Culvert VPN

Seven red flags in a free VPN's Play Store listing

Seven signs in a free VPN's Play listing that should stop you installing: odd permissions, a blank Data safety section, no developer contact and more.

Free VPNs and no sign-up · 5 min read · By Culvert VPN

Seven things in a free VPN's Play Store listing should stop you before you tap Install: permissions a VPN does not need, a Data safety section that is blank or lists shared browsing data, no developer website or domain email, a developer publishing dozens of unrelated apps, a missing or mismatched privacy policy, marketing that promises things no VPN can deliver, and "unlimited everything, free" with no visible way of paying for it. Any one is a reason to look harder; two or more is a reason to close the listing.

1. Permissions a VPN has no use for

Open About this app and scroll to App permissions. A VPN needs the VPN permission (granted through Android's own dialog when you first connect), notifications, and, if it offers split tunnelling, the ability to see installed apps. It may need Google Play billing if it sells a subscription.

Contacts, SMS, call logs, location, camera, microphone, files, and above all an accessibility service are not on that list. Each has a story behind it, and none of the stories is "to run a VPN". Which permissions a VPN app actually needs has the full breakdown.

2. A Data safety section that does not add up

The Data safety section is the developer's own declaration. Three things are wrong when you see them.

  • "No data collected." A VPN that carries your traffic necessarily learns your connection's IP address and when you connected. A developer declaring nothing has either not understood their own service or has decided not to say.
  • Browsing history, app activity or location under "shared with third parties". A VPN has no reason to share any of those with anyone, and every reason not to.
  • No way to request deletion. Google asks developers whether users can request that their data be deleted. "No" from a VPN provider is a poor sign about how the rest is handled.

3. No way to reach a real developer

Scroll to the developer section. There should be a website on its own domain, an email address on that same domain, and a postal address. Check that the website exists, mentions the app, and hosts the privacy policy. A developer whose only contact is a free webmail address, or whose website link goes to a social-media page, has made sure nobody can hold them to anything.

4. A developer with forty unrelated apps

Tap the developer's name and look at what else they publish. A company that makes a VPN, or a small family of privacy tools, is one thing. A catalogue of QR scanners, wallpaper packs, flashlight apps, a "phone cleaner" and a VPN is an advertising business, and every app in it exists to show ads and collect the advertising ID. That is the advertising and data model, and the VPN is the most valuable app in the catalogue because it sees the most.

5. A privacy policy that is missing, generic, or for a different app

Every Play listing has a privacy-policy link. Open it. The flags, in order of seriousness:

  • The link is dead, or goes to the Play listing itself.
  • The policy names a different app or company, because it was copied.
  • It reads as though produced by a generator: long, general, and never naming a single data item the VPN collects or a retention period.
  • It says nothing about connection records at all. A VPN policy that never mentions IP addresses is avoiding the subject.

A good policy is short and specific: it lists what is kept, says why, and says for how long. How to read a VPN privacy policy in ten minutes shows what that looks like.

6. Promises no VPN can keep

The listing's description is marketing, and some marketing is harmless. Some of it is a warning. A VPN cannot make you anonymous, cannot make you "100% secure", and cannot make your activity invisible to everyone; websites you log in to still know who you are, and the provider itself can still see your traffic. A listing that leans on those words is either written by someone who does not understand the product or by someone who does and is counting on you not to.

The same goes for grand claims about encryption. Every serious VPN protocol uses the same well-studied ciphers; there is no secret better one, and a listing that implies otherwise is selling a feeling.

Also worth a look: the reviews. Hundreds of five-star reviews in identical phrasing, posted in a short window, were bought.

7. Unlimited everything, free, with no paid tier

Running a VPN costs money every hour it is on. A listing that offers unlimited data, unlimited time and every location, free, and shows no in-app purchases and no other product, is not telling you how the bill is paid. The likely answers (injected ads, sold data, or your phone's connection rented to others) are all worse than a visible limit. A free tier with an honest ceiling and a Premium plan beside it is the reassuring shape, not the suspicious one; why free VPNs limit data or time explains the economics.

What a clean listing looks like

For contrast: a short permission list that matches the tables above; a Data safety section that admits to an IP address and a device identifier and says you can request deletion; a developer with a domain, a matching email and a website that hosts the policy; a description that says what the app does in plain words; and a free tier with limits you can read before you install. None of that proves an app is good. It proves the developer expected to be checked, which is the next best thing.

Culvert VPN publishes its data handling in its privacy policy (it does not log the sites you visit, your DNS queries or your traffic contents, its servers see only an opaque connection id, and it keeps your IP address for up to 30 days for abuse handling), and it is on Google Play.

Questions people also ask

Is a high download count or rating enough to trust a free VPN?

No. Downloads measure marketing spend and ratings can be bought. The listing's permissions, Data safety section, developer contact and privacy policy take a few minutes to read and are far harder to fake.

What if only one red flag applies?

Look harder at that one. A missing postal address on an otherwise clean listing may be an oversight; a shared browsing history in Data safety is not. Two or more flags together are a reason to close the listing.

Where exactly is the Data safety section?

On the Play listing, below the screenshots and description, under the heading "Data safety". Tap "See details" to see what is collected, what is shared, and whether you can request deletion.