When a VPN App Is a Data Collector: What the Facebook Onavo News Means for iPhone Users
Facebook's Onavo VPN was pulled from the App Store in 2026 after Apple's privacy crackdown. Here's how any iPhone user can spot a data-collection VPN before installing it — using App Store labels, permission audits, and business-model checks.
Answer First
Definition: A data-collection VPN is an app that uses the VPN system extension on your iPhone to intercept, log, and monetize your network traffic under the pretense of protecting your privacy. Unlike a genuine privacy VPN — which encrypts your connection and forgets what it saw — a data-collection VPN treats your browsing habits, app usage, and connection metadata as its primary product.
Why: When a VPN company’s revenue comes from behavioral data, ad intelligence, or market research rather than from subscription fees, your privacy is not its service — you are its inventory. Understanding this conflict of interest is the single most important filter you can apply before tapping “Install.”
Example: In July 2026, Facebook (Meta) finally pulled its Onavo Protect VPN from the App Store after years of escalating pressure from Apple’s privacy guidelines. Onavo was marketed as a tool that would “keep you and your data safe,” but it used its VPN tunnel to monitor nearly every interaction users had with other apps and websites — feeding that data back into Facebook’s competitive intelligence and advertising machinery. The app’s removal, tracked by major app-intelligence platforms, marks one of the most visible examples yet of a VPN app whose real customer was not the person who installed it. [See Sources for attributed coverage.]
Key Facts
- 2013 — Acquisition. Facebook purchased Onavo, an Israeli mobile-analytics startup, for approximately $200 million.
- 2014–2018 — Operation. Onavo Protect was available in the iOS App Store under Facebook’s ownership. The app routed user traffic through Facebook-controlled servers, collecting detailed telemetry about app usage and browsing activity.
- 2018 — Facebook Researcher confirmed that Onavo data was used to identify competitive threats — including the early rise of TikTok and rival messaging apps. This cross-border intelligence function parallels what dedicated social media marketing and research tools provide for content teams — except Onavo gathered its data through a VPN users believed was protecting them.
- 2019 — Apple’s App Store crackdown. Apple revised its guidelines to restrict apps that collect data about which other apps are installed. Facebook removed Onavo from iOS.
- 2026 — Final removal. Meta fully retired the Onavo brand, with all remaining versions pulled from app stores globally. [Google News coverage]
Why this matters: Onavo is not an isolated case. Analytics firms, ad-tech companies, and enterprise-intelligence vendors have all published VPN apps following the same pattern: offer free connection security, collect everything, sell the insights.
Expert Explanation
How a VPN Actually Works
A VPN creates an encrypted tunnel between your iPhone and a server the provider operates. Your traffic passes through that tunnel and emerges from the VPN server’s IP address. This prevents your ISP, coffee-shop Wi-Fi operator, or anyone on the same local network from reading your traffic.
The same mechanism makes a dishonest VPN dangerous. The provider sees everything the ISP would have seen — plus app-launch metadata, session duration, and DNS queries. Every domain you visit passes through the tunnel as a lookup. For teams managing large numbers of domains, automating DNS workflows is standard practice; for a data-collection VPN, those same queries are pure intelligence.
Three Signals to Check
1. App Store Privacy Nutrition Label — Every iOS app displays a summary of its data-collection practices. For a VPN, scroll to “App Privacy” and check:
- Data Used to Track You — If populated at all for a “privacy” app, ask why.
- Data Linked to You — If Usage Data or Diagnostics are linked to your identity, the app is building a profile.
- Data Not Collected — Some VPNs honestly declare nothing collected across all categories. This is the strongest signal.
2. Traffic Permissions at Install — iOS shows a prompt: “Allow [App] to add VPN configurations?” This grants access to all your device’s network traffic. There is no middle ground. If the company behind that prompt has no clear subscription revenue, proceed with extreme caution.
3. Business Model Transparency — Ask: How does this company pay for its servers? Subscription = aligned. Freemium with transparent limits = acceptable if the limits are clear. Completely free with no obvious revenue = the most dangerous category. Onavo was free. The product was you.
