Is a VPN safe? The real risk is the app
Turning on a VPN doesn't remove the party who can see your traffic — it changes who that party is, from your ISP to the VPN company. The tunnel itself is secure. The risk sits in the app: a 2026 study of 281 Android VPN apps found dozens leaking data, sending it unencrypted, or shipping tracking IDs to advertisers.
Switching a VPN on doesn’t remove the party who can see where you go online. It swaps one for another: your ISP steps aside, and the company that built the app steps in. That’s the real question behind “is a VPN safe” — not whether the tunnel encrypts your traffic (it does; what a VPN is and how it works covers the mechanics), but whether you’d hand the company running the other end of it everything your ISP used to see.
What does “safe” actually mean for a VPN?
The encryption itself isn’t the open question. Malware, phishing, and tracking through accounts you’re already signed into aren’t a VPN’s job either — how a VPN protects you (and what it doesn’t) draws that line in full. “Is a VPN safe” is really asking something narrower: is the specific company that wrote this app, and runs the servers your traffic now flows through, one worth that much access? That question has an answer you can actually check, unlike “is the tunnel encrypted,” which is true of nearly every app on the market and settles nothing.
For most of the providers in our full VPN rankings, the paper trail says yes: a named company, a jurisdiction, and an outside firm willing to put its name on an audit report. For an app pulled at random off an app store, nobody has checked — and a 2026 study of the apps people actually install shows what that looks like in practice.
What can go wrong inside the app itself?
A February 2026 paper — MVPNalyzer, from researchers at the University of Michigan and the University of New Mexico, presented at the NDSS Symposium — tested 281 popular Android VPN apps pulled from the Google Play Store. The ones it flagged account for hundreds of millions of installs between them. The paper’s own framing is the reason this article exists: a VPN app has to intercept all of a user’s traffic to do its job, and that requirement creates what the researchers call a transfer of trust — from whatever was watching a person before, an ISP or a hotel Wi-Fi operator, to the company that wrote the app.
What that trust bought, in this sample, was uneven. Of the 281 apps, 61 transmitted some data with no encryption at all, and 29 leaked user traffic — DNS lookups included — outside the tunnel they exist to build. Another 5 sent the VPN’s own configuration files in cleartext, and 107 skipped basic security practices in how they built those configurations. A further 169 failed to obfuscate traffic well enough to dodge blocking, undercutting one of the reasons people install a VPN in the first place. Tracking was the other common failure: 76 apps transmitted the device’s advertising ID to ad networks — privacy software handing advertisers a durable way to recognize the device. These were live apps on the Play Store when the researchers tested them, not a hypothetical worst case.
Five ways a VPN can be unsafe, and how to check each one
| Failure mode | What goes wrong | What to check |
|---|---|---|
| Traffic leaks outside the tunnel | 29 of 281 tested apps let some traffic, DNS lookups included, travel outside the encrypted tunnel | Run a DNS leak test while connected; if your own ISP's DNS servers show up, the tunnel is leaking |
| Data sent with no encryption | 61 apps transmitted some data completely unencrypted | Look for a named protocol (WireGuard, OpenVPN, IKEv2) in the app's own materials — one that never says how its tunnel is built can't be checked |
| Tracking IDs shipped to ad servers | 76 of the 281 apps sent the device's advertising ID to ad networks — an identifier that survives every IP change a VPN makes | Open the app's Play Store listing, find the Data safety section, and check whether it discloses sharing device or advertising IDs |
| Unaudited no-logs claims | A "no-logs" promise with no outside check behind it is a sentence, not a finding | Search the provider's name plus "audit"; look for a named firm and a report dated within about two years |
| An unverifiable free provider | A free app with no listed company, jurisdiction, or privacy policy has nobody accountable for what it collects | Read the privacy policy page for a real company name and registered address before installing, not just the developer name on the store listing |
Why an audited, paid provider is a different risk class
No independent framework has leak-tested the eight providers we track, so nothing here says they are clean on the failure modes above. What separates them is that there is something to check at all. Six of the eight carry a dated, named no-logs assurance report from an outside audit firm — Deloitte, KPMG, or Securitum — each dated 2025 or 2026. Our guide to no-log VPN audits covers what those reports do and don’t prove. The other two, Mullvad and Windscribe, hold infrastructure security audits instead: Cure53 checked Mullvad’s servers in June 2024, and Packetlabs checked Windscribe’s the same month. Both are real scrutiny of live infrastructure. Neither is a formal no-logs attestation, and neither vendor claims otherwise.
