A VPN provider pays for servers, bandwidth, engineering and support. Bandwidth in particular is a recurring cost that scales directly with usage: the more you use a free VPN, the more it costs its operator.
That is an unusual business to give away, and it is worth asking how the bill gets paid.
What examinations of free VPN apps have found
Academic and industry analyses of free VPN applications — particularly on Android — have repeatedly surfaced the same categories of problem. Not in every app, but at rates far too high to treat as isolated incidents.
Traffic and behavioural data sold onward. The most direct model. The service works as advertised while the operator monetises the record of where users go. This inverts the entire purpose: you installed it so a network operator could not build that list, and you handed the list to someone with an explicit financial interest in it.
Trackers embedded in the client. Studies examining large samples of free VPN apps have found the majority contained third-party tracking libraries. A privacy tool that reports your activity to advertising networks is not a privacy tool.
Broken or absent encryption. Some apps were found to tunnel traffic without meaningful encryption, or with implementations that failed basic validation — accepting invalid certificates, for instance, which defeats protection against interception. The connection indicator says protected. The traffic is not.
DNS and IPv6 leaks. A tunnel that carries most traffic while letting DNS queries escape to the local network leaks precisely the information most people are trying to hide. This is common enough that it is worth testing any VPN, paid or free, rather than assuming.
Outright malicious code. A minority, but a real one: apps carrying adware or worse. VPN clients require deep system permissions by design, which makes a compromised one unusually damaging.
Selling your connection as an exit node. The most alarming model. Some free VPN and proxy services route other people's traffic through their users' devices. Your home connection becomes someone else's exit point, and whatever they do appears to originate from your address. At least one widely-distributed service operated this way, and users discovered it through the consequences rather than the terms of service.
The structural problem
None of this requires the operators to be unusually wicked. It follows from the economics.
Running the infrastructure has a hard cost. If users pay nothing, the money comes from somewhere else, and in this market the available options are advertising, data sales, or reselling the network itself. All three are in direct conflict with the product's stated purpose.
There is a second structural issue: a VPN concentrates your traffic. Normally your activity is split across your ISP, various networks and many destinations. Route it all through one provider and you have created a single point that sees everything. That concentration is fine when the operator's incentive is to protect you — you pay them, and their business dies if they are caught abusing it. It is dangerous when their incentive is to extract value from what they can see.
Paying does not guarantee good behaviour. It does align the incentives, which is the necessary precondition.
What to actually check
Marketing claims are cheap. These questions are answerable and the answers differ between providers:
What is the logging policy, specifically? "We do not log" is meaningless without detail. Look for explicit statements about connection logs, timestamps, source addresses and bandwidth records. Infrastructure running in RAM only is a meaningful technical claim — a server with no persistent storage cannot retain what was never written to disk, and cannot hand over records it does not have.
Where is the company registered? Jurisdiction determines what a provider can be legally compelled to retain and disclose.
Who handles DNS? Queries should resolve inside the tunnel on the provider's own resolvers. If they go to your ISP or a third party, the main leak is still open.
Is there a kill switch? When the tunnel drops — and it will, on mobile especially — traffic must stop rather than silently continue over the open network.
What permissions does the app request? A VPN client needs the VPN permission. It does not need your contacts, your location or your call log.
How is it funded? If you cannot identify the revenue source, you are probably it.
Does it actually leak? Connect, then check a DNS-leak and IP-leak test site. This takes a minute and empirically tests the claim rather than trusting it.
The reasonable position
Free VPNs are not uniformly malicious, and a few are run by non-profits with transparent funding and genuine privacy commitments. Those exist and are worth knowing about.
But the default assumption for a free VPN app from an unfamiliar publisher — particularly one distributed through app store advertising — should be that its revenue comes from the thing you installed it to prevent. The research base supporting that assumption is substantial and consistent.
The choice is not really between paying and not paying. It is between paying with money, on terms you can read, and paying with the exact data you were trying to protect, on terms you cannot see.
If a VPN is worth using at all, it is worth a few dollars a month to one whose business model is simply that you paid them.