Why Apple’s Enforcement Matters — and Its Limits
Apple has been the most aggressive platform holder on this issue. The 2019 guideline change explicitly prohibited apps from collecting data about which other apps are installed — the practice Onavo relied on. In 2021, privacy labels became mandatory. But Apple cannot audit every VPN backend. As the Apple VPN Security documentation notes, what a developer does with data after it leaves your device is outside Apple’s visibility. The CISA wireless security guidance reinforces this: encryption protects data in transit, but the endpoint must itself be trusted.
Decision Framework
Use this checklist before installing any VPN app on your iPhone. One red flag warrants a hard pass.
| Signal | What to Check | Red Flag |
|---|---|---|
| Privacy Label — Usage Data | App Privacy → “Data Linked to You” | Usage Data or Diagnostics collected and linked to your identity |
| Privacy Label — Tracking | Is “Data Used to Track You” present? | Any data listed |
| Business Model | Company website: how is the VPN funded? | No clear revenue source, or “advertising” / “market research” |
| Privacy Policy | Explicit “no logs” for browsing activity? | Vague “aggregated data” language without specifics |
| Developer Reputation | Who built the app? | Parent company’s primary business is advertising or analytics |
| Independent Audit | Third-party security audit published? | None, or audit over two years old |
| Subdomain & URL Handling | Does the VPN document what domains it proxies? | Broad routing without transparency — similar to the hidden risks of unmanaged subdomains |
Practical Limits
A VPN does not prevent phishing, block malware, prevent account compromise, make you anonymous, or protect data after it leaves the VPN server. What it does do — when genuine — is encrypt traffic on untrusted networks (public Wi-Fi, airports, hotels), mask your IP from websites, and prevent your ISP from logging your history. For iPhone users on public networks regularly — or those managing cloud-based mobile devices — this is a meaningful privacy layer, as the FTC’s public Wi-Fi guide confirms: encryption is the primary defense against local network eavesdropping.
Key Takeaways
- A VPN’s technical function and its business model are separate. Onavo was technically a VPN and also a data-collection tool. Judge the latter.
- Apple’s privacy labels are useful but not guarantees. Cross-check with business model and permissions.
- Free VPNs without transparent revenue sources are suspicious. Server infrastructure is expensive.
- A VPN is one privacy layer, not a silver bullet. It does not stop phishing, malware, or account theft.
- The Onavo playbook is permanent. The habit of checking three signals — label, permissions, business model — protects you regardless of the app’s name.
FAQ
Brief answers to the most common questions about data-collection VPNs. For full responses, see the FAQ section at the top of this article.
Q: Was Facebook Onavo actually a VPN? Yes — technically. The deception was not in how it connected but in what it did with the data: logging every app and site visited for Facebook’s market research.
Q: Can Apple’s privacy labels alone tell me if a VPN is safe? No. Labels are self-reported. Cross-check against the privacy policy and business model.
Q: Does a VPN make me anonymous? No. It shifts trust from your ISP to the VPN provider. It does not prevent tracking via cookies, fingerprints, or login sessions.
Q: If a VPN is free, is my data the product? Often yes. Look for transparent revenue disclosure. If you cannot find one, treat the app as a data-collection vehicle.
Sources
- Google News — Aggregated coverage of the July 2026 Facebook Onavo VPN removal from app stores. https://news.google.com/rss/articles/CBMickFVX3lxTE9WcXRzV2doZVlmenJ5S1hmNnBLZHFZc3pudUtzSVFtZFBUSnRmdTlaSU1lSWVBYTk4eUZjMWdpNmhycFVLcmREZTdKbC0yVGpTYko3ZzQydXRlWDZNR2toWVpYQ0ZkbERjVUxCam1NXzRHZw?oc=5
- Federal Trade Commission — “Are Public Wi-Fi Networks Safe? What You Need to Know.” https://consumer.ftc.gov/articles/are-public-wi-fi-networks-safe-what-you-need-know
- Cybersecurity and Infrastructure Security Agency — “Using Wireless Networks Securely.” https://www.cisa.gov/news-events/news/using-wireless-networks-securely
- Apple Platform Security — “VPN Security.” https://support.apple.com/guide/security/vpn-security-sec802e8ab55/web