Why does protonVPN collect so many personal data and metadata compared to other VPN?

ProtonVPN is considered among the best VPN in terms of privacy and security according to various web site link1 link2. Moreover, protonVPN is open source and audited. However, according to apple app privacy, it collects so many personal data:

ProtonVPN: personal data (contact info, identifiers, user content), metadata (contact info, diagnostics, usage data)

Mullvad: no data and metadata

IVPN: no data and metadata

expressVPN: personal data (contact info, identifiers), metadata (diagnostics, usage data)

nordVPN: personal data (identifiers), metadata (contact info, identifiers, diagnostics, usage data)

Can you clarify this?

Thank you

P.S.

ProtonVPN is among the worst according to this comparison.

Until this is addressed, I would suggest using openVPN as the client.

Edit: actually, you should use openVPN regardless. It’s a much better client and way more mature. It is a little harder to setup initially (though protonVPN has a guide on it), but it’s a one time setup then you’re set for the most part.

The comparison chart is brought to you by PIA who fail to disclose that your email address is used for development and marketing purposes.

I’ve been using protonVPN via mobile on GrapheneOS. I have no complaints. I use openVPN to handle protonVPN over linux.

I like how on the comparison chart where it’s “among the worst” just says “may collect” and not “does collect”. I understand the need for privacy but I wouldn’t discredit the ability protonVPN provides.

I am a heavy advocate to opensource. If you dont trust it, dissect, inspect, intercept, and re-concept…

This is certainly interesting, I had no idea. Can you explain more on your comment

ProtonVPN is among the worst according to this comparison.

How to you calculate this? For the 2 VPNS you list as “no data and no meta data” Their app pages actual say "developer, xxxx has not provided details " This is certainly not the same as what you have written. For the remaining 3 VPNS (ProtonVPN, NordVPN, and Express) that are in the Apple chart comparison, perhaps I’m reading the chart wrong. From my understanding the privacy is broken out in three types. I’m listing here in order of most serious (revealing) to least.

  • Data used to track you
  • Date linked to you
  • Data not linked to you

Of the 3 - ProtonVPN does collect 1 or 2 more data points. However non of those fall under “Data used to track you”. The same cannot be said of NordVPN. So i would place it in the middle of those 3. Additionally based on the Apple chart data, I observe

  • ProtonVPN collects an average amount of data points among those listed
  • 4 of the 7 list VPNS use at least one data point to track you (not ProtonVPN)
  • IMO I would say ProtonVPN falls in the upper middle middle, certainly not among the worst.

The chart also does not take into account the privacy laws of the host country regarding the data that is collected. Anyone looking to acquire the data for legal purposes would have much easier access for those VPNs hosted in countries with loose (no?) privacy laws vs those hosted in countries with tighter privacy and higher legal hurdles. That being said I agree that any data being collected has the potential to be shared if the legal hurdle is overcome.

Edit - Corrected spelling typos :slight_smile:

Edit #2 - as pointed out by /u/razorfold/ - details are what data the app developers tell Apple the app collects - NOT what it really collects.

Especially “identifiers & user content” is highly disturbing! This needs to be addressed urgently!

While we are waiting for an official response, I think this has to do with their Report a Bug feature that is there in their apps. So, basically all the permissions required make sense that way.

In addition, note that their apps are open sourced on Github. If someone has taken a look at their code they could also share their inputs.

According to exodus the Android app doesn’t contain any trackers.

re PS - Private Internet Access find themselves the best, that solid.

re Proton - I use their VPN as a paid service, so they know who I am already. Are you just posting about the “Free VPN Service”?

On PC I don’t think it has access to anything personally identifiable.

The Google Play store shows this for the Free Proton version for android:

This app has access to: Other

  • view network connections
  • run at startup
  • connect and disconnect from Wi-Fi
  • full network access
  • prevent device from sleeping

So maybe the iOS version has those things due to the way Apple monetizes things?

Are there apps on the Apple Store that do not have those things?

I am a long time PVPN user and find this very disturbing indeed; am thinking of switching to ivpn until solved

Interesting this should be posted here. I’m a new user of Proton VPN… I told my friend that I just signed up for a VPN and he told me “all VPNs are compromised, you don’t gain anything from using a VPN because literally every company tracks and logs you and your traffic. Whoever needs your information that badly can get it anyway.”

I assume a VPN will know who I am by my IP address, but the website I’m visiting won’t know my IP address.

The VPN can also know who I am if I don’t use cryptocurrency or some other anonymous payment.

I’m not sure how ProtonVPN free works. The free servers don’t appear to be owned/operated by Proton.

No statement from u/protonvpn yet?

muchas gracias, gorgeous on front page

Thank you for the transparency! I wonder how other VPNs handle these things (support etc) so that they get better privacy labels? On the first look it will be worrisome for many users.

Thank you for the clarification. However, you should specify that such information (user content) is shared only in case of bug reports.

What about the other data and metadata?

Hey I got a question. Does ProtonVPN app on android identify device’s imei?

We have responded (see the pinned comment at the top of this thread). Basically, we only collect information if you use the report bug feature and send us information.