Original Research 8 min read

What Free VPN Apps Admit in Their App Store Privacy Labels

How Apple privacy labels and Google Play Data safety sections work for VPN apps, what they reveal about tracking, and why studies find many labels inaccurate.

What Free VPN Apps Admit in Their App Store Privacy Labels

Key Findings

  • In May 2021, 246 of 1,265 iOS apps with 'VPN' in their name (about 19%) declared 'Data Used to Track You' on their Apple privacy labels, according to app-intelligence firm 42matters.
  • A USENIX Security 2023 study of 5,102 iOS apps found 3,423 (about 67%) had privacy labels inconsistent with the data the apps actually sent; User ID, Device ID and location were the data types most often left off.
  • Mozilla's 2023 review of 40 top Google Play apps found discrepancies between Data safety labels and privacy policies in nearly 80% of them.
  • An analysis of 283 Android VPN apps found 75% embedded third-party tracking libraries and 82% requested access to sensitive resources such as accounts and text messages.
  • Both Apple and Google state that developers are responsible for the accuracy of their labels; neither store says it verifies the declarations against app behavior.

App store privacy labels are self-declared summaries of what an app collects, and for VPN apps they often reveal tracking that sits awkwardly next to “no-logs” marketing. In 2021, roughly one in five iOS apps with “VPN” in the name declared data used to track users across other companies’ apps and sites. Independent studies show labels are frequently incomplete, so a clean label alone does not prove that an app is private.

How the two label systems work

Apple introduced privacy labels on App Store product pages in December 2020 (Xiao et al., 2023). Google followed with the Data safety section on Google Play in April 2022 and gave developers until July 20, 2022 to fill it in (Google, 2022).

Both are questionnaires the developer completes. Apple tells developers they are responsible for keeping their answers accurate and current, and lets them change answers at any time without an app update (Apple, 2026). Google is blunter: its help page says the developer alone is responsible for complete and accurate declarations, and that Google cannot make determinations on developers’ behalf about how they handle data (Google, 2026).

FeatureApple App Privacy labelGoogle Play Data safetySource
LaunchedDecember 2020April 2022 (required by July 20, 2022)Xiao et al., 2023; Google, 2022
Main headingsData Used to Track You; Data Linked to You; Data Not Linked to YouData shared; Data collected; Security practicesApple; Google
Third-party SDK data included?Yes, data collected by “third-party partners” must be declaredYes, including data collected through SDKs and librariesApple; Google
Key exemptionData sent to service a request and not retained (for example an IP address on a server call)Transfers to “service providers” are not counted as sharingApple; Google
Who verifiesDeveloper responsible; no verification describedDeveloper “alone” responsibleApple; Google
Optional security signalNone“Independent security review” badge (MASA)BleepingComputer, 2023

What “tracking” means on iOS

Apple defines tracking as linking data from your app with other companies’ data for targeted advertising or ad measurement, or sharing data with a data broker. Since iOS 14.5 in April 2021, App Tracking Transparency has required apps to ask permission before tracking users across other companies’ apps and sites (Apple Newsroom, 2021). A VPN app that shows the “Allow app to track your activity” prompt is telling you it wants to do exactly that.

Stricter rules for VPN apps

Both stores impose extra conditions on VPNs. Apple’s guideline 5.4 says VPN apps may not sell, use or disclose any data to third parties for any purpose, must commit to this in their privacy policy, and must state what user data is collected before a user buys or uses the service (Apple, 2026).

Google’s VpnService policy requires apps to encrypt traffic from the device to the tunnel endpoint, prohibits collecting personal and sensitive data through the VPN without prominent disclosure and consent, and bans redirecting other apps’ traffic for monetization (Google, 2026).

Because of these rules, a VPN label that declares tracking data or data shared with advertisers describes behavior that Apple’s own VPN guideline does not allow.

What VPN apps declare

The largest public snapshot of iOS VPN labels comes from 42matters, an app-intelligence company, which examined every iOS app with “VPN” in its title as of May 20, 2021 (42matters, 2021). We calculated the percentages from its counts; an app can appear in more than one category.

Apple label categoryVPN apps declaring itShare of 1,265 appsSource
Data Used to Track You24619%42matters, 2021
Data Linked to You14211%42matters, 2021
Data Not Linked to You40532%42matters, 2021

The most downloaded app in the tracking group was a free app, VPN - Super Unlimited Proxy, with about 2.5 million global downloads in the previous 30 days by 42matters’ estimate. It shows the clearest gap between marketing and declaration: sold as a privacy tool, the app admits in its own label that it links your data with third-party data for advertising.

On Android, earlier code-level research points the same way. A 2016 study of 283 Android apps using the VPN permission found 75% embedded third-party tracking libraries and 82% requested permissions for sensitive resources such as user accounts and text messages (Ikram et al., 2016). In August 2026, Proton, which sells its own VPN and so has a commercial interest in the finding, reported that 85% of VPN apps downloaded in the US contained trackers detected by the open-source Exodus Privacy tool, and that 64 apps tracked users’ physical location (Proton, 2026). We could not independently verify Proton’s dataset.

