
A months-long investigation by Proton into more than 7,000 mobile VPN apps has found that 85% of the VPNs downloaded in the United States contain tracking components, while roughly a quarter of the analyzed services collect users’ physical location.
The company also identified dozens of VPN apps linked to Chinese owners, including many that allegedly obscure their ownership through overseas corporate entities.
Proton examined VPN apps available through Google Play and Apple’s App Store, using download estimates from mobile-app intelligence provider AppTweak and tracker data from Exodus Privacy, an open-source project that detects analytics, advertising, and profiling components embedded in Android applications.
According to Proton, 64 of the 390 VPN services downloaded in the US were owned by Chinese companies, with 31 allegedly concealing their actual ownership behind entities registered in jurisdictions including Singapore, Hong Kong, and the United Kingdom. Those Chinese-owned VPNs were downloaded more than three million times in the US during a single month.
Proton is a Switzerland-based privacy technology company best known for Proton Mail and Proton VPN. Its services emphasize encryption, open-source software, and privacy protections backed by Swiss law. Because Proton operates its own VPN service, its findings should also be considered in the context of its position as a competitor to many of the apps included in the study.
The investigation found that trackers embedded in VPN apps can collect information including advertising identifiers, device models, network types, mobile carrier details, and other device data. Proton estimated that apps sending information to companies in China accounted for 1.5 million June downloads, while those communicating with trackers in Russia and Israel accounted for 1.4 million and 2.6 million downloads respectively.

Proton said 64 VPN apps accessed GPS or other geolocation information. Collectively, location-tracking VPNs represented more than three million US downloads in June, or about 20% of downloads in Proton’s dataset.
The report also highlighted several VPNs owned by market-research businesses, arguing that advertising- and analytics-based business models are particularly problematic for VPN software because users route substantial portions of their internet activity through these services.
Proton criticized Apple and Google for relying heavily on developer disclosures rather than independently verifying VPN ownership and privacy practices. It called on both companies to conduct stronger forensic checks, remove VPNs that fail them, and clearly disclose operators’ real locations and data-handling practices.
Users should treat free or unfamiliar VPN services cautiously. Before installing one, verify the company behind it, review requested permissions, avoid VPNs that demand unnecessary location access, and favor providers whose applications and no-logging claims have undergone credible independent security audits.







Leave a Reply