There are several hundred VPN apps available right now, and no comparison site, including this one, has tested them all. We’ve reviewed and scored close to 50 providers based on real testing. If the VPN you’re looking at isn’t one of them, that doesn’t automatically make it bad. It means you need to do the checking yourself.
Here’s exactly what to look at before you install or pay for a VPN we haven’t covered.
Why this matters more than it sounds
A VPN sits between you and every website you visit. It sees your traffic before your ISP does. A trustworthy provider encrypts that traffic and throws away what it doesn’t need. An untrustworthy one can log it, sell it, or leave it exposed.
The scale of the problem is well documented. A widely cited CSIRO analysis, re-verified in 2024, found that 38% of free VPN apps on iOS and Android contained malware, 75% used third-party tracking libraries, and 18% didn’t encrypt traffic at all. A 2026 update from Comparitech found 84% of free VPN apps leak identifiable data through DNS, IPv6, or WebRTC channels, the exact kind of leak a VPN exists to prevent. Earlier this year, Urban VPN Proxy, a free service with roughly 6 million users, was caught logging and forwarding full AI chat sessions, including ChatGPT and Claude prompts, to undisclosed third parties.
None of that means every unfamiliar VPN is dangerous. It means the burden of proof is on the provider, not on your assumption that an app store listing equals safety.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
The checklist: what to verify before you trust it
1. Who actually owns it
Search the company name plus “owner” or “parent company.” A legitimate VPN discloses who runs it, where they’re incorporated, and ideally has a history you can trace. If the “About” page is empty, the company is a shell registered a few months ago, or the ownership is deliberately obscured behind a chain of holding companies, treat that as a real problem, not a formality.
2. Where it’s legally based
Jurisdiction determines what a government can compel the company to hand over, and whether it’s allowed to tell you when that happens. Panama, Switzerland, Sweden, and Iceland have no mandatory data retention laws and sit outside the Five/Nine/Fourteen Eyes surveillance alliances. The US, UK, and Australia don’t offer the same protection. A VPN that hides its jurisdiction entirely is a bigger red flag than one based somewhere imperfect but disclosed.
3. What the privacy policy actually says
Open it and read the data collection section specifically, not the marketing summary. A credible policy names exactly what isn’t stored: no IP addresses, no connection timestamps, no DNS queries, no per-session bandwidth data. Vague language like “we value your privacy” or “minimal data collection” without specifics is the industry’s most common way of saying nothing at all. If the policy is a 404 error, missing entirely, or clearly copy-pasted from another company (typos, mismatched product names), stop there.
4. Whether an independent audit exists
Search the provider’s name plus “audit.” A real audit is conducted by a named security firm (Deloitte, Cure53, KPMG, PwC, Securitum) and covers the actual server infrastructure, not just a review of the app’s interface. No audit doesn’t automatically mean the provider is lying, but it does mean you’re taking their word for it with nothing to check it against. See our full guide to verifying no-logs claims for how to read an audit report properly.
5. What permissions the app requests
On mobile, check what the app asks for during installation. A VPN needs network and VPN configuration permissions. It has no legitimate reason to request your contacts, SMS messages, camera, or microphone. If it asks anyway, that’s a request for data the app doesn’t need to function, which is exactly the pattern behind most fake VPN apps.
6. Where you’re downloading it from
Official app stores (Apple App Store, Google Play) run at least baseline review checks. A VPN distributed only through a direct APK download, a third-party app store, or a link from an ad has skipped that layer entirely. Sideloaded VPN apps are disproportionately represented in malware research for a reason.
7. What existing users say, and where
Check Trustpilot, the app store reviews themselves, and a search for the provider’s name on Reddit (r/VPN and r/vpnreviews are both active). Look specifically for patterns: recurring complaints about billing that’s hard to cancel, sudden mass one-star reviews around a specific date (often a sign of a breach or policy change), or accounts describing the exact same wording, which suggests fake reviews.
8. How you’re expected to pay and whether refunds are honored
A provider that only accepts cryptocurrency with no other option, or that makes cancellation deliberately difficult (hidden inside account settings, requiring a phone call), is optimizing for revenue capture over trust. A visible refund policy with a real time window is a basic sign of a business that expects to keep customers by being good, not by trapping them.
Immediate red flags, no further checking needed
Some signals are disqualifying on their own:
- The app requests permissions unrelated to VPN function (contacts, SMS, microphone)
- No privacy policy, or one that’s a broken link
- The company’s identity or location can’t be found anywhere
- It’s free, unlimited, and has no visible business model (data monetization is the likely answer)
- Branding that closely imitates a known VPN with a slightly misspelled name or lookalike logo
- Aggressive pop-up ads or urgency language (“your device is at risk, download now”)
Any one of these is enough to walk away. You don’t need to finish the rest of the checklist.
