HideMyAss! (HMA) Review

The most famous logging receipt in VPN history: in 2011 HMA itself blogged that it had handed the FBI the connection logs that convicted a LulzSec member. Fourteen years, an Avast acquisition and a Gen Digital merger later, the no-log policy is stricter (never log IP/DNS/activity; only day + coarse time + volume for 35 days) - but it is still just a policy: no audit, no court test, plus a mobile app stack that runs Firebase and two more analytics SDKs by its own admission. Add the owner's record (Avast's Jumpshot clickstream-sale scandal, FTC $16.5M penalty 2024) and 36-month contracts renewing at full price, and HMA is a mainstream convenience VPN, not a privacy tool.

3 red flagsfacts reported
3.8
no user ratings yet - be the first
Visit HideMyAss! Read full review outbound link - currently plain redirect, no affiliate parameters
Red flags (3):
  • Operator-confirmed logging in 2011 that helped convict a LulzSec member (hidemyass.com blog, 2011-09-23; FBI 2013 press release)
  • Parent company Avast fined $16.5M by the FTC (2024-02) for selling browsing data - HMA is in the same portfolio (Gen Digital)
  • iOS/Android apps use Google Firebase plus two more analytics SDKs (HMA's own no-log page)

// Review

by the vpncomparison editorial desk · review version 2 · prose updated 2026-09-28 · facts as of 2026-09-28 · how we verify

Honesty note: we have not run our own tests on HideMyAss! (HMA) yet (leak tests, speed, kill switch). Everything on this page is source-based meta-research with dated links. When we test it, results appear here and on the change log.

Overview

HideMyAss! (HMA) is a commercial VPN service founded in the UK in 2005 and now owned by Gen Digital (formerly Avast). It markets itself for streaming and casual use, but its history includes confirmed logging that led to a criminal conviction. Despite a stricter current policy, the lack of audits and its parent company’s data-selling scandal make it unsuitable for real privacy needs.

Logging & privacy

HMA claims it never logs your original IP, DNS queries, or online activity, retaining only the connection day, coarse time-of-day, and rounded data volume for 35 days. However, this claim rests solely on policy - there is no independent audit or court-tested proof. The provider’s credibility is severely damaged by its 2011 admission of handing logs to the FBI, leading to a LulzSec member’s arrest. Jurisdiction in the UK (a Five Eyes member) and the absence of a warrant canary further weaken trust.

Pricing & the renewal trap

HMA offers a 36-month plan at EUR 2.99/month (EUR 107.64 total), a 73% discount off the regular price. After this term, renewal is at full rate - effectively EUR 395.64 for three years - tripling your cost. The 30-day money-back guarantee offers limited protection. No anonymous payment methods like cryptocurrency are listed, and refunds beyond 30 days are discretionary, locking users into a long, expensive renewal cycle.

Features & performance

HMA supports OpenVPN, IKEv2, and WireGuard protocols, with a kill switch, split tunneling, and support for P2P and streaming. It operates 3,400 servers across 65 countries and allows connections on up to five devices. However, obfuscation is not documented, and there’s no evidence of censorship circumvention capability. While features are solid for mainstream use, performance claims are unverified by independent testing.

Ownership & track record

HMA is owned by Gen Digital, which includes Norton, Avast, and AVG. This ownership is a major red flag: in 2024, Avast was fined $16.5 million by the FTC for selling user browsing data via Jumpshot. HMA’s own 2011 incident - confirming it handed logs to the FBI - proves historical logging. Internal analytics on mobile apps (Firebase + two other SDKs) contradict privacy claims. These incidents, combined with unverified policies, show a pattern of trust violations.

Censorship resistance

HMA does not advertise or document any obfuscation technology. Its apps do not claim to bypass deep packet inspection, and there is no evidence it works in heavily censored regions like China or Iran. Given its logging history and lack of stealth features, this tool is not suitable for use under repressive regimes. Users in censored markets should consider audited, obfuscation-capable alternatives.

Verdict

Avoid HMA if you need real privacy - its history of logging and parent company’s data exploitation make it untrustworthy. It may work for streaming or casual use, but you’re paying for convenience, not security. The long-term cost trap and lack of anonymous payment options further reduce value. This provider pays no known affiliate trail, but its ownership does profit from user data elsewhere.

