Do Free VPNs Sell Your Data?
Some free VPNs are funded by monetising data about their users, and where that is the model it is generally disclosed somewhere — in careful language, but disclosed. “Sell” is usually the wrong word to search for, because the documents say licensed, shared with partners, provided to affiliates, or used for business purposes. The reliable way to answer the question is to find the revenue, not to grep for a verb.
This post is about the buyer side, which most writing on the subject skips. Knowing what app-derived data is actually worth money makes it much easier to tell whether a given service has a reason to collect it.
What the market for app data actually buys
There is an established industry that aggregates data from consumer apps and resells it. Its customers are not usually interested in you individually — they are buying patterns. The recognisable product categories:
App and web usage panels. Which apps and sites are popular, how usage is trending, how long sessions last. Sold to investors, market researchers, and competitors. This is the largest and most boring end of the market, and it is where “aggregated” is closest to being accurate.
Audience segments for advertising. Groups of device identifiers inferred to share an interest or intent, sold for ad targeting.
Location data. Historically the most valuable and most contested category, sold for retail analytics, mobility research, and worse.
Identity and device graphs. Linking identifiers together so that the same person can be recognised across apps and devices.
Fraud and risk signals. Data about which addresses and devices behave suspiciously.
None of that requires reading the contents of your traffic. It is assembled from metadata, identifiers, and event logs — which is exactly the kind of thing an app can collect without doing anything exotic.
Why a VPN app sits in an unusually strong position
A VPN is not a special case in what it can collect at the app level, but it is a special case in two respects.
It sees connection-level activity by construction. To route your traffic, the service is necessarily positioned where the traffic passes. Whether it records anything is a policy decision, not a technical inevitability, but the position exists. What a provider must hold merely to function is a technical question with a well-understood answer; the economic question is whether it holds anything beyond that.
It is installed with elevated network permissions and left running. A VPN profile is a persistent, always-on component that the user is motivated to keep enabled. Continuous presence is worth much more to a data business than occasional presence.
So the incentive is unusually well aligned with the capability. That is a reason for care, not an accusation — plenty of providers are in that position and do not monetise it, because their revenue comes from subscriptions.
Collected to operate versus collected to monetise
This is the distinction that does the real work, and you can apply it yourself. Ask, for each item in a privacy policy’s collection list: does the product need this to function?
Things a service plausibly needs:
- An account identifier, if there are accounts.
- Bytes transferred, to enforce a data cap. This one surprises people, but a capped free tier cannot work without counting.
- Connection success or failure counts for diagnostics.
- Payment records, where there is payment.
- Enough transient state to route your session.
Things a VPN does not need in order to route packets:
- A persistent advertising identifier.
- Precise location, separate from the address you connect from.
- A list of other apps installed on the device.
- Contacts, calendar, or photos.
- Browsing or DNS history retained over time.
- Cross-app event tracking.
A gap between the two lists is the signal. It does not prove the data is sold, but it means the collection exists for some purpose other than delivering the service, and purposes cost money to maintain, so they usually earn it back.
What “aggregated and anonymised” is doing
This phrase appears in almost every policy, and it is not automatically a euphemism — genuine aggregation exists and genuinely does reduce risk. What to watch is how much weight the sentence is carrying:
- Aggregation is a spectrum. Counts across millions of users are one thing; a per-device record with the name stripped off is another, and both get called anonymised.
- Re-identification is a known limitation of stripping identifiers from behavioural records, particularly with location or long histories. Policies that rely on the word without describing the method are asserting a conclusion.
- Ask what is aggregated from. A service that never collected per-user browsing histories has nothing to anonymise. One that describes anonymising them has told you it collects them.
The signals, in order of usefulness
- No paid tier, no ads, no donations, and no parent company. The costs are real and recurring, so something funds them. This configuration is the single strongest indicator that the funding is data-side.
- A collection list longer than the product needs, per the test above.
- Sharing described by purpose rather than by recipient — “business purposes”, “marketing partners”, “affiliates and third parties” — with no categories named.
- An unlimited free tier, for the reasons in the arithmetic of an unlimited free VPN.
- A parent company whose main business is advertising, analytics, or market research. Ownership is usually public; see why who owns the app tells you the business model.
- Store data disclosures that include tracking categories, covered in reading app store data labels.
What to do
If you can identify a funding model that is not data monetisation — a real subscription business, a nonprofit with published funding, a bundle you already pay for — the question is largely answered, and the six models are enumerated in how free VPNs make money.
If you cannot identify one, treat that as the answer rather than as a mystery. Not because every unexplained service is malicious, but because the cost is certain and you have a free choice among alternatives whose economics you can see.
And if a free service is your only option, prefer one from a company with paying customers, keep the app updated, deny permissions it does not need to function, and remove it when you are not using it. That is a reasonable position to be in; when a free VPN is actually fine covers where it genuinely works.