A recent investigation by Proton has raised concerns about how data is collected by mobile virtual private network (VPN) apps, which are used to enhance online privacy and security. The study looked at more than 7,000 mobile VPNs globally and focused on 390 available in the U.S. It found that 85% of these apps included at least one tracking tool, and 64 of them had access to a smartphone's location. The data collected can include the Android advertising ID, phone model, network type, and carrier name. These tracking elements are not always added directly by the app developers; some are integrated through commercial partnerships with foreign companies or are white-label products bought and sold for advertising revenue. In June, apps with tracking features linked to Chinese companies had accumulated 1.5 million downloads, while those associated with Russia had 1.4 million, Israel had 2.6 million, and the Five Eyes countries (a group of five nations focused on intelligence sharing) had 4.6 million. Some of the studied services are operated by companies that specialize in audience measurement and market research, such as Sensor Tower, Comscore, and BiScience. These companies have previously faced criticism for collecting user data, including conversations with AI services. Proton specifically highlighted three widely used apps—VPN Proxy Master, VPN-Fast VPN Super, and X-VPN—which had more than three million downloads in June 2026. The investigation also questioned the true identity of the app publishers. Proton found that about 60 of the 390 U.S. VPNs studied were linked to Chinese companies. For 31 of these, the owners were hidden behind shell companies registered in Hong Kong, Singapore, or the U.K. This lack of transparency is particularly concerning for users who rely on these apps to protect their internet traffic. A country's legal framework and corporate structure can influence the obligations a company has regarding data privacy and security. In China, for example, the National Intelligence Law requires organizations to support and cooperate with intelligence services. Proton used Exodus Privacy, a French organization that analyzes Android apps and identifies tracking tools in their code, to conduct the research. Exodus uses static analysis to detect known tracking SDKs in app files but does not monitor their real-time activity. While this means that not all data may be collected with every use, it still shows that tracking tools can be present in apps designed to protect privacy. Similar findings have been reported in other studies, including one presented at NDSS 2026, a major cybersecurity conference. That research found that many popular Android VPNs transmit user data in unencrypted formats or leak traffic outside the secure tunnel. Proton sells its own VPN service and has not released the full list of the 390 apps studied or the dataset used in the research. However, the findings support previous studies on the topic. The investigation highlights the need for users—especially those using free VPNs—to carefully read the terms and conditions, understand who operates the service, how it is funded, what data it collects, and whether it undergoes independent audits. Users are encouraged to make informed choices to better protect their online privacy.