Free VPN — who needs it and why
The word "free" attracts people. It's a basic principle of marketing and human psychology: if you can get a feature without paying, why not try it? VPNs are no exception. App stores are full of apps labeled "free VPN", and the first search results are reviews of "the best free VPNs of 2026".
But in the world of technology, nothing is truly free. Development, server maintenance, paying for traffic, team salaries — all of this costs money. If you don't pay for a product with money, you pay with something else. In the case of free VPNs, that currency is your data.
In this article, we'll look in detail at how the free VPN business works, what risks they carry, and what to look out for when choosing a VPN provider.
How free VPNs make money: business models
To understand the risks, you first need to understand where the money to run a free service comes from. There are several main monetization models, and they often combine with each other.
1. Selling data to advertisers
This is the most common model. A free VPN collects information about your online behavior — which sites you visit, how often, at what time, from which devices — and sells this data to ad networks. Advertisers get the ability to show you the most targeted ads.
A 2021 study by the Commonwealth Scientific and Industrial Research Organisation (CSIRO) showed that 75% of free VPN apps for Android contain trackers for data collection. Some apps sent information to dozens of different servers, including analytics platforms and ad networks.
At the same time, the user often has no idea that their data is being sold. In the user agreement, such information is usually phrased vaguely: "we may share anonymized statistics with partners". But in practice, "anonymization" often turns out to be conditional.
2. Injecting ads and tracking scripts
An even more direct way to monetize is embedding ads into web pages. Free VPNs often modify web traffic, adding ad banners, pop-ups or tracking scripts to pages.
This isn't just inconvenient — it's dangerous. Modifying web pages creates vulnerabilities. In 2020, researchers found that several popular free VPNs embedded JavaScript code that could track user input, including logins and passwords.
In addition, embedded ads are often used as an attack vector. Some ad scripts redirect users to phishing sites or trigger malicious software downloads.
3. Selling bandwidth
This is one of the most covert and dangerous ways to monetize. The VPN provider uses your internet connection as part of its infrastructure, passing other users' traffic through your device.
In 2015, it became known that Hola VPN — one of the most popular free VPNs with tens of millions of users — sold its users' bandwidth through its subsidiary Luminati. In effect, every device with Hola VPN installed became a node in a botnet network through which other people could buy internet access. This meant that strangers' traffic went through your home IP address — and you didn't know about it.
Beyond the ethical side, this approach creates serious legal risks. If traffic related to illegal activity passes through your connection, responsibility can be placed on you — because formally the IP address belongs to you.
4. Premium model with limits
Some VPNs work on a freemium scheme: basic features are free, but with limits on speed, traffic or the number of servers. To remove the limits, you need to buy a subscription.
This model is the most honest of those listed, but there's a catch here too. The free version often works as "bait" and may collect the same data as completely free VPNs. The only difference is that paying users get more features and, possibly, a stricter privacy policy.
What exactly free VPNs collect
The list of collected data depends on the specific provider, but on average free VPNs may record the following:
- Browsing history — which sites you opened, which pages you viewed, how much time you spent on each resource
- DNS queries — information about which domains you requested, which reveals the context of your behavior even when using HTTPS
- IP addresses — your real IP, as well as the IP addresses of connected devices on the local network
- Connection metadata — connection time, volume of transferred data, session durations
- Device information — device model, OS version, unique identifiers, browser type
- Geolocation data — your approximate location based on IP address or GPS
- Wi-Fi network information — the names of networks the device has connected to
Taken together, this data makes it possible to recreate a detailed user profile: habits, interests, financial situation, political views, health status and much more.
Even if a VPN uses encryption, that doesn't mean your provider can't see your actions. Encryption protects traffic from third-party observers, but the VPN server itself is the point through which all your traffic passes. The provider sees everything — if, of course, it collects that data.
Real incidents and leaks
The risks of free VPNs aren't theory. There are many documented cases of data leaks and privacy violations.
