VPN Rocks printable resource · Updated 3 August 2026
Free VPN Risk Checklist
Seven checks to run before installing a free VPN. A free service is not automatically unsafe, but its funding, ownership and data practices should be clear before you route traffic through it.
Start with one question: who pays for the VPN, and what do they receive in return?
Seven checks before installation
- Logging: Does the policy clearly rule out browsing-history and DNS-query logging?
- Funding: Is the free tier funded by paid plans, or by ads, tracking, partner offers or unexplained sources?
- Ownership: Can you identify the operating company, jurisdiction and related apps or brands?
- Permissions: Does the app request only access needed to provide a VPN connection?
- Ads and trackers: Are advertising or analytics SDKs disclosed, limited and optional where practical?
- Independent evidence: Are audit claims, open-source apps, security documents or public test results current and inspectable?
- Leak protection: Does the provider document DNS, IPv6, WebRTC and kill-switch behaviour, including known limits?
Reasons to pause
“Unlimited and completely free” with no credible business model.
Vague references to “partners” or “non-personal data” without details.
No identifiable company, support route, changelog or current policy.
Broad device permissions unrelated to creating a VPN tunnel.
Lower-risk default: a limited freemium tier from a reputable provider is usually easier to evaluate than an unknown unlimited app. Limits do not prove safety; re-check the current policy and evidence.