r/Adguard

▲ 13 r/Adguard

The hidden cost of free Android VPNs: Tracking, leaks, and false assurances

Free VPNs promise an irresistible bargain: privacy without paying for it. SplitVPN made that promise unusually explicit. Its homepage declares“VPN that makes you forget about privacy issues!” Just below, it promises unlimited traffic, fast servers — and “no logs.”

To be precise, SplitVPN is not entirely free. It offers both free and paid plans, while its Google Play listing says the app contains ads and in-app purchases. But the free version still sells that enticing idea of privacy without payment. For those users, the price becomes clearer in the small print.

The privacy policy linked from the current Google Play listing says third-party advertising services may collect information such as advertising IDs, IP addresses, device details, app usage, and approximate location. It also acknowledges that, under California privacy law’s definition, some ad-supported versions of its product may “sell” certain data to advertising partners. The policy explicitly says this does not include users’ VPN browsing activity, so it does not by itself contradict SplitVPN’s no-logs promise. But it does complicate the promise of privacy at no cost: free users may not pay a subscription fee, yet their attention and other data can still have commercial value.

In late July, the idea that user data can have commercial value took on a darker meaning. Messages on hacking forums claimed that a database stolen from SplitVPN, previously marketed as NotVPN, had been put up for sale. The seller alleged that it contained data on millions of users, including emails, IP addresses, device and subscription information, and payment records. It supposedly also included nearly 58 million connection logs — a particularly damaging claim for a service built around a no-logs promise.

SplitVPN/NotVPN confirmed the breach but disputed the claim that it had leaked connection logs. The company said someone had accessed its subscription database on July 21 and acknowledged that users’ email addresses, countries, subscription statuses, device names, and limited payment information had been exposed. However, it insisted that it does not record which websites users visit, saying that attackers invented the connection-log table to make the dump appear more valuable.

It was not the first time NotVPN had come up in a privacy context. A recent academic study of Android VPNs found that packages linked to the app sent some app-generated data over unencrypted connections and were easy to recognize as VPN traffic. Importantly, the researchers did not accuse NotVPN of leaking browsing traffic or keeping activity or connection logs.

But NotVPN was only one part of a much larger and more troubling pattern.

Many free VPNs are privacy and security time bombs. Servers, bandwidth, development, and maintenance all cost money. If users are not paying for the service, the provider may be making money through advertising, tracking, or data collection instead. And because a VPN has privileged access to their internet connection, the potential price is much higher than with an ordinary free app.

Collectively, the problematic apps identified in the study had amassed more than 2.4 billion installations. Below are the key findings.

Free VPNs: what was surveyed

The study was conducted by researchers from the University of Michigan, the University of New Mexico, and IIT Delhi and presented at the Network and Distributed System Security Symposium (NDSS) in February 2026.

The team assembled its dataset in November 2024 by searching Google Play for 40 popular terms associated with VPNs, including “VPN,” “free VPN,” “best free VPN,” “secure VPN,” “VPN with no logs,” “VPN for privacy,” “VPN for streaming,” and “VPN for gaming,” and so on. Google Play returned up to 30 apps for each search term, producing as many as 1,200 results per country before duplicates were removed. The final sample contained 281 free VPN apps.

Then they tested them on a physical Android 14 device using MVPNalyzer, a framework developed for the project. The apps were checked for:

  • unencrypted communication between the app and its own servers;
  • DNS or browsing traffic escaping the VPN tunnel;
  • advertising identifiers and other device data being sent to trackers;
  • weak or outdated VPN configurations;
  • VPN traffic that could be easily recognized and blocked.

Traffic and DNS leaks, tracking and fingerprinting — the dangers behind free VPNs

The first problem went against the very purpose of using a VPN: 61 apps sent their own data to servers without encryption. This was app-generated traffic, not users’ browsing traffic, but it could still be seen or altered by the user’s internet provider, the operator of a public Wi-Fi network, or an attacker monitoring the connection. In 5 cases, apps even downloaded their VPN configuration files this way. An attacker could potentially replace the file and redirect the supposedly protected connection to a server they controlled — while the app continued to show that the VPN was “connected.”

Another 29 apps allowed traffic to escape the tunnel. This traffic might still be encrypted by a website through HTTPS, but it would bypass the additional protection and privacy the VPN was supposed to provide. This included apps leaking DNS requests, leaking browser traffic, and creating tunnels that carried data without adding any VPN encryption. Each of these independently defeats a basic reason for using a VPN. A DNS leak, for example, can reveal which websites or services someone is trying to reach even if the pages themselves remain encrypted.

