Sovatun Guide

When Apple Pushes a VPN Off the App Store: What It Tells You About Choosing One

Facebook's Onavo VPN was removed from the App Store for violating Apple's data-collection rules. Here is what that event reveals about how to spot a genuine privacy VPN — and what even Apple's review process cannot guarantee.

Answer First

Definition: Apple’s App Store Review Guideline 4.5.2 states that apps “should not transmit data about other apps on a user’s device without permission.” It is one of the few platform-level rules that directly affects how VPN apps can use the system-level network access a VPN configuration grants them.

Why: A VPN on your iPhone is given a system-level network tunnel that can see every packet your device sends and receives. The same permission that lets a genuine VPN encrypt your traffic also lets a data-collection app inspect which other apps you open, what domains they contact, and how long you use them. Apple’s 4.5.2 is a guardrail that says: even if you hold that power, you may not use it to profile the user’s other apps.

Example: In July 2026, Facebook’s Onavo Protect VPN was removed from the App Store after Apple determined that it was transmitting data about other apps installed on users’ devices, as reported by Mashable. Onavo was marketed as a security tool, but behind the VPN tunnel, Facebook was using the connection to map competitive app usage and feed product decisions. The same infrastructure that could have been protecting privacy was siphoning intelligence back to a company whose primary business is data monetization.

The takeaway is not “Apple catches every bad actor.” It is that the App Store review process, when it works, can be a useful public signal — and that users who learn to read that signal are better equipped to choose a VPN that actually respects their privacy.


Key Facts

  • Onavo Protect was a free VPN app owned by Facebook. It offered standard VPN features — encrypting connections, blocking certain trackers — but routed all device traffic through Facebook-controlled servers.
  • Apple enforces Guideline 4.5.2 on a case-by-case basis. The rule prohibits apps from collecting data about which other apps are installed or used on the device. Onavo was found in violation.
  • The VPN configuration itself was not the problem. Apple permits VPN apps to route traffic through their servers. The violation was what Facebook did with the visibility that configuration gave them: monitoring other apps without user consent.
What Onavo claimedWhat Onavo did
Protect your connection and block malicious sitesRouted all traffic through Facebook’s servers
Keep your data safeCollected app-usage data from the device
Free privacy toolUsed collected data for competitive intelligence
Compliant with App Store rulesRemoved for violating Guideline 4.5.2

Expert Explanation

To understand why the Onavo case matters, you need to know one technical fact about how VPNs work on iOS.

When you enable a VPN profile on your iPhone, the operating system grants that app access to a virtual network interface. Every packet your phone sends — every website you visit, every app that phones home, every push notification — passes through that interface. A well-designed VPN encrypts those packets and forwards them to a server the provider operates. The server decrypts the traffic and sends it to the public internet.

That is the honest path.

The dishonest path looks identical at the OS level. The VPN app still creates an encrypted tunnel. The data still leaves the device. The difference is what happens next: instead of discarding the packet metadata, the app logs which destination IPs belong to which apps, timestamps each connection, and sends that data to a database controlled by the provider. The user sees the green “VPN” icon and believes their traffic is protected. It is — from third-party snooping. But it is fully visible to the company running the VPN server.

Apple’s Guideline 4.5.2 is one of the few safeguards against this. It cannot audit the server side — no platform review can. What it does is give Apple a basis to investigate and, when violations are found, remove the app. The removal is public and the press covers it. That coverage becomes a signal other users can learn from.

The limit is real. Apple reviews an app at the time it is submitted. A provider could pass review in week one and change server-side behavior in week two. The 4.5.2 enforcement is a deterrent and a cleanup mechanism, not a real-time audit.

From a user perspective, the question should never be “Is this on the App Store?” It should be “Does this provider’s business model align with my privacy?” That is a question only the provider’s public documentation — and third-party audits — can answer.


Decision Framework

Here is a simple checklist you can run on any VPN app you are considering — whether it is on the App Store or not.

