LeoTun

Internet Freedom Alliance

2026-10 sing-box upgraded: old configs no longer work. Sign in and re-scan the code on the sing-box page, once per device.
2026-09 New router firmware is out — please update. OpenVPN is back: download a profile, import it, and connect in one tap.
2026-09 New Personal plan: 4 USD/month for 2 devices, routers included — everyone should have a VPN router.
HomeRouterOpenVPNCiscoHiddifyProxyPrivateContact

Related guides

Is a VPN Safe to Use? Who Can See What

Updated 2026-10-08

The short answer: a VPN is an encrypted tunnel, and how safe it is depends on who is at the other end. With a VPN on, your local network and internet provider see only that you are connected to a server, not which sites you visit. That view moves to the VPN operator, who can see the domains you visit and when, but not the content of HTTPS pages. So “is a VPN safe” comes down to three questions: who runs it, which app you installed, and what permissions it asked for. This guide sets out what each party can see, gives a five-minute self-check, and lists what a VPN does not protect you from.

Who sees what once the VPN is on

  • Your local network and internet provider (home broadband, office or campus Wi‑Fi, a café hotspot): they see that your device is connected to a server, when, and how much data moved. They do not see the domains you visit or the content.
  • The VPN operator: sees your source IP, the domains or addresses you visit, the timing and the volume. Content inside HTTPS sites — pages, passwords, chats, payment details — is not visible to it.
  • The sites you visit: they see the exit IP instead of your home IP. Once you log in, though, the site knows who you are, and the cookies in your browser still identify you.
  • Software on the device: what your apps, keyboard and browser extensions can see has nothing to do with the VPN and is the same with it on or off.

HTTPS content is hidden; domains and timing are not

Nearly every site and app uses HTTPS today: a second layer of encryption between your device and the site, with the keys held only at the two ends. The VPN server passes that encrypted data along and cannot open it. Your banking password, the body of an email and your chat messages look the same to a VPN operator as they do to an internet provider: ciphertext.

What stays visible is the writing on the envelope: which domain, at what time, how much data. Without a VPN your local network and provider see that; with a VPN the operator does. A VPN moves that visibility from one party to another, which is why the choice of operator matters most.

Content becomes visible in two cases. One is a site still on unencrypted HTTP, which the address bar marks “Not secure”. The other is a root certificate installed on your device by someone else, which lets them decrypt HTTPS. The second is the one to guard against, and the self-check below shows where to look.

Safety depends on three things

These three questions settle most of it. For how to verify each one, and what to do if a questionable app is already installed, see How to recognise a risky VPN app, which lists ten signals you can check yourself.

  • Who runs it: can you find the operating entity, how long has it been running, is there support you can reach, and does the privacy policy say exactly what is kept? The operator now holds the view of where you go, so its trustworthiness comes first.
  • Which app you installed: a standard client from an app store or the developer’s own site (Cisco, OpenVPN, Hiddify, Tailscale and the like) can be verified. An installer passed around in a group chat or a file share, or a service that only works with its own app, cannot.
  • What permissions it asked for: a VPN needs one permission, to set up the tunnel. Contacts, SMS, photos, location, or a request to install and trust a certificate all go beyond what a VPN has any use for.

Is a VPN safe on an iPhone? Can you be monitored?

A VPN app on an iPhone runs inside the system sandbox. The only thing it receives is the ability to set up a VPN tunnel, and the “Would Like to Add VPN Configurations” prompt on first connection is the normal step. It cannot read other apps’ data, your photos or your messages unless you grant that separately.

Three things deserve attention on an iPhone: anything that asks you to install a profile and trust a certificate; apps installed outside the App Store through enterprise signing or device management; and a phone issued and managed by an employer or school, where the administrator can see more than any VPN. Open Settings → General → VPN & Device Management and make sure every entry there is one you recognise.

As for being monitored: your carrier can see that you are using an encrypted connection and which server it goes to, not the sites or content inside it. The VPN operator can see domains and timing. Neither sees HTTPS content.

