How do free VPNs make money?

Updated

Servers cost money, so a free VPN is paid for by subscribers, by ads, or by you. Some free VPNs and privacy apps have collected browsing and app-usage data and sold it to analytics firms, investors and advertisers, or rented out users' internet connections as proxies. A clear paid plan is the best sign yours doesn't.

Silhouette of a person walking at night, looking at a phone
Photo: Roman on Unsplash

Every gigabyte that goes through a VPN costs the company money: servers, bandwidth, staff. When an app is free, someone else is paying. A VPN is also in a unique position to see what you do: every site and every app on your phone sends its traffic through it. That combination is why "how does this free VPN make money?" is the most important question you can ask before you install one.

The three ways a free VPN pays for itself

ModelWho paysRisk to you
FreemiumPaying subscribers fund the free tierLow: the free plan is a sample of a paid product
AdsAdvertisers pay to show you ads in the appMedium: annoying, and ad SDKs track you inside the app
Your data or your connectionData buyers, or people who rent your internet connectionHigh: the VPN is selling exactly what you installed it to protect

The first two are normal businesses. The third is the one to avoid, and it isn't a theory. Here is what has actually happened.

Real cases

Onavo: a VPN run by a social network

Facebook bought the Israeli VPN company Onavo in 2013. Onavo Protect was marketed as a free app that kept you safe, while its traffic data showed Facebook which apps were growing. According to reporting at the time, that data informed the WhatsApp acquisition. Apple pushed it out of the App Store in August 2018 for collecting data about other apps. Court filings made public in 2024 in a US class action describe "Project Ghostbusters", in which Onavo was used to decrypt analytics traffic from Snapchat, and later YouTube and Amazon.

Sensor Tower: VPNs and ad blockers owned by an analytics firm

In 2020, BuzzFeed News found that the app-analytics company Sensor Tower owned at least 20 apps, including Luna VPN and Free and Unlimited VPN, without saying so in the apps. Some asked users to install a root certificate that let the company read encrypted traffic. The apps had about 35 million downloads. Sensor Tower sells app-market data to businesses.

Avast and Jumpshot: browsing history sold for years

Not a VPN, but the same pattern from a privacy brand. The US Federal Trade Commission found that Avast collected browsing data through its antivirus and browser extensions since at least 2014 and sold it through its subsidiary Jumpshot to more than 100 third parties, while telling users its products blocked tracking. In 2024 the FTC ordered Avast to pay $16.5 million and banned it from selling browsing data for advertising.

Hola: your connection rented out to strangers

The free Hola VPN routed traffic through its users' own devices. From late 2014, its sister company Luminati sold access to those users' connections) as exit nodes to paying customers. In 2015 the network was used to attack a website. Hola said this was part of its free terms, and updated its FAQ to say so more clearly.

The bigger picture

A 2016 study of 283 Android VPN apps by CSIRO and UC Berkeley researchers found that 67% included at least one third-party tracking library, 38% were flagged for malware or adware, and about 18% didn't encrypt traffic at all.

Who buys this data

  • Market-intelligence firms want to know which apps and sites people use, how much and how often. They sell those reports to brands, app developers and investors.
  • Investors and hedge funds buy "alternative data": a jump in visits to a retailer can move a trade before the company reports its results.
  • Advertisers and data brokers turn browsing history into audience segments ("looking for a loan", "planning a trip") for targeting.
  • Residential proxy buyers rent real home and mobile IP addresses for web scraping, price monitoring and ad verification, and sometimes for fraud. When a VPN sells your connection, their traffic leaves from your IP.

How this happens on Android

Google Play's VpnService policy does allow a VPN to collect personal and sensitive data, but only with a prominent disclosure inside the app and your explicit consent. So the trick is usually a consent screen worded to sound harmless: "help us improve the service", "allow analytics for a faster connection", or a browser extension that asks to "read and change data on all websites". One tap, and the history leaves with your permission.

Checklist: is your free VPN selling your data?

  1. Is there a paid plan? A freemium VPN earns from subscribers. No paid plan and no ads means something else pays.
  2. Read the first screen after install. Decline any consent for "analytics", "partners" or "improving the service" that isn't required to connect.
  3. Search the privacy policy for sell, share, partners, aggregate and anonymised. "We don't sell personal data" plus a list of named processors is a good sign; "aggregated data may be shared with partners" is not.
  4. Check who owns it. Look at the developer name on Google Play and search it. Apps from analytics or ad-tech companies are a red flag.
  5. Check permissions. A VPN needs network access and notifications, not your contacts, SMS or location.
  6. Never install a root or user certificate because a VPN asks you to. That lets it read encrypted traffic.
  7. Watch for "peer" or "community" networks. If free users' devices carry other people's traffic, your IP is the one that shows up.

How SimpleV pays for itself

SimpleV VPN is freemium, and that's the whole business:

  • Premium subscriptions pay for the servers. Free users get 500 MB a day as a sample of the same service.
  • No ads, and we don't sell personal data or use it for advertising.
  • No traffic logs: we don't record the sites you visit or what you send. We count only total bytes per device, to apply the free allowance.
  • No account needed for the free plan, and nobody else's traffic goes through your phone.
  • The privacy policy names what we collect and why.

FAQ

Do all free VPNs sell your data?

No. Many free tiers are funded by paying subscribers or by ads. The risk is highest when there's no paid plan, no ads and no clear explanation of how the company earns money.

Is a paid VPN guaranteed not to sell data?

Not guaranteed, but the incentive is different: subscribers are the business. Check the privacy policy and the owner either way.

Can a VPN see my browsing history?

It can see which sites and apps you connect to, because that traffic goes through it. On HTTPS sites it can't read the content. That's why the VPN's logging policy matters.

What is a residential proxy and why does it matter?

It's a network that sends other people's traffic through ordinary home or mobile connections. Some free VPNs and apps join their users to such networks, so strangers' traffic leaves from your IP address.

How do I remove a VPN's certificate on Android?

Settings → Security & privacy → More security settings → Encryption & credentials → User credentials (names vary by phone). Remove any certificate you don't recognise, then uninstall the app that asked for it.