The scale of tracking was even more striking. More than 80% of the tested apps contacted advertising or tracking domains. The researchers identified them using EasyList, EasyPrivacy, Disconnect, and the AdGuard Mobile Ads filter.

Seventy-six apps transmitted the Android Advertising ID, while others shared IP addresses, device models, operating-system versions, language, or location information. One app even transmitted precise coordinates. Most of these details may appear harmless. Combined, they can build a persistent device profile, connect activity across apps and sessions, and potentially link it back to a real network or location. Instead of removing a layer of surveillance, a free VPN may simply add a new one.

The configurations hidden behind the “Connect” button were hardly more reassuring. Of the 108 OpenVPN configurations the researchers obtained, 107 failed at least one security check. Many relied on weak authentication, outdated settings, or lacked basic protections against known attacks.

>

For users relying on VPNs to bypass censorship, there was another catch. The researchers could easily identify 169 apps as VPNs through standard ports, common protocols, or obvious domain names. In 101 cases, apps contacted domains containing the word “vpn.” Once a censor can recognize a VPN connection, blocking it becomes much easier.

The researchers aimed to survey the most popular Android VPN apps, so if you think these were obscure services with only a few thousand users, that is unfortunately not the case. Current Google Play listings show that several of the VPNs mentioned in the report have surpassed 100 million downloads:

  • Instabridge — 100 million+ downloads — was flagged for unencrypted traffic, tracking, easy detection, and configuration problems.
  • VPN Proxy Master — 100 million+ downloads — was linked to unencrypted traffic, tracking, and easy detection.
  • Super VPN — 100 million+ downloads — was found to transmit some data without encryption.
  • Thunder VPN — 100 million+ downloads — was among the apps found to transmit Advertising IDs.

If anything, the download numbers make the findings more unsettling. These apps were not hiding in obscure corners of the internet: users found them on Google Play, surrounded by ratings, download counts, privacy labels, and checkmarks that made them look vetted.

Google guardrails are not enough

Google Play does impose requirements on VPN apps. To remain in the store, they must declare their use of Android’s VPN service and encrypt data between the device and the VPN endpoint, follow Google’s user-data and malware policies, publish a privacy policy, and complete the Data safety form. Google also says that it reviews apps for compliance with its policies. From a user’s perspective, this understandably looks like Google has checked that the app is safe.

The problem is that these checks are far less comprehensive than the labels suggest. The Data safety section is largely a self-disclosure completed by the developer — not the result of Google independently examining everything the app sends. Google’s own documentation states: “You alone are responsible for making complete and accurate declarations in your app’s store listing on Google Play”. Google may act when it discovers a discrepancy, but it does not claim to verify every declaration before users see it. So, what may look like Google’s seal of approval in fact is little more than a developer’s word. Worse still, instead of providing transparency, these declarations can give a false sense of security.

For example, the current Google Play Data safety page for VPN Proxy Master says that data is encrypted in transit and displays an “Independent security review” checkmark. Yet the version examined by the MVPNalyzer researchers was flagged for unencrypted traffic, tracking, and VPN traffic that was easy to identify.

Google Play’s current Data safety page for VPN Proxy Master, captured on July 30, 2026.

The researchers tested the app in November 2024, while the listing was updated in July 2026, so the current version may differ.

Google’s Verified badge is more meaningful. To earn it, a VPN provider must undergo a Mobile Application Security Assessment at Level 2, or MASA Level 2. This is the higher of the program’s two assurance levels: instead of relying mainly on the developer’s answers, a Google-authorized lab manually tests the app against an international mobile-security standard. AdGuard VPN passed this assessment too. That is certainly more reassuring than self-disclosure, but it still covers a particular version at a particular time — not every server request or future update.

Then there is the metric that may be most persuasive of all: install count. A VPN with 100 million downloads feels tried and tested. But even when the number is genuine, it is no guarantee that the app works properly or keeps its privacy promises. And the count itself can be heavily inflated. As the study showed, popularity tells you how far a VPN has spread — not how well it protects you.

If the product is free, you are likely the product

Free VPNs do not run on good intentions alone. Servers, bandwidth, development, and maintenance all cost money, so if users are not paying the bill, someone else must be, and, more often than not, it would be advertisers or companies interested in user data.

