App store privacy labels are self-declared summaries of what an app collects, and for VPN apps they often reveal tracking that sits awkwardly next to “no-logs” marketing. In 2021, roughly one in five iOS apps with “VPN” in the name declared data used to track users across other companies’ apps and sites. Independent studies show labels are frequently incomplete, so a clean label alone does not prove that an app is private.
How the two label systems work
Apple introduced privacy labels on App Store product pages in December 2020 (Xiao et al., 2023). Google followed with the Data safety section on Google Play in April 2022 and gave developers until July 20, 2022 to fill it in (Google, 2022).
Both are questionnaires the developer completes. Apple tells developers they are responsible for keeping their answers accurate and current, and lets them change answers at any time without an app update (Apple, 2026). Google is blunter: its help page says the developer alone is responsible for complete and accurate declarations, and that Google cannot make determinations on developers’ behalf about how they handle data (Google, 2026).
| Feature | Apple App Privacy label | Google Play Data safety | Source |
|---|---|---|---|
| Launched | December 2020 | April 2022 (required by July 20, 2022) | Xiao et al., 2023; Google, 2022 |
| Main headings | Data Used to Track You; Data Linked to You; Data Not Linked to You | Data shared; Data collected; Security practices | Apple; Google |
| Third-party SDK data included? | Yes, data collected by “third-party partners” must be declared | Yes, including data collected through SDKs and libraries | Apple; Google |
| Key exemption | Data sent to service a request and not retained (for example an IP address on a server call) | Transfers to “service providers” are not counted as sharing | Apple; Google |
| Who verifies | Developer responsible; no verification described | Developer “alone” responsible | Apple; Google |
| Optional security signal | None | “Independent security review” badge (MASA) | BleepingComputer, 2023 |
What “tracking” means on iOS
Apple defines tracking as linking data from your app with other companies’ data for targeted advertising or ad measurement, or sharing data with a data broker. Since iOS 14.5 in April 2021, App Tracking Transparency has required apps to ask permission before tracking users across other companies’ apps and sites (Apple Newsroom, 2021). A VPN app that shows the “Allow app to track your activity” prompt is telling you it wants to do exactly that.
Stricter rules for VPN apps
Both stores impose extra conditions on VPNs. Apple’s guideline 5.4 says VPN apps may not sell, use or disclose any data to third parties for any purpose, must commit to this in their privacy policy, and must state what user data is collected before a user buys or uses the service (Apple, 2026).
Google’s VpnService policy requires apps to encrypt traffic from the device to the tunnel endpoint, prohibits collecting personal and sensitive data through the VPN without prominent disclosure and consent, and bans redirecting other apps’ traffic for monetization (Google, 2026).
Because of these rules, a VPN label that declares tracking data or data shared with advertisers describes behavior that Apple’s own VPN guideline does not allow.
What VPN apps declare
The largest public snapshot of iOS VPN labels comes from 42matters, an app-intelligence company, which examined every iOS app with “VPN” in its title as of May 20, 2021 (42matters, 2021). We calculated the percentages from its counts; an app can appear in more than one category.
| Apple label category | VPN apps declaring it | Share of 1,265 apps | Source |
|---|---|---|---|
| Data Used to Track You | 246 | 19% | 42matters, 2021 |
| Data Linked to You | 142 | 11% | 42matters, 2021 |
| Data Not Linked to You | 405 | 32% | 42matters, 2021 |
The most downloaded app in the tracking group was a free app, VPN - Super Unlimited Proxy, with about 2.5 million global downloads in the previous 30 days by 42matters’ estimate. It shows the clearest gap between marketing and declaration: sold as a privacy tool, the app admits in its own label that it links your data with third-party data for advertising.
On Android, earlier code-level research points the same way. A 2016 study of 283 Android apps using the VPN permission found 75% embedded third-party tracking libraries and 82% requested permissions for sensitive resources such as user accounts and text messages (Ikram et al., 2016). In August 2026, Proton, which sells its own VPN and so has a commercial interest in the finding, reported that 85% of VPN apps downloaded in the US contained trackers detected by the open-source Exodus Privacy tool, and that 64 apps tracked users’ physical location (Proton, 2026). We could not independently verify Proton’s dataset.
How accurate the labels are
Every large study we found reported widespread label errors.
| Study | Store | Sample | Finding | Source |
|---|---|---|---|---|
| Lalaine (USENIX Security 2023) | Apple | 5,102 iOS apps | 3,423 had non-compliant labels; 3,281 failed to disclose data or purposes | Xiao et al., 2023 |
| “See No Evil” (Mozilla Foundation) | 40 top free and paid apps | Nearly 80% had discrepancies; 16 rated “Poor,” 6 “OK” | MediaPost, 2023 | |
| Hidden Links (FOCI 2025) | 21 VPN apps | One family’s apps sent users’ IP-derived ZIP code to a Firebase endpoint while privacy policies said no addresses were collected | Mixon-Baca et al., 2025 |
The Lalaine researchers found that User ID, Device ID and location were the data types developers most often left off their labels, and pointed to opaque data collection by third-party SDKs, which developers may not fully understand, as one root cause (Xiao et al., 2023). Mozilla pointed to Google’s service-provider exemption as a loophole that lets apps omit data flows from the “shared” section (MediaPost, 2023).
Why “Data Not Collected” can be honest and still incomplete
Under Apple’s definition, data only counts as “collected” if it is retained longer than needed to serve the request; an IP address sent on a server call and not kept does not need to be declared (Apple, 2026). For a VPN that genuinely keeps no logs, that is fair. But the label is the developer’s own description of its retention, so an app that does keep data can use the same wording. The label cannot show what happens on the VPN’s servers.
Security badges are not privacy labels
Since November 2023, Google Play has highlighted an “Independent security review” badge in the Data safety section for VPN apps that passed a Mobile Application Security Assessment against the OWASP MASVS standard. NordVPN, Google One and ExpressVPN were the first to display it (BleepingComputer, 2023). The badge tests how an app is built; it does not certify the accuracy of the privacy declarations, a provider’s logging, or who owns the company.
What this means for you
- Read the label before installing. On iOS, scroll to “App Privacy.” On Google Play, open “Data safety.” It takes 30 seconds.
- Treat tracking as a deal-breaker for a VPN. “Data Used to Track You,” a tracking permission prompt, or data “shared” with advertising partners all contradict the purpose of a VPN.
- Be skeptical of an empty label. “No data collected” is the developer’s own unaudited claim, and research shows many labels understate collection.
- Cross-check the privacy policy. Look for named ad networks, analytics SDKs and location data. Contradictions between the policy and the label are a red flag.
- Check permissions on Android. A VPN rarely needs access to contacts, SMS or precise location.
- Look for independent evidence. Published no-logs audits and the Play security badge each cover part of the picture; neither alone is sufficient.
Methodology and limitations
The sources are Apple’s and Google’s developer documentation (read in full on the official sites), app-store policy pages, a 2021 dataset from app-intelligence firm 42matters, peer-reviewed research (USENIX Security 2023, ACM IMC 2016, FOCI 2025), Mozilla Foundation’s 2023 study as reported by MediaPost, and a 2026 study from Proton, a VPN vendor. We did not rely on label audits published by VPN review sites.
The 42matters snapshot dates from May 2021, shortly after labels launched, and labels can change at any time without an app update. The general-purpose accuracy studies (Lalaine, Mozilla) did not focus on VPN apps, so their rates should not be read as VPN-specific error rates. The 2016 Android study predates both label systems, and we did not test any app ourselves for this article.