Free Apps & Software Alternatives

Before You Install a Free VPN on Android: What the App Asks For and Collects

A free privacy app that hides your browsing from your network can also see that browsing. Before you install one, the thing to decide is whose hands you’re putting your internet traffic in, and the store listing already tells you more about that than most people check.

When you look at a free VPN for Android, three things are visible before you tap Install: what the developer says it collects, what it can access on your phone, and what the free plan holds back. None of them proves an app is safe. Researchers behind a 281-app audit found serious flaws that no listing reveals. Still, the three signals together will rule out a lot of bad options, and one of them is easy to misread.

What the App Asks For and What It Can See

Android makes you grant a VPN one special permission before anything else. According to Android’s developer guide, the system shows a connection request dialog before a VPN app can become active for the first time, asking you to confirm that you trust the VPN. Once you accept, the app reads your phone’s outgoing traffic, encrypts it and sends it to the provider’s server. A key icon in the status bar then shows the tunnel is running.

That dialog is there because of what you’re handing over. The MVPNalyzer researchers from the University of Michigan, the University of New Mexico and IIT Delhi call this a transfer of trust: the VPN protects you from snooping networks, but now the VPN provider sits where your internet provider used to. Notebookcheck puts it more bluntly: from that point on, the VPN app itself can see everything, and you’re just moving your trust from your network provider to whoever built the app.

A VPN also doesn’t make you anonymous. Business Insider points out that websites and apps can still identify you through logins, cookies or browser fingerprinting, and your internet provider can usually tell you’re using a VPN.

How free VPNs make money

Running servers costs money, so the question with any free VPN is how it’s paid for. Business Insider lists the usual options: serving you ads, pushing you to upgrade to a paid plan, or, worst case, selling your data or loading your device with malware. Its reviewers also note that some free VPNs make money by selling user data, which is why they call data logging the most notable risk.

The better-known providers explain their own model openly, and their explanations are worth reading as claims rather than proof. Proton says its free service is supported by paying users and promises no ads and no logs. TunnelBear, explaining recent free-plan changes, says many free VPNs now rely on in-app advertising or data collection, and that it has never done either. hide.me says it doesn’t make money on its free service at all and treats it as a route to its paid plan.

So the listing details matter for this reason: an ad-funded app has a financial reason to collect identifiers, while a subscription-funded app has a reason to keep the free tier limited. Those two models leave different marks on a store page.

Before You Tap Install: Three Signals to Check

Each of these signals shows you something different, so check all three rather than stopping at the first one that looks fine.

Signal 1: the Data Safety section

Google’s Play Help page says to open the app’s listing, find the “Data safety” summary and select See details. The section only covers apps distributed through Google Play, and it only appears on Android 5 and up.

When you read it, look first at “Data shared”. Google defines shared data as data the app transfers to a third party, and one of its data types, “Device or other IDs”, specifically includes the advertising identifier. A VPN that shares device IDs for “Advertising or marketing” is telling you where its money comes from.

Two limits apply. First, the section is written by the developer. Google’s developer documentation makes developers solely responsible for the accuracy of their declarations. Second, the declarations have carve-outs: under Google’s rules, data that’s only processed briefly in memory, or transferred to a service provider working for the developer, doesn’t have to be listed as collected or shared. Google also says practices may vary based on your use, region and age, so the listing a phone in Lagos sees may not match the one seen in another country.

Signal 2: permissions that don’t match the job

The permissions list is a separate thing from Data Safety. Google says it’s based on technical information about how the app works, not the developer’s own description, and that the two sometimes disagree. On the Play Store version MakeUseOf described in 2025, you find it by scrolling to About this app, finding App permissions and tapping See more. The layout may be different on your phone’s Play Store version.

A VPN’s job is to move network traffic, so ask of every permission, “What does this have to do with routing my connection?” The Zimperium zLabs study of nearly 800 free VPN apps, reported by ThaiCERT, found some Android apps asking to read complete system logs, which the researchers said could let them build detailed profiles of users. It also found iOS apps asking for continuous location access, which has nothing to do with a VPN’s purpose. Access to your contacts, call logs, SMS or microphone should get the same question.