This does not make every free VPN unsafe. Some providers offer a limited free version supported by subscriptions. AdGuard VPN’s free plan, for example, includes 3 GB of monthly trafficfour server locations, and support for two devices, while paid users get unlimited traffic and more locations.

So how do you separate a reasonable free plan from a privacy trap? Here is a quick cheat sheet for choosing a VPN:

  • Google its name. Search for the VPN and its owner alongside words such as “breach,” “leak,” “privacy,” or “scam.”
  • Find out who runs it. A real company should have a proper website, clear contact details, and some history. A developer offering dozens of nearly identical VPNs under generic names is a red flag.
  • Check how the free version makes money. The provider should explain whether it relies on subscriptions, advertising, or something else. Its privacy policy should also clearly say what data it collects.
  • Look beyond ratings and downloads. Read recent reviews, especially the negative ones, but remember that even millions of installs and a high score cannot prove that a VPN is safe.
  • Check its permissions. If a VPN wants access to your contacts, photos, microphone, or precise location without a convincing reason, choose another one.

None of these checks takes long, but together they can tell you far more than a download count or a shiny badge. Before handing a VPN the keys to your internet connection, it is worth finding out who is standing on the other side. A VPN should give you one less thing to worry about, not add another one to the list.

reddit.com
u/shwrellia — 22 hours ago
▲ 16 r/Adguard

Any filter to block Reddits embedded Ads? (Web and/or iOS App)

Hi,

I am looking for a Filterlist which blocks Reddit's App and/or Webads. Is there any?

Cheers

reddit.com
u/Electrical_Region741 — 3 days ago

Adguard not working?

Title. adguard is not blocking ads in pixiv and insta. there are times where i have to turn it off and on and sometimes doing that doesn't fix anything.

i checked the app, battery restriction is turned off, background activity is on, app is also locked. provate dns is turned off

am i doing something wrong or am i just dumb?

Device: POCO X6Pro

OS: HyperOS 3.0.8.0

reddit.com
u/reisentei41 — 3 days ago
▲ 10 r/Adguard+1 crossposts

built an Adguard High Availability controller

Hi team, in case any of you are homelabbers and running multiple versions of Adguard Home, or want too, I built something to make it super easy to manage.

It's a DNS Controller specifically for Adguard Home, can support a cluster of nodes, in a central control plane, giving you the ability to push configs to all nodes at once, read the stats, logs etc in a central place from all nodes, revert configs, etc. a real HA controller.

It doesn't affect the DNS operations at all, all traffic is still via your nodes.

check it out at https://github.com/benchristian88/atlas-dns if you are keen to try it out.

I built it because I wanted it, no product validation, no other user feedback, just felt like something I wanted. Hope someone finds it useful.

u/vive-le-tour — 4 days ago

Got issues with private dns on android when connect to wifi.

Only private AdGuard dns has issue. Public Adguard dns and other dns are working fine. I tried disabling all filters, user rules and access settings but it still isn’t working.

Anyone know how to fix?

reddit.com
u/Kaylenio — 4 days ago

Is there any way i can use youtube and spotify ad free?

I have galaxy tab s9 fe plus and I use brave browser but it sucks in tablet

Is there any way I can use ad free apps ?

reddit.com
u/gyanei — 5 days ago

Most of the location (98%) shown & detecting as Russia with Russian IPs

As the subject said.

this is very annoyed as most of the location only showing Russian IPs and detected by all the sites as Russia ???

pls fix this error as its repeating regularly ... connect to Austria and get Russia

Most of the Location are the same Russian IPs..

waiting the support and fix soon....

reddit.com
u/Ok-Pin-1498 — 5 days ago

ad-guard selfhosted

hi how are you guys recently i install ad-block on my mini server it blocked some ads but in an online media player you know it i get an ad in the middle of the video so its every 4min of time watching i have on my DNS blocklist Hagezi pro and pro++ and couple more from ingenuity GPT mind you i rookie to those things basically my goal was when am outside using cellular data i want to block it so i download Tailescale log in my account the same as the server i go to GPT he destroy half of what i did then spend too much time with him fixing it and i did if you run into the same things i would very much appreciate it

reddit.com
u/SpellFine2263 — 5 days ago
▲ 1 r/Adguard+1 crossposts

nothing is working

https://preview.redd.it/6iyse02dkajh1.png?width=1371&format=png&auto=webp&s=1d95721e7d5db440f2ea8f3a1d71a8286fe00402

