Riseup VPN
Structurally the most trustworthy free VPN: a Seattle activist collective running RiseupVPN as a donation-funded experiment - no account, no IP logging, open-so
2020 breach exposed ~900GB of user logs/DNS records despite 'zero-log' claims. Still distributed. Textbook free-VPN trust failure.
by the vpncomparison editorial desk · review version 1 · prose updated 2026-09-28 · facts as of 2026-09-27 · how we verify
UFO VPN is a free, ad-supported service owned by dreamfii, operating under opaque Hong Kong jurisdiction. It markets itself as a zero-log provider but suffered a catastrophic 2020 breach exposing nearly 900GB of user data - including plaintext passwords and session logs - directly contradicting its claims. This is a textbook case of trust failure in the free-VPN space.
UFO VPN’s no-logs claim is court-proven-logging? No - worse. In 2020, researchers found an unsecured database containing 1.2TB of user logs: real IP addresses, session tokens, geo-tags, and even plaintext passwords for ~23 million accounts. Despite advertising “zero logs,” the data proved extensive logging. No audits exist, no warrant canary, and jurisdiction in Hong Kong offers no transparency. This isn’t unproven - it’s disproven by evidence.
There is no paid tier listed - only an ad-supported free tier. However, the “free” model here is predatory: the 2020 breach revealed UFO VPN injected ads at the network level, monetizing user traffic directly. You pay with your data. No renewal pricing, contracts, or refunds are documented because the service operates on exploitation, not subscription. There is no honest pricing - only hidden costs.
No documented protocols, obfuscation, kill switch, multihop, or P2P support. Servers count, countries, and device support are unknown. The app does not support streaming or advanced privacy features. Independent testing has not been conducted, but the 2020 breach confirms the infrastructure was poorly secured. This is a bare-bones app with no transparency - assume minimal functionality and maximum risk.
Owned by dreamfii, a company with unclear corporate transparency, operating from Hong Kong. The 2020 breach exposed 1.2TB of user data, including sensitive identifiers and plaintext credentials, while the service actively claimed to keep no logs. A second exposure followed weeks later, partially wiped by the “Meow” bot. These are not isolated incidents - they reflect systemic negligence. Facts are reported, not verified, but the evidence speaks clearly.
UFO VPN offers no known obfuscation methods. Given its history of logging, poor security, and exposure of user IPs and traffic metadata, it is unsuitable for use in censored environments like China, Iran, or Russia. The app itself has been shown to inject ads and track user activity - making it a surveillance vector, not a shield. Avoid for any censorship-circumvention use.
Do not use UFO VPN. It logged user data despite claiming otherwise, exposed millions of records, and monetized traffic via ad injection. This is not a privacy tool - it’s a data harvesting operation. Free alternatives exist that are open-source, audited, and transparent. The money trail is unclear, but the risk is certain.
| Intro price | see provider site |
|---|
See the 3-year total next to the marketing number: true-cost calculator →
affiliate status not verified yet
If we sign up for this program, every link here becomes rel="nofollow sponsored" and this box stays. Until then our links are plain redirects with zero tracking. Ranking logic physically cannot read affiliate fields - here is the proof.
Before you pay: check the renewal price, the refund window, and whether a cheaper or free path covers your use case - the honest checklist.
Based on our checks as of 2026-09-27: UFO VPN scores 4.7/10 in our weighted review. We logged 3 red flags (listed above). User reports, ownership and the incident record are documented with dated sources in the meta-review below.
An ad-supported free tier that injects ads into your traffic and has exposed plaintext passwords, IPs, and session logs. No security, no privacy, no transparency - just risk.
There is no paid plan documented - only a free tier. But you “pay” with your data: browsing habits, IP, and device info were all logged and leaked.
In 2020, 1.2TB of unsecured logs were found: real IPs, session tokens, geo-tags, and plaintext passwords for ~23M users - proving logging despite “zero-log” claims.
No. It lacks obfuscation, has poor security, and logs user data. It’s been shown to inject ads and expose traffic - making it dangerous in high-censorship regions.
Unknown - no payment or signup details are documented. But the 2020 breach showed plaintext passwords stored, meaning no real anonymity even if claimed.
It already did - twice in 2020. User data was exposed en masse. With no transparency or accountability, another breach is likely, not preventable.
Consider Proton VPN’s free tier (independent, Swiss-based, audited) or Mullvad (flat-priced, privacy-first, open-source). Avoid free apps with no transparency.
Structurally the most trustworthy free VPN: a Seattle activist collective running RiseupVPN as a donation-funded experiment - no account, no IP logging, open-so
1M+ (TTP: ranked #82-99 US App Store 2024) installs. Not independently audited in this dossier Included as second instance of the multi-brand farm pattern.
Nonprofit privacy institute; VPN is a member perk, not a product. (Specific VPN subpage 404'd at crawl 2026-09-27 - site restructured.)
No comments yet - be the first. Posting runs a short proof-of-work in your browser (anti-spam), no account needed.