Names you’ll actually run into, and what’s known about them
These aren’t on our comparison table, either because they didn’t pass testing, they’re bundled products rather than standalone VPNs, or we simply haven’t finished reviewing them. Run the checklist above on any of them yourself. Here’s what’s publicly documented as a starting point.
Turbo VPN. One of the most-installed free VPN apps on Android. Security researchers at Top10VPN and TroyPoint have documented DNS leaks and unsafe permission requests, and reporting has linked its distribution to a Chinese cybersecurity firm sanctioned by the US government over alleged ties to the People’s Liberation Army. Free, high install count, and a documented leak history: treat with real caution.
UFO VPN. In 2020, security researchers at vpnMentor found UFO VPN was part of a cluster of Hong Kong-based, white-label “no-log” apps (alongside FAST VPN, SUPER VPN, Flash VPN, Secure VPN, and Rabbit VPN) that shared the same backend and left 1.2 terabytes of user data, including emails, IP addresses, and plaintext passwords, exposed on an unsecured server. The “no logs” claim and the actual logging didn’t match.
SuperVPN. A separate incident in 2023 exposed a database of roughly 360 million records tied to SuperVPN users, including IP addresses, geolocation, and browsing history. Not a one-off: this is the second major SuperVPN-linked exposure in three years.
Hola VPN. Free and peer-to-peer: instead of routing your traffic through Hola’s own servers, it routes other users’ traffic through your device, and sells that bandwidth commercially through its Luminati/Bright Data brand. In 2015, someone bought access to that network and used Hola users’ IP addresses to help run a DDoS attack. If you install this, your connection isn’t just protected, it’s also for sale.
Avast SecureLine VPN and AVG Secure VPN. Both now sit under Gen Digital (the merged Avast/AVG/Norton/LifeLock group). Neither has a published independent no-logs audit as of this writing, which puts them behind the providers on our table that do.
McAfee Safe Connect. Worth knowing precisely because it cuts the other way: McAfee’s bundled VPN runs on TunnelBear’s infrastructure, a provider that is on our comparison table and has a history of regular, published audits. The underlying plumbing here is more credible than the antivirus branding on top of it might suggest.
Kaspersky VPN Secure Connection. Kaspersky itself was banned from sale in the US in 2024 by the Department of Commerce, which cited the Russian government’s legal ability to compel Kaspersky to hand over or manipulate customer data. That’s a jurisdiction risk specific to Kaspersky as a company, and it applies to the VPN product too.
Opera’s built-in browser VPN. Marketed as a free VPN inside the Opera browser, but it’s a proxy that only encrypts traffic inside the browser itself, not your whole device, and Opera has stated it uses browsing data for advertising. Useful to know if you assumed “VPN” meant the same protection as a standalone app.
None of this is a comprehensive verdict on any of these products today; policies and ownership change. It’s what a first check of each turns up, and exactly the kind of check step 4 above walks you through for anything not on this list. We keep a longer, alphabetical version of this running list in our VPN name directory.
The ten-minute version
If you don’t have time for the full walkthrough, run this shortened version: search the provider’s name plus “audit,” search the name plus “data breach” or “lawsuit,” open the privacy policy and scan the data collection section for specifics rather than slogans, and check what permissions the app requests before installing. Four searches, ten minutes, and you’ll know more than the app store listing tells you.
When it might still be worth the risk
Occasionally a smaller or newer VPN is genuinely fine, just under-marketed. Independent providers without a large budget for audits or PR aren’t automatically worse than the household names, some are excellent and simply haven’t been reviewed yet by sites like this one. The difference is whether the provider is transparent about what it doesn’t have (no audit yet, small team, newer company) versus obscuring basic facts about who runs it. Transparency about limitations is a good sign. Silence about ownership and jurisdiction is not.
If a VPN isn't on a comparison site's list, don't treat that as a verdict either way. Check ownership, jurisdiction, the actual wording of the privacy policy, whether an independent audit exists, and what permissions the app requests. Any provider that fails more than one or two of these has told you enough. If you'd rather skip the research entirely, our full comparison table covers close to 50 providers we've already tested against these exact criteria.
See NordVPN, audited six times and one of the few providers with a fully public track record or try ProtonVPN’s free tier, which skips the free-VPN business model problem entirely by also selling a paid product.
Keep reading: How to Choose a VPN in 2026: 7 Criteria That Matter and How to Verify a VPN’s No-Log Policy: What Actually Counts as Proof.