Your VPN App Is Not the Tunnel: Proton's 2026 Tracker Study
The tunnel can be perfect and the app can still talk
A VPN is usually judged on its tunnel: the protocol, the encryption, the no-logs claim, the leak test. That is only half of the product. The other half is an app installed on your phone, with its own permissions, its own network requests and its own list of bundled third-party libraries.
Encryption protects the contents of your traffic from the network between you and the VPN server. It does nothing about the app on your own device deciding to report what it knows about you to somebody else. The two can fail independently: a provider can run a well-audited tunnel and still ship an app whose analytics and advertising libraries collect device and location data. Judging the app by the tunnel's reputation is the mistake this article is about.
What Proton AG's study reported
In research published on 27 August 2026, Proton AG looked at trackers in mobile VPN apps. Every figure below is the study's finding as published by Proton; it is not an independent verification.
85% of mobile VPN apps downloaded in the United States contained at least one tracker.
64 apps actively collected users' physical location data.
Trackers gathered device identifiers, device models, network types and mobile carrier names, and some apps tracked GPS location.
64 of the apps were from Chinese companies, and 31 of those used paper companies registered in Singapore, Hong Kong and the UK to obscure ownership.
Apps named in the reporting on the study include VPN Proxy Master, VPN-Fast VPN Super and X-VPN.
Worth stating plainly: Proton AG sells a VPN, so this is a vendor's own research. That does not make the findings wrong, but it does mean you should read them as the study's reported results and look for corroboration rather than treat them as a settled independent audit.
What a tracker inside a VPN app actually collects
The individual items sound harmless. A device ID is a string, a carrier name is public information, and whether you are on Wi-Fi or cellular is mundane. Combined, they behave differently. A device identifier is stable across sessions and survives an IP change, which is precisely the thing a VPN exists to change. Add the carrier, the device model and a location, and you have a signature that describes one handset rather than a crowd.
That is what correlation de-anonymisation means in practice. Hiding your IP removes the network's easiest label, but a stable device identifier with a carrier and a location attached can be matched to the same person across services, datasets and time. If the same identifier shows up in an advertising network's records and in a data broker's files, the VPN has hidden where you connect from while the app has been explaining who you are.
There is a second effect that is easier to overlook: a VPN is often used precisely by people who do not want to be associated with a location or a network. A tracker that records the carrier and the GPS position of that user defeats the purpose more directly than any IP leak, because it is not a mistake in the tunnel. It is a feature of the app.
Why obscured ownership is a fair question
A tracker is a technical fact; who controls the data behind it is a legal one. The study reports that many of the apps traced back to Chinese companies, and that 31 of those used paper companies registered in Singapore, Hong Kong and the UK. The relevant point is not nationality as such. It is what a corporate structure says about who can be compelled to hand data over. Chinese law lets authorities require companies within its jurisdiction to disclose data, and a shell company registered elsewhere makes the real owner harder to identify before you install anything.
For a reader, the practical test is simple: if you cannot work out who owns the app from its store listing and its privacy policy, that is a question with no available answer, and an app you cannot attribute is a poor foundation for privacy.
Checking your own phone
You do not need to decompile anything. Android and iOS both expose enough to give you a useful answer in an afternoon.
Audit the permissions. On Android, open Settings, then Apps, then the VPN app, then Permissions. On iOS, open Settings, then Privacy & Security, then Location Services, and read the app's own entry. A VPN app needs network access and a VPN slot. It does not need location, contacts, phone, SMS or access to all files.
Read the privacy dashboard. Android's Privacy Dashboard shows which apps used location in the last 24 hours. iOS App Privacy Report shows which apps accessed what, and which domains they contacted. Leave it running for a day of normal use, then look.
Take location away and see what happens. Set the VPN app's location permission to Denied and use it normally. If the tunnel connects and works, the app never needed location in the first place, and any request for it was about data rather than function.
Watch the network with a blocking DNS. On Android, set a private DNS provider that blocks known tracker and advertising domains. On iOS, install a DNS-level content blocker profile. Then use the VPN app for a while and read the blocking log: a VPN app that triggers requests to analytics and ad domains is telling you what it sends.
Read the store listing's data safety section. Check whether it claims to collect location, device identifiers or app activity, and whether it says that data is shared with third parties. Compare that claim with what you actually saw in the previous steps.
Find out who owns it. Look at the developer name on the listing, the privacy policy's contact address and any named parent company. If the trail ends at a registered office with no operating company behind it, treat that as your answer.
What to do with the results
Most of these checks are not pass or fail. A single analytics library in an app is not the same as continuous location collection, and a permission you denied is data the app cannot take. What the checks give you is a comparison: you can see the difference between an app that asks for nothing it does not need and one whose list of requests has nothing to do with moving packets.
If a VPN app asks for location, keeps a stable device identifier and sends requests to advertising domains, the tunnel's quality stops being the deciding factor. The encryption may be flawless, and the app still describes a specific phone and a specific place to a chain of companies you have never heard of. If the provider's ownership is also unclear, you have no practical way to find out what happens to that description later.
The reasonable standard is not perfection. It is a provider whose app needs what the app does, whose business is legible, and whose privacy policy matches what your phone shows you.
Bottom line: the tunnel is not the whole product
A VPN can protect your traffic and still be able to describe you. Proton AG's study is a reminder that the privacy you buy is delivered by two things at once, the tunnel and the app, and that a strong tunnel is no defence against telemetry running beside it. Check the permissions, watch the requests, and ask who is behind the app. Those three questions will tell you more than any encryption headline.



