Infrastructure is never free
Every gigabyte you push through a VPN crosses servers someone rents and links someone pays for. A service with millions of users has a large monthly bill, and it has to be covered by something.
Guides
A VPN service pays real money for servers, bandwidth and staff. When the app is free and has no visible income, that money usually comes from you in another form: your browsing data, injected ads, or your device being resold as an exit point for other people's traffic.
Every gigabyte you push through a VPN crosses servers someone rents and links someone pays for. A service with millions of users has a large monthly bill, and it has to be covered by something.
The common ways to monetize a free VPN are selling browsing records to data brokers, inserting ads into your sessions, and reselling your connection. All three work against the reason you installed a VPN.
A trial of a paid service, or a limited free tier from an operator that openly explains its business model, is a different situation. The red flag is unlimited free service with no explanation of who pays.
Somebody always pays. A VPN provider rents servers in many countries, buys transit bandwidth, pays developers and support, and covers app store fees. For a popular service this adds up to a serious recurring cost that does not disappear because the download button says free.
A paid provider covers this with subscriptions, which keeps the incentives simple: you pay money, you get a tunnel, and the provider's interest is keeping you as a customer. A free provider with no subscriptions has to find revenue elsewhere, and the only asset it holds is its users, their traffic and their devices.
The business models behind free VPN apps are well understood, and most of them conflict directly with privacy. The app sits in a perfect position to observe everything you do online, and that observation point itself is the product being sold.
None of these models require the app to be technically broken. The tunnel can work exactly as advertised while the logging happens quietly on the server side, where you have no way to see it.
Independent researchers who analyze free VPN apps in bulk tend to find the same categories of problems again and again: privacy policies that permit sharing traffic data with third parties, embedded trackers from advertising companies, requests for permissions a tunnel does not need, and in some cases no working encryption at all.
Another recurring finding is opaque ownership. Many free apps with different names and logos trace back to the same few companies, so a user comparing options in an app store may be choosing between fronts of one operator.
The specifics vary from report to report, but the pattern is stable enough to treat as the default assumption: a free VPN with no clear revenue source should be presumed to monetize its users until it demonstrates otherwise.
An ad-stuffed app is annoying; a compromised tunnel is dangerous. A VPN app runs with the ability to see and redirect all of your device's traffic. If the operator is careless or malicious, that position can be abused for credential harvesting on non-HTTPS connections, for redirecting you to lookalike pages, or for installing a root certificate that breaks TLS inspection protections.
Abandonment is a quieter risk. Free apps are often side projects: the tunnel keeps running on old server software with known vulnerabilities, nobody answers security reports, and the app silently changes hands when the original developer sells it. You would have no way to notice the new owner has different plans for your data.
With a paid service you at least know the incentive structure and have a counterparty accountable to paying customers. Aurora, for example, publishes what it does and does not log and gives a 14-day refund window, so trying it costs nothing but is not funded by your data.
Free is not automatically a scam. A time-limited trial of a paid service is free precisely because the provider expects some users to subscribe; the economics are transparent. The same goes for a limited free tier — capped traffic or fewer locations — offered by an operator whose paying customers clearly fund the infrastructure.
The distinguishing feature is a visible answer to the money question. If the provider says plainly that free users get a slice of the paid infrastructure as marketing, the incentives are aligned with yours. If the service promises unlimited free bandwidth forever and never explains its income, the incentives are not.
You do not need to be a security researcher to do a basic sniff test. Ten minutes of reading tells you most of what matters, because monetization has to be disclosed somewhere — usually in the privacy policy, in the permissions, or in the company's own marketing to advertisers.
None of these checks needs special tools, and a provider that fails two or more of them has told you enough. Walk away; there is no shortage of alternatives.
In most countries, yes: using a VPN is legal and completely ordinary. Businesses run on VPN connections every day. A minority of countries restrict or license VPN services, and those rules change, so check current local regulation where you live or travel. And a legal tool never legalizes illegal actions done through it.
Yes, a VPN adds some overhead, but how much depends almost entirely on distance and server quality. Through a nearby, uncrowded server on a modern protocol like WireGuard, the loss is often barely noticeable. Through a distant or overloaded server, latency climbs and throughput drops visibly. Sometimes a VPN is even faster.
The classic scare story — someone in a café stealing your password out of the air — is mostly obsolete, because HTTPS already encrypts the content of nearly all your connections. What remains on public Wi-Fi is subtler: visible metadata like domain names, fake access points, captive portals, and other devices sharing the network with you.