Some unusual permissions do have reasons, so this is a question to ask rather than an automatic fail. If you want to see what’s built into an app beyond the Play list, Exodus Privacy lets you search by app name or Play Store link and lists the tracking software built into it.

Signal 3: the free-tier limits

The limits tell you how the provider handles the cost of free users. A cap on data or server choice suggests a provider that wants you to upgrade. “Unlimited everything” with ads suggests the ads are covering the cost. The table below shows how these limits differ in practice.

The “Verified” badge is not the fourth signal

Google gives some VPN apps a “Verified” badge. According to Google, apps need to complete a Mobile Application Security Assessment (MASA) Level 2 validation, have at least 10,000 installs and 250 reviews, be on Play for at least 90 days and use an organisation developer account. That’s a real bar. But Google also says the independent review does not verify the accuracy and completeness of the developer’s Data Safety disclosure. The MVPNalyzer researchers told Digital Trends that Data Safety information and the badge may work more like marketing signals than full security guarantees.

What the listings say, side by side

The table compiles each app’s Google Play Data Safety declaration, as shown on the US-English Play web listing on 29/09/2026, together with each vendor’s own description of its free tier. These are self-declared statements, not test results, and they can change with the next update.

App (developer) Data Safety: shared with third parties Data Safety: collected Free-tier limits (vendor’s statement) What to weigh
Proton VPN (Proton) None declared Crash logs (optional), purchase history, email, user IDs, phone number (optional). Independent security review listed One device, no ads, no data or speed limits; free servers in 10 countries, with the next server picked at random and a cooldown between changes No cap, but you can’t pick your country; needs an account
Windscribe None declared Device or other IDs (developer communications), email (optional). Independent security review listed 2GB a month by default, 10GB once you confirm an email Low cap for heavy use; the email trade-off gets you more data
hide.me (eVenture Limited) None declared No data collected declared; no deletion request option listed 7 server locations, one device, unlimited data Smallest declared footprint in this set; server choice is European and US only
TunnelBear None declared Crash logs, diagnostics, other performance data, email 2GB a month; country selection and split tunnelling moved to paid plans Tight cap; you can no longer choose a location on free
1.1.1.1 + WARP (Cloudflare) Device IDs, name, email, user IDs, photos and videos, location, web browsing history, other actions Similar categories, including web browsing history; listing says data can’t be deleted Replaces your IP with a Cloudflare IP that reflects your approximate location Listing and privacy page read very differently; read both
Turbo VPN Device or other IDs, for advertising or marketing App interactions, device IDs, photos (optional), email (optional), user IDs, crash logs Listing shows contains ads and in-app purchases; free limits not checked here The listing openly states an ad-sharing model

Two rows show why reading only one signal can mislead you. Turbo VPN’s declaration is short but says plainly that device IDs go to third parties for advertising. Cloudflare’s listing declares sharing across a long list of categories, including browsing history. Cloudflare’s own WARP privacy page, meanwhile, says it collects only limited DNS query and traffic data without the content, and that it won’t sell or rent personal information. The table can’t tell you which reading is right. What it does show is that a listing and a privacy policy can describe the same app very differently, and you need to read both before trusting either.

What You Give Up When You Choose Free

Even an app that passes all three checks costs you something, and the cost usually shows up as speed, capacity and reliability.

Speed comes first. Business Insider says free VPNs often cap speeds and can throttle connections because their servers are overloaded. That makes streaming, video calls and large downloads harder, and some plans give you a set amount of data before cutting you off or slowing you sharply. Server choice goes next: the same guide says some free VPNs offer as few as 10 preselected locations, and you can’t always choose which one you join. Proton’s free plan is an example. It picks your next server at random and makes you wait between changes.

There’s also a cost Nigerian readers on data bundles will feel directly. hide.me explains that its VPN works on top of your existing internet connection and asks users to keep enough quota to avoid interruptions. In other words, a VPN’s monthly allowance is a separate limit from your MTN or Airtel bundle. Browsing through Windscribe’s 10GB still uses your own data as well.

When it works, then stops

One user on r/AndroidGaming described a free VPN that worked at first, then stopped changing their IP address, and said a second free VPN behaved the same way. The reply that thread’s research record highlights didn’t offer a fix. It just advised against free VPNs. A single thread can’t tell you the cause. But the documented behaviour of free tiers gives some possible explanations to check: a used-up allowance, an overloaded free server, or a plan that assigns you a server you didn’t choose.

