Free VPNs look identical to paid ones until the connection has to carry something continuous. Video. Voice. A live stream. That is where the gap opens.
The cap disappears in one sitting
Most free tiers hand out 500 MB a month. Some stretch to 10 GB, a few reset a small daily allowance at midnight. Those numbers read as generous next to a browsing session and they are nothing next to video.
A WebRTC video call at 480p consumes somewhere between 300 and 500 MB an hour. Push the resolution to 720p and the figure lands near a gigabyte. Random video chat platforms like OmeTV, which absorbed a large share of the traffic after Omegle shut down in November 2023, keep the camera running by design. There is no idle state and no buffering pause. A 500 MB monthly allowance covers roughly one conversation.
The cap is not an accident of engineering either. It is set at the level where a user gets far enough into the product to want it and not far enough to stop paying for anything, which is a perfectly rational way to run a funnel and a terrible basis for choosing infrastructure.
There is a second cost that nobody mentions on the pricing page. Encapsulating traffic in a tunnel adds overhead, usually somewhere between four and ten percent depending on the protocol and the packet size. On a metered bundle, that overhead is paid twice over: once by the VPN allowance and once by the mobile data allowance underneath it. Anyone running video through a tunnel on a Kenyan bundle is watching two counters drain at once.
Most free services throttle rather than cut the connection, which is worse. The tunnel stays up. It simply stops working properly, and users go hunting through router settings for a fault that lives in their provider’s billing logic.
Servers fill up, and they fill up in the evening
Free tiers are oversubscribed on purpose. The server pool is smaller, the user count per server is higher, and load peaks precisely when people are home with time to spare.
Providers do not hide the arrangement. Priority routing for paying subscribers appears as a bullet point on their own pricing pages, which is a polite way of saying that free traffic waits behind everyone else’s when the link saturates. The free tier also tends to lock users to three or four locations, chosen for cost rather than coverage.
For anyone connecting from Nairobi or Mombasa, the geography compounds it. Free providers rarely maintain East African infrastructure, so traffic routes to Johannesburg, London or Frankfurt before it reaches the destination. Survivable for a web page, where an extra 200 milliseconds disappears into the render. For live video it adds latency the session never recovers from, and the picture degrades into frozen frames with audio arriving a second late.
Sustained load is the only condition that separates a service worth installing from one that merely benchmarks well, and it is almost never how VPNs get tested. Gizmodo put its shortlist through continuous video sessions instead of one-off file downloads, and the ones that held up there look nothing like a standard speed ranking.
What 283 apps revealed
The most thorough audit of this market is now a decade old and still the one worth citing. Researchers from CSIRO’s Data61, the University of New South Wales and UC Berkeley analysed 283 Android VPN apps and published the results at the Internet Measurement Conference in 2016.
The sample was not a fringe selection. It covered apps with millions of installs each, sitting in the top results for the obvious search terms, carrying four-star ratings.
Eighteen percent of them did not encrypt tunnel traffic at all. Thirty-eight percent contained code that VirusTotal flagged as malicious. Sixty-six percent leaked DNS requests, eighty-four percent leaked IPv6 traffic, and seventy-five percent shipped with third-party tracking libraries embedded in them. Roughly one in six ran non-transparent proxies that altered traffic in transit, including injecting advertising into pages the user had requested, and a handful went as far as intercepting TLS.
The leak figures deserve a moment because they are the least intuitive. An app can encrypt everything it carries and still hand the user away, because the device asks its resolver where a domain lives before the tunnel is involved. The connection is private. The record of who was asked for, and when, is not.
The obvious objection is the date. Android has changed enormously since 2016, the Play Store’s review process has hardened, and several of the worst apps in that sample no longer exist.
The business model has not. An app that gives away bandwidth still has to recover the cost somewhere, and the places available to recover it are advertising, data brokerage and the sale of idle user connections as residential proxy capacity. That last practice surfaced repeatedly in 2023 and 2024 investigations into free proxy networks, and it inverts the entire proposition. The user installs a tool to keep their traffic private and ends up renting out their connection to strangers who route their own traffic through it.
