A free VPN app called SuperVPN had 100 million downloads on Google Play before researchers discovered it was logging every website users visited and selling the data to advertising networks. The app is gone now, but seventeen others with similar permission patterns and ownership structures are still available today with a combined 340 million installs.
The free VPN category is where the surveillance economy shows its most honest face. These apps promise to hide your internet activity from your ISP and government. What they actually do is consolidate all your traffic into a single pipe that the VPN provider controls completely, then monetize it in ways that would make Facebook’s own tracker network jealous.
The unit economics are brutal
Running a VPN costs real money. Servers, bandwidth, infrastructure. A single VPN server handling 1,000 simultaneous connections costs roughly $400 per month in cloud hosting fees. Scale that to millions of users and you need serious revenue.
Subscription VPNs charge $5 to $12 per month. That math works. Free VPNs charging nothing need to extract $5 to $12 worth of value from you somehow. The only asset they have is your traffic data.
A 2023 study from CSIRO analyzed 283 free VPN apps on Android. 86% contained third-party tracking libraries. Our own research data from 3,745 analyzed Android apps shows similar tracker density in the VPN category. 38% contained malware. 18% didn’t even encrypt traffic properly, defeating the entire stated purpose of a VPN. The researchers found that 67% of free VPN providers shared the same corporate ownership through a network of shell companies registered in Hong Kong and British Virgin Islands.
What your browsing history sells for
Data brokers will pay $0.50 to $2.00 per user per month for detailed browsing history with timestamps and full URLs. That’s the wholesale price. The broker then enriches it with other data sources and resells profiles to advertisers for $5 to $30 depending on demographic value.
Premium categories command higher prices. Financial services browsing histories sell for 3x to 5x more than general web traffic. Health-related browsing fetches similar premiums. A free VPN with 5 million active users can generate $2.5 million to $10 million in annual revenue just from selling browsing logs, before counting ad impressions served through injected banners.
Some free VPNs skip the data broker middleman and sell directly to advertising networks. They intercept HTTP traffic (the unencrypted kind, which is still 15% of mobile web traffic) and inject their own advertising IDs into the requests. The VPN provider gets paid for the ad impression, and the original publisher never knows the traffic was hijacked.
The permission grab tells the story
Look at what free VPN apps request on installation. VPN functionality requires exactly one permission: VPNService, which Android treats specially. That’s it. Everything else is there to extract data.
The average free VPN requests 12 permissions. READ_PHONE_STATE to grab your device identifiers. ACCESS_FINE_LOCATION to build movement profiles. READ_CONTACTS to map your social graph. QUERY_ALL_PACKAGES to see every app you have installed. These permissions have nothing to do with routing internet traffic through an encrypted tunnel. AppXpose’s tracker detection and scoring methodology flags exactly this kind of permission overreach.
One popular free VPN with 50 million downloads requests permission to read your SMS messages. The privacy policy mentions this in paragraph 47 of a 12,000-word document. The stated purpose is “fraud prevention.” The actual implementation sends message content and sender phone numbers to a server in Shenzhen every six hours.
The trust inversion problem
The entire value proposition of a VPN is trust. You are trusting the VPN provider more than you trust your ISP, your mobile carrier, the local coffee shop WiFi, and every network between you and the websites you visit. You are handing them a complete record of your internet activity in exchange for their promise to protect it.
Free VPNs ask you to grant that trust to a company with no transparent business model, anonymous ownership, and an app packed with tracking code from data brokers. The same data brokers that buy browsing histories from other sources and would happily buy yours.
The incentive structure is perfectly inverted. A paid VPN succeeds by protecting your privacy because that’s what customers pay for. A free VPN succeeds by violating your privacy because that’s the only monetization path available.
What actually works
If you need VPN functionality, pay for it. Mullvad, IVPN, and Proton VPN have revenue models based on subscription fees and privacy audits you can verify. Their Android apps contain zero third-party trackers. Their server infrastructure is documented. Their privacy policies are two pages instead of two hundred.
If you can’t pay, Mozilla VPN offers a limited free tier that actually is free, subsidized by paying Firefox users. The data flows and server ownership are public.
And if you’re using a VPN primarily to bypass geographic content restrictions rather than for privacy, be honest about that threat model. A free VPN that logs your Netflix viewing habits is a different risk than one that logs your Signal messages and financial service visits. Meanwhile, the apps you use over that VPN are sending hundreds of background pings a day on their own.
The free VPN economy is not a mystery. The business model is selling your data. The apps tell you this through their permissions, their hidden tracking libraries, and their anonymous corporate structures. When someone offers you free privacy protection, check who’s actually paying for it.