VPN Super Unlimited Proxy data leak
In 2024, security researchers discovered that the database server of VPN Super Unlimited Proxy — one of the most downloaded free VPNs in the App Store — was accessible without a password. As a result, more than 21 million records ended up in the open, including users' IP addresses, names of files they downloaded, and website URLs.
This leak demonstrated two key problems: first, a free VPN may not have the resources to ensure the security of its own infrastructure; second, user data can be stored without encryption.
Malware apps
In 2020, Cisco Talos published a study in which three free VPN apps for Android were found to contain malicious code. The apps Super VPN, Flash VPN and Secure VPN were removed from Google Play after discovery, but by that point they had been downloaded by more than 1.2 million users.
The malware intercepted DNS queries and redirected users to phishing sites. Some apps also collected excessive device information, including serial numbers and contact data.
Mass privacy policy audits
Regular studies of free VPN privacy policies show alarming statistics. Periodic Google Play store audits identify dozens of apps that:
- Collect more data than necessary for VPN operation
- Transfer data to servers in China, the UAE and other jurisdictions with limited privacy
- Don't encrypt user data at rest
- Have no "no-logs" policy, or claim one but actually keep logs
The "you are the product" concept
The famous phrase "if the product is free, then you are the product" applies fully to free VPNs. There's no alternative: maintaining server infrastructure, bandwidth, app development and support — all of it requires real costs. If the user doesn't pay for these costs directly, the company must cover them with something else.
In the context of VPNs, this is especially dangerous because a VPN service has access to the most sensitive user data. You entrust it with all your internet traffic — including bank logins, correspondence, medical data, work information.
When you use a free VPN, you're effectively handing control of your internet connection to a company that's interested in monetizing your data. It's a paradox: a tool that should protect your privacy becomes its main threat.
Technical security risks
Besides privacy issues, free VPNs often suffer from serious technical vulnerabilities.
Weak or missing encryption
Some free VPNs use outdated encryption protocols or don't encrypt traffic at all. Others claim to use AES-256 but actually apply less reliable algorithms, because encryption requires computing power, and free providers seek to minimize infrastructure costs.
Research regularly finds free VPNs that:
- Use the PPTP protocol, which has been considered insecure since 2012
- Don't support Perfect Forward Secrecy
- Use static encryption keys that can be compromised
- Don't encrypt DNS queries, leaving a DNS-leak vulnerability
No Kill Switch
The Kill Switch feature automatically disconnects the internet if the VPN connection drops. This is a critical feature, because without it your real IP address and unencrypted traffic can be exposed in the split second before reconnection.
Most free VPNs don't support Kill Switch. This means that on any connection failure, your real identity and traffic become available to the provider, government agencies or cybercriminals.
Shared IP addresses
Free VPNs often use a shared pool of IP addresses for many users. This creates a problem not only for privacy — a site may block you because another user of the same IP behaved suspiciously.
WebRTC leaks
Browsers with WebRTC support can reveal your real IP address even through a VPN. Reliable VPN providers offer protection against WebRTC leaks. Free services usually don't bother with this, because it requires developing special browser extensions or configuring client software.
Legal and regulatory risks
Using a free VPN creates legal risks that many people don't think about.
First, if a free VPN sells your traffic to third parties (as in the Hola case), your IP address is formally associated with you. If illegal activity is carried out through that IP, law enforcement will come to you — because the IP belongs to your provider.
Second, many free VPNs are registered in jurisdictions with minimal data protection regulation. This means you have virtually no legal tools to protect yourself if your data is misused.
Third, some free VPNs violate the terms of use of popular services. For example, if you use a free VPN to bypass geo-restrictions on streaming services, it can lead to your account being blocked.
How to evaluate a VPN provider
When choosing a VPN service, it's worth paying attention to several key factors. This will help distinguish a reliable service from a potentially dangerous one.