On an iPhone, LeoTun uses official clients from the App Store — Cisco’s own app for the Cisco method, Hiddify for the Hiddify method — and never asks you to install a certificate. If the store does not show them, see what to do when iOS cannot install an app.

Is a free VPN safe?

There are two kinds of free. Free software — open-source clients such as OpenVPN, Hiddify and Tailscale — costs nothing and can be verified. A free service is different: servers and bandwidth cost money, and a service that does not charge you recovers the cost elsewhere, usually through ads, collecting and selling usage data, or using your device as an exit for other people.

So judge a free VPN by what keeps it running, then apply the three questions above. For anything involving logins, payments or work, use a service whose operator you can identify. A fuller comparison is in Free or paid China VPN?

A five-minute self-check

  1. Source: did the app come from an app store or the developer’s site? If the installer came from a group chat, a file share or a QR code, reinstall the same client from the official channel.
  2. Permissions: open system settings, look at what the app has been granted, and turn off everything except the VPN itself. It should keep working.
  3. Certificates and profiles: on iOS, Settings → General → VPN & Device Management; on Android, Settings → Security → Encryption & credentials → Trusted credentials → User. Remove any entry you do not recognise and uninstall the software that put it there.
  4. Exit: once connected, open a page that shows your IP and confirm it is the region you chose. Then run a DNS check as described in DNS leak vs DNS poisoning.
  5. HTTPS: open your bank or mailbox and click the padlock. The certificate issuer should be an ordinary certificate authority. If the browser warns about the certificate, stop there.
  6. Background use: if the app uploads heavily while idle and the battery drains noticeably faster, stop using it and pick another.

What a VPN does not protect against

A VPN protects the path: people on the same Wi‑Fi, the local network and your provider cannot see where you go. Safety inside the device and inside your accounts comes from system updates, software from proper sources and careful habits. The items below stay in your hands with or without a VPN.

  • Phishing: fake login pages, fake support agents, fake prize links. If you type the password yourself, the encrypted tunnel delivers it faithfully. Read the domain before you type.
  • Malware: a trojan on the device, cracked software with a backdoor, or a browser extension of unknown origin gets your data before it ever enters the VPN.
  • Logged-in accounts: sign in to WeChat, Google or Taobao and the platform knows it is you, whatever the exit IP. A VPN changes your address, not your identity.
  • Weak and reused passwords: one site leaks and the others open with the same key. Give important accounts their own passwords and turn on two-step verification.
  • Information you hand over: posts you publish, forms you fill in, and the location and contacts access you grant to apps.

What you can verify about LeoTun

  • The clients are the official and open-source builds from Cisco, OpenVPN, Hiddify and Tailscale, mirrored unmodified. You can replace the copy downloaded here with the one from the official channel at any time.
  • Every protocol is a standard one, so you can capture the traffic and inspect it yourself.
  • Registration takes an email address only: no phone number, no real-name check.
  • We keep only the information billing needs. We do not record the sites you visit, inspect traffic, inject ads or sell data.
  • No certificate to install, and no request for contacts or location.

FAQ

Can a VPN operator see my passwords and messages?

Not over HTTPS. Passwords, chats and payment details are encrypted between your device and the site, and the VPN server only relays ciphertext. What it can see is the domains you visit, the timing and the volume. The exception is a root certificate from someone else on your device, so never install a VPN that asks you to trust a certificate.

Is a VPN worth using on public Wi‑Fi?

Yes. With it on, other people on the hotspot and the hotspot’s owner see one encrypted connection. They cannot see the domains you visit or alter what you receive. This is one of the most practical uses of a VPN.

Does a VPN make me anonymous?

No. A VPN replaces the address websites see with the exit IP and hides your destinations from your provider. The VPN operator still knows your source IP, and your logged-in accounts and browser cookies still identify you. Treat it as an encrypted route.

Should I allow “Add VPN Configurations” on an iPhone?

