JC JC Mobile App Studio
JC

Privacy , Friday July 10, 2026

Your free VPN might be the thing tracking you.

You install a VPN to be harder to watch, so it stings to learn that many of the most popular free ones do the opposite. A new study ran 281 of the top free VPN apps through an automated test rig and found leaks, tracking, and broken encryption everywhere. Here is the plain version, and why this is the one kind of app you should never grab for free without thinking. Verified July 10, 2026.

Researchers from the University of Michigan, the University of New Mexico, and IIT Delhi built an automated testing framework called MVPNalyzer and pointed it at 281 of the most popular free VPN apps on Google Play. The team, led by associate professor Roya Ensafi, presented the work at the NDSS 2026 security conference. Her motivation was blunt: people rely on these apps for privacy, and many fail to uphold even basic protections. (Michigan Engineering)

The findings are ugly. 29 apps let user traffic leak outside the encrypted tunnel, including the DNS lookups that reveal which sites you visit, and 24 of those DNS leakers alone account for roughly 360 million installs. 61 apps sent data in plain text. 76 handed the device's advertising ID to third parties, and more than 80 percent of the apps, 246 of them, phoned home to known advertising and tracking servers. Nearly one in five still leaned on weak or outdated encryption like the aging Blowfish cipher or triple DES. More than 60 percent failed basic security hardening. Add it all up and the flagged apps have been installed more than 2.4 billion times. (The Hacker News)

Here is the part the marketing never says out loud. A VPN does not make you invisible. It takes every bit of traffic leaving your phone and reroutes it through one company's servers. That means you are handing that one company a front row seat to everything you do online. When you pick a VPN, you are not removing a watcher, you are choosing a new one and hoping they are trustworthy. A VPN that leaks or sells your data is worse than no VPN at all, because it collected the traffic in one convenient place first and charged you nothing, which usually means you were the product.

An editorial illustration of a smartphone connected to a glowing tunnel of light, with small streams of light leaking out through cracks in the tunnel wall, on a dark teal background.
A VPN is a tunnel for all your traffic. The study found a lot of leaky tunnels.

The 281 app study looked at Android, so it is tempting for iPhone owners to feel safe. Do not. Broader reporting on this research, which spanned nearly 800 free VPN apps across Android and iOS, flagged iPhone specific problems too. About 25 percent of the iOS VPN apps lacked a valid privacy manifest, the file Apple requires so you can see how an app handles your data. Over 6 percent requested private entitlements, which are powerful permissions that can grant deep access to the operating system. And some asked for always on location, which a VPN has no business needing. (Hackread)

Same lesson, different store. A free VPN on the App Store is still a company asking to carry all your traffic, and the review process does not guarantee it handles that traffic well.

I am not telling you to swear off VPNs. A good one has real uses. It hides your traffic from a network you do not trust, like sketchy public Wi-Fi. It hides your IP address from a website you are visiting. It lets you get around a regional block. Those are legitimate jobs, and a reputable, audited VPN does them well.

What a VPN does not do is make you anonymous or private in general. It does not stop the apps on your phone from tracking you. It does not stop data brokers from buying and selling your profile. It does not undo the fact that you are logged into your accounts. If your mental model is "VPN equals privacy," the study is a good reminder that the truth is much narrower, and that a bad VPN turns a narrow benefit into a wide open risk.

If you genuinely need a VPN, pay for a reputable one that publishes independent audits, and skip the free ones entirely. Before you install any of them, check the permissions, because a VPN asking for your location, your contacts, or always on access is a red flag you can see without reading a single security paper. And be honest about whether you need one at all, since for most everyday privacy the bigger wins live somewhere else, like turning off ad tracking, using a private DNS, and being choosy about which apps you let phone home in the first place.

This is the whole reason we build on device. The safest data is the data that never leaves your phone. A VPN, even a great one, still ships your traffic to somebody. An app that does its work locally ships nothing, so there is no server to leak, no company to trust, and no advertising ID to hand out. Different problem from a VPN, but the same principle runs through both: the fewer places your data can leak from, the safer you are. A leaky tunnel is still a tunnel to somewhere. On device is a wall.

For the basics behind all of this, see What on-device AI means and Encryption explained. You can see what this studio builds at jcmobileappstudio.com.

JC

Written by Josuam Collazo

A lifelong tech enthusiast in his mid-thirties who builds privacy-first iOS apps in his spare time and writes plain-language pieces on tech, money, on-device AI, and your rights at work, drawn from his own experience at work and in life. More about Josuam

More from the blog

Plain-language writing on tech, workers' rights, investing, and on-device AI.

Read the blog

Comments

Be kind and stay on topic. Comments are reviewed before they appear.

Contact

Get in touch.

Beta access, app ideas, bug reports, or partnership questions, the inbox is open.

Support available in English and Espanol.