None of this requires bad intent from the developer. It requires a bandwidth bill and no subscribers.
Advertising has to know what you did
The ad-funded route sounds like the harmless option. It is the one with the sharpest structural problem.
Advertising revenue depends on attribution, which means knowing which users saw what and what they did afterwards. A VPN sits in the single best position on the device to answer that question, because every request passes through it before it reaches anywhere else. The commercial incentive points directly at the data the product exists to conceal.
Some providers resolve this honestly, by serving un-targeted ads and keeping nothing. Others resolve it by writing a privacy policy that promises not to log browsing activity while quietly reserving the right to share aggregated or anonymized usage data with partners, a category elastic enough to hold almost anything.
Reading those two clauses side by side is the fastest audit available to a non-technical user, and it takes about four minutes.
The permission you cannot narrow
Android’s VpnService interface is all or nothing. An app that holds it sees every packet leaving the device, from banking sessions to messaging traffic, and there is no setting that grants it partial visibility. Users approving that dialogue are extending more trust than any other permission on the system asks for, including the camera. Most of them tap through it in under two seconds, on the same evening they installed the app, because the alternative is not being able to open the site they came for.
The system offers one useful control that almost nobody enables. Always-on VPN, buried in the network settings, combined with the option to block connections when the tunnel drops, closes the window where traffic escapes during a re-connection. On free tiers that reconnect constantly, that window opens dozens of times a day.
Google has tightened the perimeter since. The Data safety section became mandatory across the Play Store in July 2022, forcing developers to declare what they collect. In late 2023 the company began letting VPN apps display an independent security review badge after passing a Mobile Application Security Assessment.
Both are improvements on a store that used to ask for nothing. Neither is verification in the sense a user would assume. The Data safety declaration is self-reported, and the security badge is optional, which means its absence tells you very little and its presence tells you a lab checked the app against a baseline rather than audited the company behind it.
Free is fine for exactly one thing
None of this makes every free tier worthless, and pretending otherwise would be dishonest.
There is a real distinction between a free tier attached to a paid product and an app that has no paying customers at all. The first has a business that survives without monetising its users and a reputation that breaks if it gets caught. The second has neither. For twenty minutes on hotel Wi-Fi, checking a webmail account, the first category is a sensible thing to have installed.
For anything continuous, anything financial, anything running for hours with a camera attached, it stops being a reasonable trade.
Look for the audit, not the price tag
Paying does not automatically buy competence. Plenty of subscription services have logged user activity while advertising that they do not, and a monthly fee has never stopped a provider from making promises its infrastructure cannot keep.
What correlates with trustworthiness is duller than any feature list: a published third-party audit, carrying the name of the firm that ran it and the date it was run, repeated on a schedule rather than commissioned once for a launch announcement. A jurisdiction that does not compel data retention helps. A transparency report that documents the requests received, and what was handed over, helps more. Providers who commission audits tend to publish the unflattering findings alongside the reassuring ones, because an audit nobody can criticize is an audit nobody believes.
Almost no free provider has ever commissioned one, and the handful that gesture at security certifications tend to be pointing at a compliance framework rather than an inspection of their own servers. Those frameworks describe how a company manages its own information security. They say nothing about what happens to a user’s traffic once it enters the tunnel.
Verifying an audit claim is less work than it sounds. The report itself should be downloadable rather than summarized in a blog post, and the scope statement on its first page is the part that matters. An assessment of a company’s internal security practices is a different exercise from an inspection of server configuration, which is different again from a review of whether the no-logging claim survives contact with the infrastructure. Providers who have done the third one say so plainly, because it is the expensive one. That absence is the useful data point, more than any figure in a speed comparison, and it is the first thing worth checking before the camera goes on.





