The more serious version of “it stopped working” is the kind you don’t notice. The MVPNalyzer audit found 29 apps leaking user traffic, including DNS lookups, outside the tunnel, and 61 sending some data unencrypted. Notebookcheck’s summary adds that five apps loaded their configuration files unencrypted. That let an attacker on the same Wi-Fi, such as whoever runs a public hotspot, redirect the connection while the app still showed “Connected”. Those flaws don’t show up on a store listing, which is exactly Notebookcheck’s point.

Android does include a safeguard worth knowing about. Its developer guide describes an always-on VPN option and a Block connections without VPN switch in the VPN settings, which stops network traffic that isn’t going through the VPN. The trade-off is stated plainly in the same guide: with blocking on, you have no internet connection until the VPN connects. If your free server drops out, your phone goes offline rather than quietly leaking. The guide places VPN settings under Settings > Network & Internet > VPN, though the labels on your phone may differ.

The Decision: Free VPN, Free Stack, or Paid

You have four realistic options, and which one fits depends on what you need the VPN for.

A checked free VPN fits occasional use, such as an untrusted hotel or café network, where Business Insider sees added privacy as the main benefit. “Checked” means it passed all three signals, and ideally its provider publishes an independent audit. Notebookcheck’s advice is to prefer providers with a recent, independent audit, to be wary of free apps full of ads, and to treat “verified” or “no logs” as a starting point, not proof.

A free stack is the option most comparisons leave out. A poster on r/dns described getting tired of slowdowns and clunky VPN apps and building a setup from RethinkDNS, Cloudflare WARP and NextDNS instead, which they reported as fast and costing nothing. That’s one person’s account, and the performance claims are theirs. The pieces themselves are documented. RethinkDNS is a free, open-source Android firewall and DNS blocker that routes your traffic through itself using Android’s VPN slot, and its Play listing declares no data collected or shared. NextDNS filters at the DNS level and its free plan covers 300,000 queries a month, after which it keeps working as ordinary DNS without blocking. The catch is that Android allows only one active VPN service per user, so you can’t simply switch on several VPN-type apps side by side. Combining them means configuring them, which is real work. Also, a DNS blocker on its own doesn’t hide your IP address.

A paid VPN makes sense if you’d run it every day, stream, or need a particular country. Business Insider notes that paying gets you more servers and features but doesn’t automatically make a VPN safer, so the same three checks still apply. Paid prices, and whether Nigerian cards are accepted, change often enough that you should confirm both on the provider’s own checkout page.

No VPN is a legitimate choice for everyday browsing at home. It’s also the better choice than an app that fails the checks. An app that leaks outside its tunnel or can be redirected over Wi-Fi gives you the feeling of protection while sending your traffic through a stranger’s servers.

Where Most People Go Wrong

The usual mistake is treating a free VPN as a free privacy upgrade when it’s really a decision about who gets to see your traffic. The listing gives you three clues before you install: what’s declared as shared, whether the permissions fit the job, and how the free tier is paid for. The “Verified” badge doesn’t replace any of them. Check all three, and read the privacy policy whenever the listing and the vendor’s own claims don’t match.

Frequently Asked Questions

Does a free VPN still use my mobile data bundle?

Yes. hide.me explains that a VPN runs on top of your existing connection, so your network bundle is still consumed. A VPN plan’s own allowance, such as Windscribe’s 10GB, is a separate limit on top of that.

Is a free VPN better than nothing on public Wi-Fi?

A checked one can add privacy on an untrusted network. An unchecked one can make things worse: MVPNalyzer found five apps whose unencrypted settings let someone on the same Wi-Fi redirect the connection while the app still showed “Connected”.

Can I run RethinkDNS and a free VPN app at the same time?

Not as two separate running VPN apps. Android allows one active VPN service per user, and starting a new one automatically stops the existing one. RethinkDNS uses that same VPN slot for its firewall.

Can 1.1.1.1 + WARP make me appear in another country?

Cloudflare says WARP replaces your IP with a Cloudflare IP that reflects your approximate location, so it isn’t designed for changing your location. It also says WebRTC traffic, used by some video-call apps, bypasses WARP and can reveal your IP.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button