📋 VPN App Privacy Checklist

  1. Read the privacy policy — not the marketing page. Look for specific language about what is logged: connection timestamps, source IPs, destination IPs, bandwidth usage. A genuine privacy VPN states explicitly what it does not store.
  2. Check who owns the company. If the parent company’s primary revenue comes from advertising, data brokerage, or analytics, ask why they would offer a free VPN. Services require servers, bandwidth, and staff. If you are not paying, your data likely is.
  3. Look for a third-party audit. Independent security firms can audit a provider’s infrastructure and confirm whether logging claims match reality. Public audit reports are a strong positive signal.
  4. Confirm the VPN uses a standard protocol (WireGuard, IKEv2, or a current OpenVPN implementation). Proprietary or undocumented protocols may introduce vulnerabilities or hidden data channels.
  5. Search the app name alongside “data collection” or “privacy controversy.” If a VPN has been removed from a store or reported by journalists, the record is usually easy to find.
  6. Assume any free VPN has a secondary revenue model. That model may be transparent (a freemium tier) or opaque (data monetization). Verify which applies before installing.

Practical limits of this checklist:

  • A privacy policy can change without notice. What is true today may not be true next month.
  • A third-party audit covers infrastructure at a point in time. It does not guarantee continuous compliance.
  • Apple’s removal of an app is a lagging indicator — it happens after the violation, not before.
  • No checklist can guarantee a provider is not misbehaving on the server side. The best you can do is reduce the number of organizations that would need to collude to violate your privacy.

Key Takeaways

  1. App Store approval is a useful but incomplete signal. Apple’s enforcement of Guideline 4.5.2 can expose bad actors — but only after they have been operating, and only if Apple investigates. Do not treat a store listing as a privacy seal.
  2. The VPN permission is powerful. The same system-level network access that encrypts your traffic can also expose it to the VPN provider. Choose a provider whose business model does not create an incentive to misuse that access.
  3. A VPN encrypts your connection on public Wi-Fi and hides your IP address from the sites you visit. It does not prevent phishing, block malware, stop account compromise, or eliminate all tracking. Products that claim otherwise are overpromising.
  4. Free consumer VPNs nearly always monetize something. Servers cost money. If the app is free, the revenue comes from somewhere — data, upgrades, or enterprise cross-subsidy. Know which.
  5. Public removal events are teachable moments. The Onavo case is not a reason to avoid VPNs. It is a reason to choose one with clear, verifiable privacy practices.
  6. Your iPhone already has built-in protections. Apple’s iCloud Private Relay (for iCloud+ subscribers) and per-app network permissions offer baseline privacy without a third-party VPN. A VPN adds value primarily for public Wi-Fi and for hiding your IP from destination servers.

FAQ

Q: Isn’t every VPN on the App Store already vetted by Apple? A: Apple’s review checks that an app does what it claims and does not transmit data about other apps on the device (Guideline 4.5.2). It does not audit the destination servers, inspect the VPN provider’s business model, or verify how logs are handled after data leaves the device. Store presence is a floor, not a ceiling.

Q: Could a privacy-focused VPN also be removed from the App Store someday? A: It could, but for the opposite reason: a genuine VPN might be removed because it refuses a government demand for logging, or because Apple changes a policy that incidentally affects VPN configurations. The Onavo case is different — Onavo was removed for collecting data it should not have collected in the first place.

Q: If a VPN app has “no logs” in its privacy policy, is that enough? A: No. “No logs” is a marketing term; the legal term is the privacy policy itself. Read whether the policy says “we do not store connection timestamps, source IPs, or destination IPs.” Many apps labeled “no logs” still collect aggregated metadata for analytics. The policy (not the tagline) is what matters.

Q: Does a VPN protect me from phishing or malware? A: No. A VPN encrypts the tunnel between your iPhone and the VPN server, which protects against snooping on public Wi-Fi. It does not block phishing pages, stop malware, prevent account compromise, or remove tracking cookies. Those require separate tools and habits.


Sources

Further reading on SovaTun: When a VPN App Is a Data Collector | Getting Started with Cloud Phones | Ainnc: Cross-Border Social Media Marketing | BashClaw: Developer Tool for Cloud Phones