How accurate the labels are

Every large study we found reported widespread label errors.

StudyStoreSampleFindingSource
Lalaine (USENIX Security 2023)Apple5,102 iOS apps3,423 had non-compliant labels; 3,281 failed to disclose data or purposesXiao et al., 2023
“See No Evil” (Mozilla Foundation)Google40 top free and paid appsNearly 80% had discrepancies; 16 rated “Poor,” 6 “OK”MediaPost, 2023
Hidden Links (FOCI 2025)Google21 VPN appsOne family’s apps sent users’ IP-derived ZIP code to a Firebase endpoint while privacy policies said no addresses were collectedMixon-Baca et al., 2025

The Lalaine researchers found that User ID, Device ID and location were the data types developers most often left off their labels, and pointed to opaque data collection by third-party SDKs, which developers may not fully understand, as one root cause (Xiao et al., 2023). Mozilla pointed to Google’s service-provider exemption as a loophole that lets apps omit data flows from the “shared” section (MediaPost, 2023).

Why “Data Not Collected” can be honest and still incomplete

Under Apple’s definition, data only counts as “collected” if it is retained longer than needed to serve the request; an IP address sent on a server call and not kept does not need to be declared (Apple, 2026). For a VPN that genuinely keeps no logs, that is fair. But the label is the developer’s own description of its retention, so an app that does keep data can use the same wording. The label cannot show what happens on the VPN’s servers.

Security badges are not privacy labels

Since November 2023, Google Play has highlighted an “Independent security review” badge in the Data safety section for VPN apps that passed a Mobile Application Security Assessment against the OWASP MASVS standard. NordVPN, Google One and ExpressVPN were the first to display it (BleepingComputer, 2023). The badge tests how an app is built; it does not certify the accuracy of the privacy declarations, a provider’s logging, or who owns the company.

What this means for you

  • Read the label before installing. On iOS, scroll to “App Privacy.” On Google Play, open “Data safety.” It takes 30 seconds.
  • Treat tracking as a deal-breaker for a VPN. “Data Used to Track You,” a tracking permission prompt, or data “shared” with advertising partners all contradict the purpose of a VPN.
  • Be skeptical of an empty label. “No data collected” is the developer’s own unaudited claim, and research shows many labels understate collection.
  • Cross-check the privacy policy. Look for named ad networks, analytics SDKs and location data. Contradictions between the policy and the label are a red flag.
  • Check permissions on Android. A VPN rarely needs access to contacts, SMS or precise location.
  • Look for independent evidence. Published no-logs audits and the Play security badge each cover part of the picture; neither alone is sufficient.

Methodology and limitations

The sources are Apple’s and Google’s developer documentation (read in full on the official sites), app-store policy pages, a 2021 dataset from app-intelligence firm 42matters, peer-reviewed research (USENIX Security 2023, ACM IMC 2016, FOCI 2025), Mozilla Foundation’s 2023 study as reported by MediaPost, and a 2026 study from Proton, a VPN vendor. We did not rely on label audits published by VPN review sites.

The 42matters snapshot dates from May 2021, shortly after labels launched, and labels can change at any time without an app update. The general-purpose accuracy studies (Lalaine, Mozilla) did not focus on VPN apps, so their rates should not be read as VPN-specific error rates. The 2016 Android study predates both label systems, and we did not test any app ourselves for this article.

Sources

  1. App privacy details on the App Store — Apple Developer, 2026
  2. App Review Guidelines, sections 5.1 and 5.4 — Apple Developer, 2026
  3. iOS 14.5 offers Unlock iPhone with Apple Watch, diverse Siri voices, and more — Apple Newsroom, 2021-04-26
  4. Provide information for Google Play's Data safety section — Google Play Console Help, 2026
  5. Understanding Google Play's VpnService policy — Google Play Console Help, 2026
  6. Get more information about your apps in Google Play — Google, 2022-04-26
  7. Analysis of Privacy Labels in iOS VPN Apps — 42matters, 2021-05-21
  8. Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels — Xiao et al., USENIX Security 2023, 2023
  9. Mozilla Finds Contradictions Between Google Play Store Data Safety Labels, Privacy Policies — MediaPost, 2023-02-23
  10. An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps — Ikram et al. (CSIRO Data61, ICSI), ACM IMC 2016, 2016
  11. Hidden Links: Analyzing Secret Families of VPN Apps (FOCI 2025) — Mixon-Baca, Knockel, Crandall (ASU / Citizen Lab), 2025-07
  12. Shady VPNs could be spying on millions of Americans — Proton, 2026-08-27
  13. Google Play adds security audit badges for Android VPN apps — BleepingComputer, 2023-11-03
Cite this research: PhantomGuide Research Team, “What Free VPN Apps Admit in Their App Store Privacy Labels”, PhantomGuide, 2026-10-01, https://phantomguide.com/research/vpn-app-privacy-labels/

More Research