How free VPNs make money — four answers, and a checklist
Servers and bandwidth cost real money, so "unlimited and free" has to be paid for somehow. The four business models behind free VPNs, and four questions that tell you which one you are looking at.
Worth its own article, because the answer decides whether you press install.
Some arithmetic first. A server capable of carrying proxy traffic costs a few dollars a month. Bandwidth is the real expense — ten thousand users at 10 GB each is 100 TB, and at standard cloud egress rates that is a four-figure monthly bill in dollars.
So when an app advertises unlimited data, no signup, completely free, the immediate question is: who is paying that bill?
Four business models
1. Advertising — the benign one
You watch a video before connecting, or the client carries banners.
Easy to spot and not especially harmful. At least it is happening in the open. I lasted two days with one that demanded thirty seconds of video per connection.
2. Your device becomes somebody's exit node
More subtle and considerably worse.
While you are not using the app, your device carries other people's traffic. Their activity leaves through your home connection, under your IP address.
If someone does something illegal through it, the first door investigators knock on is yours.
Hola was caught running exactly this model in 2015; security researchers found the user network was also being resold. Its reputation never recovered.
3. Selling data
DNS queries, domains visited, timestamps, device model, OS version, advertising ID — packaged and sold to data brokers.
The thing to internalise: a VPN provider sits astride all of your traffic. Everything your ISP cannot see, they can.
Reputable providers constrain themselves with a no-logs policy and pay an auditor to verify it. An anonymously registered free app with no identifiable operator has nothing constraining it at all.
4. It is malware
The worst case. Academic scans of Android VPN apps keep surfacing the same problems:
- Permissions with no relationship to the function (contacts, SMS)
- Embedded third-party trackers
- Some traffic transmitted without encryption
- Outright malicious payloads
These are reproducible research findings, not folklore.
Why the reputable free tiers are different
Proton, Windscribe and hide.me are usable for one structural reason: they have a paid product.
The free tier is the top of an acquisition funnel. Use it, like it, upgrade.
Under that model, selling user data is suicide. One exposure and the paying customers leave. Their commercial interest and your privacy interest point the same way.
That is the whole test: what pays for this, and would selling me out destroy it?
The four-question checklist
Run any free service through these. Fail two, do not install it.
1. Is there a paid product?
Yes → the free tier is probably acquisition. Reasonable odds. No, and it advertises unlimited free data → be suspicious.
2. Can you identify the company?
Look for a company name, registered address and contact details. If there is no identifiable entity, there is nobody to complain to when something goes wrong.
Jurisdiction matters too. The EU, Switzerland and Canada come with privacy law attached. An untraceable offshore address does not.
3. Is there an independent audit?
Serious providers pay a security firm to examine their no-logs claim and publish the report.
Published audit → significant point in its favour. A no-logs sentence with nothing behind it → marketing copy.
4. What does the privacy policy actually say?
Search it for: share, partner, third party, affiliate, aggregate.
"We may share aggregated data with partners" leaves the definition of aggregated entirely in their hands.
Free nodes are a different risk model
Everything above concerns free VPN apps. Free nodes and subscriptions — the approach used where those apps do not work — carry a different shape of risk:
- Better: there is no proprietary client. You use Clash, sing-box or another open-source client, so the software itself is not the threat.
- Worse: you have no idea who runs the server, and they can still see your traffic metadata.
Which lands on the same conclusion: keep accounts that matter off nodes you cannot vouch for.
Full breakdown: Is using free nodes safe?
What I do
Two lanes:
- Browsing, reading, research → free nodes. There is nothing there worth taking.
- Any login, any file transfer, anything related to work → the paid line only.
The separation costs about four dollars a month. Best value security spending I do — more useful than any software I could install.
Read next
- Free VPNs that still work in 2026
- Do free VPNs work in China?
- Is using free nodes safe?
- Luobo Cloud after three months
Questions people keep asking
Are all free VPNs unsafe?
No. Free tiers from companies with a paid product (Proton, Windscribe, hide.me) are funded by subscribers; the free tier is customer acquisition, and selling user data would destroy the business that pays for it. The dangerous category is apps with no paid product that still advertise unlimited free data — that revenue has to come from somewhere.
How can I tell whether a free VPN is trustworthy?
Four questions. Does it have a paid product? Can you identify the company and where it is registered? Has an independent auditor examined the no-logs claim? And does the privacy policy contain the words "share", "partner" or "affiliate"? Fail two and walk away.
What is the realistic worst case?
Ranging from mild to severe — ad saturation, browsing history sold to data brokers, your device used as an exit node so someone else's activity traces back to your address, and at the far end, credentials intercepted where traffic is not properly encrypted.
Does a no-logs claim mean anything?
Only with evidence behind it. A no-logs sentence on a homepage is marketing copy. A published third-party audit is a claim someone staked their name on. The difference matters more than the wording.