
A free VPN is not automatically dangerous, and a paid VPN is not automatically trustworthy. The real question is whether the operator, funding model, data practices and technology stand up to scrutiny.
What recent research actually found
2025 study, defined sample: Researchers presenting “Hidden Links: Analyzing Secret Families of VPN Apps” at the 2025 FOCI workshop examined related families of mobile VPN apps. They found apps that appeared independent could share code, infrastructure and security weaknesses. The result is evidence about the tested app families—not proof that every free VPN behaves the same way.
The FTC’s consumer guidance also warns that some VPN apps may fund themselves through advertising or sharing information with third parties. CISA’s 2024 mobile-communications guidance says commercial VPN providers can have questionable security and privacy policies. Together, these sources support careful verification, not blanket claims.
Six risks worth checking
Unclear ownership
Different app names can conceal shared operators or infrastructure. If you cannot identify who is responsible for the service, accountability is weak.
Data collection
A VPN can see connection information and potentially more, depending on its design. Compare the privacy policy, app-store disclosure and actual permissions.
Weak implementation
A VPN label does not guarantee secure protocols, safe key handling, leak protection or prompt patching. Look for recent, scoped independent testing.
Advertising and trackers
Analytics or advertising components can undermine the privacy goal. Check disclosures and avoid apps requesting permissions unrelated to VPN operation.
Capacity limits
Free tiers may restrict data, locations, speed or simultaneous devices. Those are commercial limits, not necessarily security defects, but they can make the service unsuitable.
Misleading promises
No VPN makes you anonymous everywhere, defeats every block, or protects you after you sign in and share information. Treat absolute claims as a warning sign.
A practical VPN safety checklist
- Identify the operator: find a real company, jurisdiction and support channel.
- Understand the funding: paid upgrades are easier to evaluate than a service with no visible revenue model.
- Read the logging policy: distinguish activity logs from operational connection data.
- Review permissions: microphone, contacts, accessibility or location access needs a specific explanation.
- Look for independent evidence: prefer recent audits with a named auditor, date and scope—not an unexplained “audited” badge.
- Check the basics: modern protocols, leak protection, app updates, account security and usable support.
- Test before relying on it: confirm your required location, device and network during the refund period.
Free tier, unknown free app, or paid service?
A reputable provider’s free tier can be useful for occasional browsing if its limitations fit your needs. An unknown app with vague ownership and sweeping promises is a different risk category. A paid service usually has more capacity and support, but you should still verify its practices.
If you need consistent multi-device access, more locations, or help when a restrictive network interferes, compare the available VPN plans. For the wider decision process, see our VPN buying guide, privacy and security guide, and explanation of VPN obfuscation.
Choose a service you can evaluate
Review the plans, supported devices and setup options before buying. Access results can vary by network and service.
Frequently asked questions
Are all free VPNs unsafe?
No. A free tier from a transparent provider can be legitimate, but “free” is not proof of safety. Check who operates it, how it is funded, what it logs, its permissions, and whether its security claims have been independently tested.
How does a free VPN make money?
Business models vary. Some use paid upgrades, while others use advertising, analytics, partnerships, or data collection. Read the privacy policy and app-store disclosure instead of assuming every free service uses the same model.
What should I check before installing a VPN app?
Verify the developer and ownership, read the privacy policy, review requested permissions, look for a clear logging policy and recent independent audit, confirm modern protocols, and check whether support and account-security options exist.
Can a free VPN protect me on public Wi-Fi?
A correctly implemented VPN can encrypt traffic between your device and its VPN server, but it does not make an untrustworthy provider safe, remove malware, or protect information you voluntarily give to a website.
Will a free VPN reliably unblock streaming or restricted networks?
Sometimes, but free tiers commonly have fewer locations, congestion, data limits, or no obfuscation. Availability changes, so no provider can honestly guarantee access to every service or network.
Is a paid VPN automatically trustworthy?
No. Payment alone proves nothing. Apply the same checks to paid services: ownership, policy clarity, independent audits, app permissions, protocols, support, and a realistic refund policy.
Sources and methodology
- FOCI 2025: Hidden Links—Analyzing Secret Families of VPN Apps (peer-reviewed workshop paper; mobile VPN app-family analysis).
- US Federal Trade Commission: In the market for a VPN app? (consumer guidance; published 2018).
- CISA Mobile Communications Best Practice Guidance (December 2024).
Evidence note: App stores and VPN products change. The cited research describes its tested sample and date; it should not be generalized to every free or paid VPN.