Yes, that is the normal authorisation for an app to set up a tunnel. The prompt to refuse is a different one: installing a profile and then enabling full trust under Certificate Trust Settings. That hands over the key to your HTTPS traffic, so cancel it.

How do I test whether my VPN is safe?

Check four things once connected: the exit IP is the region you chose; a DNS leak test shows no servers from your local provider; an IPv6 test does not show your local address; and an HTTPS site shows an ordinary certificate authority as issuer. Then confirm in system settings that the app installed no certificate.

Are free VPNs usable at all?

Free open-source clients are fine. A free service depends on what funds it. If you cannot tell where the income comes from, assume it earns from your data or your device and keep important accounts away from it.

Related pages

  • How to recognise a risky VPN app →
  • Free or paid China VPN? →
  • DNS leak vs DNS poisoning: how to check and fix →
  • What to do when iOS cannot install an app →
  • What we log and what we never do →
  • Tencent Video or iQIYI Blocked Abroad? Fix It in 5 Steps →
  • How to Choose a China VPN →
  • Does Cisco AnyConnect Work in China? →
  • Choosing a VPN Router →
  • How to Import a Hiddify Subscription →
  • China VPN for Students Abroad →
  • What a Web Proxy Is and When to Use One →
  • What the Private Network (Tailscale) Is →
  • How to Use OpenVPN and When to Choose It →
  • Flashing the Router Firmware: From Stock to Ours, Step by Step →
  • What the Router Firmware Does →
  • How to Reach Us and Never Lose Contact →
  • Where We Beat Other VPNs →
  • Which connection method fits which scenario →
  • Which Region Is Fastest from Inside China →
  • For the TV and the Grandparents at Home →
  • Watching Home Cameras and a NAS in China from Abroad →
  • Cannot Connect, Slow, or Dropping: What to Check →
  • Setting Up for Business Trips and Travel →
  • On a Company Laptop: No Admin Rights, Corporate VPN Already On →
  • Many Devices, One Setup, No Redo on a New Phone →
  • Routing a Synology or QNAP NAS →
  • Routing a Linux Server and Command-Line Tools →
  • “Damaged” on a Mac, and how to verify the installer →
  • Using RustDesk for remote help →
  • What macOS's Network Extension Approval Is →
  • How split routing works on a VPN router →
  • Not enough device slots? Temporary vs long-term fixes →
  • Dropbox and other apps want an HTTP / SOCKS proxy — what to do →
  • How to Get Good Answers from the AI Support →
  • How to manually uninstall the Cisco client on a Mac →
  • Cisco error “remote user is disabled” →
  • Refund Policy and Feedback →
  • What a VPN is, what it is used for, and how to connect →
  • VPN vs “airport” proxy subscriptions vs accelerators →
  • VPN protocols compared: WireGuard, OpenVPN, AnyConnect, Hysteria2 →
  • VPN Slow? How to Run a Speed Test and Find the Cause →
  • VPN on iPhone: which method to use and how to set it up →
  • VPN on Android: which client to use and how to set it up →
  • VPN on a computer: which method for Windows and Mac →
  • Using ChatGPT in China: Why It Fails and What Matters →
  • No Verification Code for an Overseas App? Telegram, Instagram and TikTok in China →
  • What Is OpenWrt? Soft Routers, Bypass Gateways and VPN Routers for China →
  • How to Use a VPN in China: Set Up Before You Land →
  • VPN Not Working in China? Why, and What to Try →
  • Best VPN for China: How to Judge One Yourself →
  • Do VPNs Work in China? What NordVPN, ExpressVPN and Others Say Themselves →
  • eSIM vs VPN in China: Which One Do You Need? →
  • Travel VPN Router for China: Setup and Who Needs One →
  • WhatsApp in China: Does It Work and How to Set It Up →
  • Google in China: Gmail, Maps and Google Play Explained →
  • YouTube in China: How to Watch, and Why Netflix Refuses →

Flags by Twemoji (CC-BY 4.0)·IP Geolocation by DB-IP

AboutGuidesContact

© 2007–2026LeoTun