Related guides
How to Recognise a Risky VPN App
Updated
Every byte your device sends passes through the VPN app, and it can look at whatever it likes. Two kinds deserve particular suspicion: apps with a regulatory backing that demand real-name registration in the name of “compliance” and hand records upward, and free accelerators of unknown origin that earn from your data, your device, or something they plant. Both have one thing in common: they work fine. The problem is in what you cannot see. Below are ten signals you can verify yourself, what to do if you already installed one, and a three-minute self-check.
Why a VPN app is riskier than an ordinary app
A VPN works at system level: it receives the traffic of every program on the device, including the ones running in the background without your knowledge. An ordinary app can leak what it collected itself; a VPN can leak everything you do on that device. The bar for choosing one has to be far higher.
“Nothing happened” is not evidence of safety. Logging, reporting and injection happen on the server or in the background where the user feels nothing; the consequences often arrive months later and cannot be traced to a specific app.
Ten signals
- Unknown origin: the installer arrives through a chat group, a file-sharing link or a QR code, with no official site or store page. A legitimate client comes from an app store, the developer’s site, or a release page whose signature can be checked.
- It asks you to install a root certificate: “trust this certificate”, “install this profile”, trust a CA. With a root certificate installed it can decrypt all your HTTPS traffic, banking and email included. A normal VPN never needs this.
- Excessive permissions: a VPN that wants contacts, SMS, call logs, precise location or your photo library. A VPN needs only the permission to build a tunnel.
- Identity checks: registration requires an ID card, a face scan or a Chinese phone number. That is exactly how a “compliant” VPN ties your identity to your traffic records; a legitimate service needs an email address.
- Proprietary protocol and a closed client: usable only through its own app, with no support for any standard protocol (AnyConnect, OpenVPN, WireGuard, sing-box), so you cannot verify with an open-source client what it actually sends.
- Free with no visible income: no paid tier, no ads, no business customers, yet running for years. Mainland exit bandwidth is metered; a service that charges nothing collects elsewhere.
- No company, no support, no history: no operating entity to be found, nobody to contact, a domain registered less than a year ago, frequent renames.
- Abnormal background traffic: the device keeps uploading while idle, battery and data drain fast. It may be using your device as someone else’s exit, or syncing your data.
- Marketing that stresses “official”, “registered” and “legal and compliant” while implying everything else is illegal: the classic pitch of the regulatory-backed apps, whose compliance consists of logging and reporting.
- Store ratings that are uniformly glowing, reviews that read alike, and download counts out of proportion to review counts: bought.
How to verify
- Check the protocol: does the site say which protocols it uses and whether third-party clients work? A service reachable with OpenVPN, AnyConnect, sing-box or Tailscale lets you capture and inspect what is sent.
- Check permissions: after installing, open the system settings, revoke everything except the VPN permission, and see whether it still works. If not, uninstall.
- Check certificates: iOS Settings → General → VPN & Device Management; Android Settings → Security → Encryption & credentials → Trusted credentials → User; Windows certificate manager → Trusted Root Certification Authorities. Anything it installed: delete it and uninstall the app.
- Check for leaks: while connected, open a DNS-leak test and an IPv6 test page to confirm resolution and addresses go through its servers; then open an HTTPS site and confirm the certificate issuer is the site’s real CA.
- Check the operator: does the site name a company or team, say how long it has operated and where support is; is there a refund policy; does the privacy policy state specifically what is logged?
If you already installed one
- Uninstall it, then check the locations above and remove any certificate or profile it installed.
- Change passwords — banking, email, everyday accounts — especially any you logged into while using it.
- On accounts with two-factor authentication, review the login history and remove unfamiliar devices.
- If it went on a router, factory-reset and reflash official or verifiable firmware.
How we make ourselves verifiable
RoyalShield does not ship its own app: clients come only from the official upstreams — Cisco, OpenVPN, sing-box/Hiddify, Tailscale — mirrored unmodified, and you can replace our download with the official or open-source build at any time. Every protocol is standard and can be inspected with a packet capture.
Registration needs an email address only — no phone number, no ID. What we log is on the About page: email, plan, expiry, and the duration and volume of each connection, for billing; no content, no ad injection, no data sales.
No certificates, no contacts, no location. If a client claiming to be ours ever asks you to install a root certificate, it is not ours.
FAQ
Is everything free unsafe?
Open-source clients — OpenVPN, sing-box, Tailscale — are free and trustworthy. The risk is in free services, not free software; ask what the service lives on.
Is an app safe because it is in the app store?
Listing only means it passed the store’s automated review; it says nothing about server-side logging. Check the permissions, identity requirements, protocol and operator from the ten signals — the store does not do that for you.
How can I tell whether a VPN logs my content?
You cannot from the client side. You can only judge how much verification it allows: standard protocols, open-source clients, a specific privacy policy, an identifiable operator. If it offers none of the four, treat it as logging.
Can router firmware carry the same risk?
Yes — firmware of unknown origin can hijack the entire home network. Flash only official OpenWrt or firmware whose source you can verify; ours is built from OpenWrt with only the route components and split-routing rules added.
Related pages
- How we differ from other VPNs →
- Free or paid China VPN? →
- Tencent Video or iQIYI blocked abroad? Fix it in 5 steps →
- About us: how it is built, what we log →
- How to Choose a China VPN →
- Does Cisco AnyConnect Work in China? →
- Choosing a VPN Router →
- How to Import a sing-box Subscription →
- China VPN for Students Abroad →
- What a Web Proxy Is and When to Use One →
- What the Private Network (Tailscale) Is →
- How to Use OpenVPN and When to Choose It →
- What the Router Firmware Does →
- How to Reach Us and Never Lose Contact →
- Which Connection Method to Choose →
- Which Region Is Fastest from Inside China →
- For the TV and the Grandparents at Home →
- Watching Home Cameras and a NAS in China from Abroad →
- What to Do When iOS Cannot Install an App →
- Cannot Connect, Slow, or Dropping: What to Check →
- Setting Up for Business Trips and Travel →
- On a Company Laptop: No Admin Rights, Corporate VPN Already On →
- Many Devices, One Setup, No Redo on a New Phone →
- Routing a Synology or QNAP NAS →
- Routing a Linux Server and Command-Line Tools →