Server design tells a similar story. Every paid provider we track runs RAM-only servers that erase everything on reboot, except one: Proton VPN, audited by Securitum for the fifth year running in 2026, which argues a diskless fleet adds little in practice and instead runs encrypted disks with the keys stored off-site — a published, deliberate choice, not a gap. The most private VPNs ranks the field on exactly this kind of evidence.
Each of the eight is also a company registered somewhere specific — NordVPN in Panama, Proton VPN in Switzerland, Private Internet Access in Colorado, among others — which means there’s a legal entity that can be asked, sued, or audited about what it stores. A free app with no listed company and no privacy policy has none of that: there’s nobody to hold to the no-logs line in its store description.
Only two of the eight run an actual free tier — Proton VPN Free and Windscribe Free, both covered in our best free VPN picks — and both carry the same audit trail as their paid plans. An app marketed simply as “free VPN”, with no paid plan and no named company behind it, is a different proposition — MVPNalyzer’s sample is where that leads: traffic leaking outside the tunnel, or ad IDs sent onward. Free access to a server network costs the company running it money somewhere; when a listing gives no clue where that money comes from, the app itself is the product.
Is a VPN safe, then?
For a named, audited provider, the answer is yes — the tunnel does what it promises, and the company behind it has something checkable to lose if it lies about logging. The risk the MVPNalyzer numbers expose sits somewhere else entirely: unvetted free apps with no audit, no named company, and no reason to tell you the truth about what they collect. How a VPN protects you (and what it doesn’t) covers the separate question of what even a trustworthy VPN can’t fix, and how to choose a VPN walks through the checks worth running before you pay for one.
Frequently asked questions
Is a VPN safe to use?
Generally yes, provided the provider is a named company with a recent, named no-logs audit. The tunnel itself is standard, well-tested encryption; what varies is whether the company running it deserves the traffic you hand it. Unaudited apps with no company behind them are the exception among reputable services, not the rule.
Are free VPNs safe?
It depends entirely on which one. A couple of major providers run a real free tier with the same audit trail as their paid plans and published limits on what they collect. Most other apps marketed as a free VPN on an app store have no comparable audit trail — a 2026 study of 281 Android VPN apps found dozens of them leaking traffic or sending tracking IDs to advertisers.
Can a VPN be hacked?
A VPN app is software, and software has bugs. A 2026 review of Android VPN apps found real ones: apps that leaked traffic outside the tunnel, shipped configuration files in the clear, or skipped basic security practices when building their tunnels. That isn't the encryption protocol failing — it's implementation mistakes in specific apps, which is exactly why a provider's audit history matters as much as which protocol it names.
Can my VPN provider see my activity?
Yes. Your VPN provider sits exactly where your ISP used to sit, so it technically can see your traffic unless it has a policy, and independent proof of that policy, against recording it. Turning on a VPN doesn't eliminate the party that can see your activity — it chooses who that party is.
How do I know if a VPN is safe?
Check four things: a named auditor behind the no-logs claim, a report dated within the last couple of years, a real company you can identify from its privacy policy, and — for the app itself — a Play Store listing that doesn't flag unnecessary tracking permissions in its Data safety section. A provider that clears all four sits in a different risk class than an anonymous free app.
Sources
- NDSS Symposium 2026 — MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNs — accessed
- Proton VPN blog — No-logs audit — accessed
- Proton VPN blog — Why we don't use RAM-only servers — accessed
- Proton VPN — Free plan — accessed
- Proton VPN — Homepage (jurisdiction) — accessed
- Mullvad blog — Fourth infrastructure audit completed by Cure53 — accessed
- Windscribe — Has Windscribe been audited? — accessed
- Windscribe — Use for free — accessed
- NordVPN — No-log VPN (jurisdiction) — accessed
- Private Internet Access — Terms of service (jurisdiction) — accessed