversations across several services and share them with AI chat platforms).

Some VPNs track your location

In what many could reasonably see as the ultimate act of betrayal, 64 VPN apps actively track your physical location using GPS and other geolocation data. Anyone with access to this data can see if you are at a protest or meeting with a journalist, lawyer, or source, and ultimately share that information with law enforcement or intelligence services.

These apps include some of the most popular VPNs in the US, such as VPN Proxy Master, VPN-Fast VPN Super, and X-VPN, and collectively they were downloaded more than 3 million times in June. This means roughly 20% of all VPN downloads in our dataset come from apps that track where you are, which is likely the very thing you installed a VPN to prevent.

And this tracking data is often being made available to governments that are difficult to trust.

App stores are profiting from surveillance

Apple and Google publicly tout their privacy credentials. Yet these apps, which can track everything you do online and send your personal data to ad-tech companies, are freely downloadable on their app stores with no warning labels.

While app stores require VPN developers to submit their identities and their privacy policies, they rely heavily on self-reporting and do little to verify what they are told. Apple and Google check that the paperwork exists, but they don’t independently audit whether a VPN actually behaves in the way its privacy policy claims.

Despite their privacy claims, Apple and Google prioritize profits over the best interests of their users. They typically take around a 30% commission on all revenue generated from in-app purchases and subscriptions. Apple, in particular, seeks to justify this commission by claiming it is necessary to cover the costs of reviewing and curating apps to keep users safe (despite credible evidence that it pockets up 78% of these fees(nieuw venster) as pure profit).

The profit-centric model is also amply illustrated by Apple’s willingness to cooperate with authoritarian orders from the Chinese government, which has resulted in 66 of the 100 most popular apps worldwide being unavailable to iOS users in China.

Many of these are news apps (including the likes of The New York Times, BBC News, and Reuters), showing that Apple is happy to assist the Chinese government’s censorship regime in exchange for access to the highly lucrative China market. It even threatened to remove Proton VPN(nieuw venster) because the App Store description said our app could be used to “unblock censored websites.”

The result? Authoritarian-linked VPNs that have access to all your traffic, including your web browsing, app usage, and personal information, are tracking your online behavior for advertising purposes.

So what can be done about it?

To permit these suspicious apps to exist on their platforms is a dereliction of duty to both consumers and developers. This is unacceptable. We therefore urge Apple and Google to:

  • Perform more stringent forensic security and ownership checks on VPN apps (not simply rely on self-reporting)
  • Remove all apps that fail to meet these checks from their app stores
  • Provide greater transparency about all VPN apps so that people can make informed decisions about which ones can be trusted. This includes providing information on where a company is (really) based and what it’s doing with your data

For such transparency to be effective, Apple and Google must use a tiny portion of their vast resources to investigate services and ascertain that they are what they purport to be.

What you can do to stay safe

To safely protect your privacy with a VPN:

  • Use a service with transparent ownership that’s located in a country with real privacy laws
  • Only trust VPNs that have been independently audited

There’s no excuse

Because all of your internet activity passes through its servers, any VPN has the potential to access a great deal of highly personal information about you, your life, your political leanings, what you like to buy, and your hobbies and interests. Even if privacy is not a primary concern when picking a VPN app, you should be worried about shadowy, unaccountable companies with links to places like China and Russia, where the government has unrestricted access to all data.

In total, 85% of the apps we studied in the US are behaving in ways contrary to how they are marketed and what you’d reasonably expect from a VPN service. This is inexcusable.

Many of these apps may claim that this data collection is only done to optimize performance. But the fact that they can collect this data — and that so much of it is sent to places like Russia and China — is cause for grave concern.

Thankfully, there are reputable VPN services that genuinely care about protecting your privacy. This includes Proton VPN, which offers 100% free VPN service with open-source apps, no ads, no data limits, and a strict no-logs policy that’s independently audited and backed by Swiss privacy laws.

How can we do this? It’s quite simple. We transparently fund our free plan with a premium service that offers a range of advanced (but entirely optional) features. Because at Proton, we believe that privacy shouldn’t come with strings attached.


Cover image by Bernard Leonardo.