Opening paragraph
Proton has published a warning on its company blog that popular vpn apps in the United States may be tracking millions of users. Proton described tracking inside apps intended to protect privacy as the "ultimate betrayal," and the available summary indicates many US apps include tracking features.
What happened
Proton posted a public warning on its blog alerting users that some vpn applications — software meant to protect users’ internet traffic — appear to include tracking functionality. The company framed such tracking inside privacy-focused apps as a severe breach of user trust.
The available report summary suggests the issue affects a substantial portion of vpn apps in the US and that millions of users could be exposed to tracking. The summary also includes a phrase indicating that as many as 85% of apps in the US may contain tracking features; however, the full report or a complete list of affected apps was not included in the summary.
Who is affected and why it matters for vpn users
- Users of free or paid vpn apps in the United States are the primary group named in the warning.
- The concern is that apps claiming to secure privacy might collect or share usage data, undermining the core purpose of a vpn: to protect user traffic and anonymity.
This matters for anyone who relies on a vpn for privacy-sensitive activities because tracking by the app developer or third parties could reveal metadata or other information about app use.
What is known and what remains unclear
- Known: Proton issued a blog warning and used strong language, calling such tracking an "ultimate betrayal." The summary suggests the problem may be widespread in the US market and could affect millions of users.
- Unclear: The available summary does not publish a full list of named apps, the specific tracking mechanisms identified, the data collected, or the technical methodology Proton used to reach its conclusions.
Readers should treat the warning as a prompt to review vpn app permissions and privacy policies. The available summary does not provide timelines for remediation or enforcement, nor does it specify recommended vendor actions. Proton’s blog post is the single public statement described in the summary; further details would be needed to assess scope and verify specific app behavior.