Monetization model
The first and most important question: where does the money to run the service come from? If a VPN is free and has no obvious way to monetize — that's a serious red flag. A company can't operate at a loss forever.
A paid VPN with a transparent business model is the first sign of reliability. You pay for the service, and the company is interested in providing you with quality service rather than selling your data.
No-logs policy
A no-logs policy means the VPN provider doesn't store or keep records of your online activity. This is a critical feature, because even if the data is requested by a third party (a court, a government body), the provider simply won't have anything to provide.
But it's important to understand: no-logs policies differ. Some providers declare one, but actually keep logs. The best way to verify is an independent audit.
Independent audit
Reputable VPN providers regularly conduct independent audits of their infrastructure and privacy policies. Audit results are published for public access. If a provider hasn't been audited, that isn't necessarily a red flag, but having an audit significantly increases trust.
Jurisdiction
Where is the VPN provider registered? In which jurisdictions are its servers located? This matters because data protection laws differ between countries. Five Eyes jurisdictions (US, UK, Canada, Australia, New Zealand) and Fourteen Eyes (an expanded list including Germany, France and other countries) are considered less private.
Encryption protocols
A reliable VPN must use modern protocols: WireGuard, OpenVPN or their derivatives. Outdated protocols (PPTP, L2TP without IPsec) don't provide a sufficient level of security.
Transparency
Pay attention to how the provider communicates with users. A transparent company publishes information about its team, place of registration, financial reports (where possible), and audit results. Secrecy and lack of information is always a concerning factor.
What a reliable VPN does
To sum up: a reliable VPN service should meet several basic criteria:
- Paid model — you pay for the service, and the company doesn't need to monetize your data. This creates the right incentive: to earn from service quality, not from selling users.
- Strict no-logs policy — the provider doesn't collect or store data about your online activity. Ideally, this should be confirmed by an independent audit.
- Modern encryption — using current protocols (WireGuard, OpenVPN), encrypting DNS queries, protection against WebRTC and IPv6 leaks.
- Kill Switch — automatic internet disconnection when the VPN connection drops.
- Transparent privacy policy — clear, simple wording without legal ambiguity. Information about what data is collected (if any), why and how it's used.
- No embedded ads or trackers — the service doesn't modify web traffic or embed third-party code into pages.
- Modern protocols — support for WireGuard, OpenVPN or proprietary improved solutions based on them.
The Plan B approach
"Plan B" is built exactly on the principles described above. We believe a VPN is a tool of trust, and trust is built on transparency.
Here's how it works in practice:
- Paid subscription. We honestly say: we earn from subscriptions. This means our only client is you. We don't need to sell your data to advertisers because you've already paid for the service. The interests of the company and the user coincide.
- No-logs policy. We don't keep logs of your online activity. We don't know which sites you visit, what you download, or who you correspond with. This isn't a marketing slogan — it's the operating principle of our infrastructure.
- AmneziaWG protocol. We use an improved version of WireGuard that provides modern encryption and high speed at the same time. This protocol was developed with privacy requirements and censorship resistance in mind.
- Minimum data for registration. Only a Telegram account is needed to connect. We don't collect your name, phone number, email or other personal data. Payment via cryptocurrency allows you to remain completely anonymous.
- Simplicity and speed. Connection through a Telegram bot — no complicated settings, server addresses or configuration files. This makes a VPN accessible to people who don't want to dig into technical details.
We're not perfect — no one is. But we strive to make "Plan B" an example of how a modern VPN service should work: honestly, transparently, safely.
Conclusion
Free VPNs are a tempting idea that in practice turns out to be a security compromise. At best, you get a slow connection with limits. At worst, your data is traded, your traffic is modified, and your connection is vulnerable to interception.
Investing in a paid VPN is an investment in your own privacy. It's not a luxury, but a necessity in a world where digital privacy is becoming increasingly fragile. Choose a provider you can trust, and make sure its business model doesn't contradict your interests.
A tool for protecting privacy shouldn't be its threat. Choose consciously.