My AdGuard just went down and started not working like this, so then I switched to Firefox + uBlock Origin, same thing downloaded it TODAY so everything is updated I don't know what's the issue, and I just wanna watch videos without ads I did everything multiple times, and nothing is working same issue I even just made a reddit account to find out what the hell is going on

reddit.com
u/highsiiiiiiiii — 6 days ago
▲ 68 r/Adguard

The team behind uAssets, the filter lists used by uBlock Origin, says it will stop fixing ad-blocking issues on Facebook

The team behind uAssets, the filter lists used by uBlock Origin, says it will stop fixing ad-blocking issues on Facebook. They say Facebook keeps finding ways around new fixes, making the work increasingly difficult to sustain.

This won’t affect AdGuard’s Facebook filters. We maintain our own rules and will continue updating them.

There’s nothing to celebrate here. It shows how hard it is for small, often volunteer-run teams to keep up with tech giants — and how important their work is for everyone who wants more control over what they see online.

reddit.com
u/shwrellia — 8 days ago

Do i need separate subscriptions for Mac & phone?

I purchased a subscription through my iPhone, but when I try to use my MacBook, it says it’s not connected and I have no licenses purchased whatsoever. so my question is, is the subscription actually for multiple devices or is it specifically for multiple mobile devices?

reddit.com
u/Working_Advice_5097 — 6 days ago

It's too hard to create custom filters

When using Adguard on Android, it's just so hard to create a custom filter. The assistant log is useless. I have no idea what allowed item is causing an element on a web page to show. I like using Chrome, but if a site has a weird pop-up or annoyance I want to block, I have to send the website from Chrome to Brave and use the remove elements option and then copy the rule into Adguard to even have the slightest idea.

Like for example, the assistant is useless in determining that the stupid next article button that takes up half the side of my screen is this

www.androidcentral.com###click-to-next-forward

How am I supposed to know this without the help from yet another outside app?

I'm just venting that I was hoping they'd create an element picker or rule creator in the built in browser so that if I find something I need to block I can just open it in the built in browser real quick, select it, and it automatically creates a user rule and saves it in the Adguard user rules list.

reddit.com
u/Responsible-Field653 — 7 days ago

Netflix ad tier and Ad Guard - recent changes???

I've been using ad guard on my mac with firefox mozilla browser to watch my netflix ad tier shows. Zero commercials - until today. So now it's not working apparently. Any idea why? or is anything else works? thx

reddit.com
u/Koffenut1 — 8 days ago
▲ 10 r/Adguard

Adguard VPN Auto connect feature

It would be great to see a VPN Auto connect feature for untrusted networks. Like most other VPN apps have.

Or auto disconnect on trusted networks. Either way.

Maybe an auto connect to fastest location feature too. The VPN requires too much interaction.

reddit.com
u/Responsible-Field653 — 7 days ago
▲ 24 r/Adguard

What happened to the WireGuard support?

I bought the long term AdGuard VPN license because they had promised the WireGuard support. But still after three years, no signs of it. On top of it, they removed WireGuard coming soon from the website as well. Should I request for a refund?

reddit.com
u/BUHx192Ck0 — 10 days ago

Adguards private browsers not working

Adguard private browser not working on 4.13.1 is there a patch that I could download that might fix this issue thank you for all help.

reddit.com
u/Individual-Sport-458 — 8 days ago

Adguard android blocking all traffic after android update

I have used Adguard on my Pixel 8 Pro for a few years now without any issues but since I installed the last update I'm having an issue with all traffic being blocked, both in Firefox and Chrome, and also on the Reddit app.

My phone has Android 17 build number CP2A.260805.005 installed.

Does anyone know what could be causing this and have any suggestions for how to fix this?

reddit.com
u/litli — 8 days ago
▲ 0 r/Adguard+1 crossposts

Ad Guard Home (Docker) not resoling host names for clients (on Unifi)

I have a UDM. On one of my servers, I am running the Ad Guard Home docker. Everything is working properly. Ad Guard's Query Log shows me client IPs.

I want it to show hostnames.

I have 3 VLANs on my UDM and I created 3 clients with those IP ranges.

I have it configured to rerverse lookup private IPs.

Not sure what is wrong?

I have added screenshots to https://imgur.com/a/coyfZ0M.

u/imthenachoman — 11 days ago