++ What holds up

  • Explicit no-log policy with unusual candor about what IS collected (day, coarse time, data volume, 35-day retention)
  • Kill switch and split tunneling; streaming and P2P officially embraced
  • Large network: 65+ countries, 100+ locations, 3400+ servers, 5 devices
  • 30-day money-back guarantee

-- What to watch

  • Operator-confirmed 2011 logs handover (LulzSec/Kretsinger case) - the current 'never log IP' claim has no independent verification
  • Owned by Gen Digital (Norton/Avast): Avast was fined $16.5M by the FTC (2024) for selling users' browsing data via Jumpshot
  • Mobile apps ship three analytics tools (Google Firebase + two others) by HMA's own admission; desktop claims zero third-party tools
  • 3-year contract sold at EUR 2.99/mo against a EUR 10.99/mo regular price - classic renewal trap
  • No warrant canary, no public audits, proprietary apps

Pricing reality check

Intro pricesee provider site
Refund window30 days

See the 3-year total next to the marketing number: true-cost calculator →

// The money trail - what review sites earn by recommending this

affiliate status not verified yet

If we sign up for this program, every link here becomes rel="nofollow sponsored" and this box stays. Until then our links are plain redirects with zero tracking. Ranking logic physically cannot read affiliate fields - here is the proof.

Incident record (2)

  • 2024 Avast fined $16.5M by FTC for selling browsing data via Jumpshot Antivirus/VPN giant Avast harvested detailed browsing data from its own products and sold it via subsidiary Jumpshot (exposed Jan 2020 by PC source →
  • 2011 HideMyAss logs help convict LulzSec member HideMyAss published a blog post confirming it handed the FBI connection logs for user 'recoded' (Cody Kretsinger), who pleaded guilty to the source →

Before you pay: check the renewal price, the refund window, and whether a cheaper or free path covers your use case - the honest checklist.

Visit HideMyAss! or compare all VPNs →

// HideMyAss! FAQ

Is HideMyAss! (HMA) legit?

Based on our checks as of 2026-09-28: HideMyAss! (HMA) scores 3.8/10 in our weighted review. We logged 3 red flags (listed above). User reports, ownership and the incident record are documented with dated sources in the meta-review below.

What do I actually get with HMA?

Access to 3,400 servers in 65 countries, support for P2P and streaming, kill switch, split tunneling, and apps for major platforms. No obfuscation or independent privacy verification. Designed for geo-unblocking, not anonymity.

What is the renewal price and total cost over three years?

You pay EUR 107.64 for the first three years (EUR 2.99/month), then renew at the full rate of EUR 395.64 for the next three - more than triple the initial cost. No price lock beyond the initial term.

What evidence supports HMA’s no-logs claim?

None beyond its policy. No audits, court tests, or technical proofs exist. The claim is contradicted by its 2011 handover of logs to the FBI and the parent company’s history of selling browsing data.

Does HMA work in censored countries like China or Iran?

No. HMA does not offer obfuscation or documented censorship circumvention. There is no evidence it can bypass deep packet inspection or operate reliably in high-censorship environments.

Can I pay anonymously with cryptocurrency?

No. HMA does not list cryptocurrency or other anonymous payment methods. You must use traceable fiat payments, increasing exposure compared to privacy-focused providers.

What happens if HMA shuts down or gets taken over?

Given its ownership by Gen Digital - a company with a history of data monetization - any shutdown or transition could involve data retention or transfer. No public plan exists for user data in such a scenario.

What’s an honest free or cheap alternative?

Consider Mullvad (flat rate, audited, anonymous accounts) or IVPN (independent, audited). For budget needs, Proton VPN’s free tier offers real no-logs and transparency - unlike HMA’s unproven claims.

// The meta-review: what the internet says about HideMyAss! (HMA)

We do not expect you to trust us. This review is a meta-review: below you see what other review sites claim - with their conflicts of interest labeled - what users report on Reddit and forums, and who actually operates HideMyAss! (HMA). Every claim links to its source so you can verify it yourself.

