Screenshot of a VPN app store listing highlighting the 'Location Access' permission toggle.

1 in 6 VPNs Track Your Location, According to New Report From Proton

When a service promises anonymity, the last thing users expect is that the tool itself is spying on them; the new Proton report shows that 1 in 6 VPN apps on major stores contains location trackers, a fact that turns the very premise of a VPN on its head for anyone who assumes privacy by default.

Scale of the Problem in Consumer App Stores

The investigation examined every VPN listed on Apple’s App Store and Google Play, tallying a total of 64 applications that embed tracking code capable of harvesting sensitive data. Those 64 represent a substantial slice of the market, given that the stores host hundreds of VPN options, meaning a typical user has a high probability of downloading a compromised app.

Proton’s methodology relied on static code analysis and network behavior monitoring, revealing that the trackers are not optional add‑ons but built‑in components that activate as soon as the VPN connects. This means the privacy breach occurs silently, without any user‑visible prompt or permission request beyond the standard app install.

The report also notes that the presence of trackers is the "exact opposite of what a VPN is supposed to do," underscoring a systemic disconnect between marketing claims and technical implementation across the ecosystem.

Why Trackers Slip Into VPN Apps

Many VPN developers monetize through third‑party advertising or analytics SDKs, which often come bundled with location‑tracking capabilities. The economic incentive to collect user data for ad targeting outweighs the reputational risk for smaller or less scrupulous developers.

From a technical standpoint, the SDKs integrate at the binary level, making it difficult for end‑users to detect the extra code without specialized tools. This covert integration exploits the trust users place in the VPN label, effectively weaponizing the privacy promise to harvest the very data the user seeks to conceal.

Furthermore, the open‑platform policies of iOS and Android allow apps to declare broad permissions, such as "access to precise location," which can be granted automatically if the user accepts the initial install prompt, thereby granting trackers unobstructed data flow.

Implications for the Broader Privacy Ecosystem

When a privacy‑focused product like a VPN fails to protect, the ripple effect erodes confidence in all privacy‑first technologies, potentially driving users back to less secure alternatives like plain HTTP or unencrypted Wi‑Fi. This regression undermines the market pressure that has historically pushed providers toward stronger encryption standards.

The presence of trackers also creates a feedback loop: data harvested from VPN users can be sold to advertising networks, which then refine targeting algorithms, making it harder for any individual to achieve anonymity even when using multiple privacy tools.

Regulators may view the systemic mislabeling of VPNs as a consumer protection issue, prompting stricter disclosure requirements or even bans on apps that bundle undisclosed trackers, which could reshape the app store vetting processes.

What This Actually Means For You

  1. Scrutinize permission requests: If a VPN asks for location or other sensitive permissions, treat it as a red flag rather than a benign requirement.
  2. Prefer open‑source VPN clients where the code can be audited, reducing the chance of hidden tracking modules.
  3. Cross‑check any VPN against independent privacy audits such as Proton’s report before installation.
  4. Use a layered approach: combine a vetted VPN with additional privacy tools like DNS‑over‑HTTPS to limit data exposure.
  5. Stay informed about app store disclosures; a VPN listed under “privacy” does not automatically guarantee a tracker‑free experience.

Immediate Action Steps

First, audit the VPN apps currently installed on your devices: open the app’s permission settings and revoke any location or analytics permissions that are not essential to core functionality. If the app refuses to operate without them, consider uninstalling it.

Second, consult Proton’s published list of offending apps and replace any flagged VPN with a proven, open‑source alternative; supplement this choice with a personal security device that can monitor outbound traffic for unexpected connections.

Frequently Asked Questions

Do all VPNs track user location?

No. The Proton study identified 64 apps with trackers, which translates to roughly one‑sixth of the VPNs surveyed, meaning the majority still operate without embedded location tracking.

Can I trust the permissions screen to reveal hidden trackers?

Only partially. Trackers can be embedded within the app binary and operate without explicit permission prompts, so a clean permissions list does not guarantee the absence of covert data collection.

What’s the safest way to verify a VPN’s privacy claims?

Look for independent audits, open‑source codebases, and community reviews that specifically address the presence or absence of third‑party trackers, as highlighted in the Proton report.

What Do You Think?

Given that a tool designed to shield you is itself spying, should the industry enforce mandatory third‑party privacy certifications before a VPN can be marketed as a privacy solution?

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.