// What other reviewers say (0)

Every source carries a conflict label from our review-site database. "Affiliate-funded" means the site earns money if you buy what it recommends. We include critical voices deliberately.

No third-party reviews with usable evidence found yet. For a VPN with no affiliate program that is normal - the affiliate-funded sites do not cover what does not pay.

// What users say (0)

Reddit, forums, HN - paraphrased and linked, never quoted out of context. Anecdotes, not proof - but refund complaints and leak reports are the best early-warning system this market has.

No user threads found yet. If you have first-hand experience, post it in the comments below - it feeds this section after review.

// AI fact summary - everything we know, compressed

Generated by Qwen3 on 2026-09-28 from our fact database plus the linked sources. It summarizes - it does not add facts. Check anything that matters against the linked sources.

Bottom line: HMA is a mainstream VPN for streaming and casual use, not a privacy tool. Its brand history includes proven logging and data disclosure, and its parent company was fined for selling user data. Avoid if you have any real privacy needs.

The logging truth: The provider claims it no longer logs IP, DNS, or activity, keeping only anonymized connection metadata for 35 days. However, this claim is unverified by audit or court test, and it contradicts HMA’s own 2011 admission that it provided FBI logs that identified a LulzSec member. The UK jurisdiction and Gen Digital ownership (ex-Avast, fined $16.5M in 2024 for selling browsing data) further undermine trust.

Pricing reality: Introductory pricing is aggressive - down to €2.99/month for a 36-month contract - but reverts to full price (€13.99/month) at renewal. The 30-day refund window is standard, but long contracts create lock-in risk.

What reviewers say vs what users say: Official materials and likely affiliate reviews praise HMA’s speed and streaming support, but independent voices (Hacker News, 2025) express deep skepticism about all no-logs claims, especially for brands with HMA’s history. The conflict is clear: marketing portrays reliability, while user sentiment highlights the lack of evidence behind privacy promises.

Who runs it: HMA is owned by Gen Digital (US-listed), which acquired it via Avast in 2016. The ownership history is significant: Avast was fined for data sales, and HMA’s own 2011 logs handover remains a landmark case in VPN trust failures.

// Sources & how this review was built

Every external source used on this page, with the date we fetched it. Methodology: how we verify. Sources disappear or change - if a link is dead, tell us via contact.

  1. incident blog.hidemyass.com - Lulzsec fiasco - from HideMyAss VPN provider (operator confirmation of 2011 logs handover) dated 2011-09-23 · fetched 2026-09-27
  2. operator hidemyass.com - HMA no-log policy page fetched 2026-09-27 · HTTP 200
  3. operator hidemyass.com - HMA homepage (pricing + features) fetched 2026-09-27 · HTTP 200
  4. reference Wikipedia - HMA (VPN) fetched 2026-09-27 · HTTP 200
  5. regulatory FTC - FTC Order bans Avast from selling browsing data, $16.5M penalty (2024-02-22) dated 2024-02-22 · fetched 2026-09-27

// Rate HideMyAss! (HMA)

Community score: no ratings yet

One rating per user and provider. Smoothed display (statistical prior) prevents single-vote manipulation.

// User comments (0)

No comments yet - be the first. Posting runs a short proof-of-work in your browser (anti-spam), no account needed.

// Similar providers

Mullvad VPN

The most honest VPN on the internet, and in 2026 still the one this industry is measured against: numbered accounts, cash or Monero accepted, open-source client

8.9
court-proven no-logs audit open source crypto accepted
intro $5.71 /month
Sweden commercial vpn 7 h ago

IVPN

The anti-affiliate champion candidate holds up: no affiliate program (stated out loud on the homepage), flat honest pricing, quarterly warrant canary, annual th

8
audited canary open source crypto accepted
intro $6 /month
Gibraltar (IVPN Limited, registered in Gibraltar; founder/operated since 2009) commercial vpn 7 h ago

Private Internet Access

The best-evidenced no-logs claim in the business - twice tested in US courts (2016, 2018) and twice found to have nothing - plus the cheapest long-term renewal

7.7
court-proven no-logs audit open source
intro $2.03 /month
United States commercial vpn 7 h ago