Mayak Blog

A safe VPN: how to tell whether you can trust it

The safety of a VPN is not a property of the app but a decision about whom to trust: whoever runs the tunnel takes your carrier’s place. Below: what exactly it can see, what to ask about “logs” and the country, what free services pay with, and how to tell an honest one from a trap.

In short. A VPN is safe to use only if three things about it can be checked: what it sees and keeps — written in a policy as a list with retention periods, not as a “no logs” slogan; who is behind it and under which country’s law it works; and how it earns its living. What a service actually does cannot be checked from outside, so trust what is written and verifiable, not promises. For Mayak that is the privacy policy (edition of 21.09.2026): the list of records, the periods and what we do not collect — below.

We make Mayak, a private network for Android and Android TV. Everything said about us below comes from our privacy policy and is in plain text: check it. 3 days free after you confirm your email, no card needed.

What a VPN service sees — and why that is the main question

Without a VPN, the road your traffic takes is visible to whoever carries it: your carrier or the owner of the Wi-Fi. They know which sites you go to: we measured this in the article on public Wi-Fi — the site name is visible even over HTTPS. With a VPN your carrier sees one connection to one server, and the site names are now seen by the service. The visibility does not disappear; it moves to whoever you handed the tunnel to (how it works).

Android says so outright. The first time any such app connects, the system shows its own window, and the text in it belongs to the system, not to the developer:

“… wants to set up a VPN connection that allows it to monitor network traffic. Only accept if you trust the source.”

What the service does not see is the content of pages opened over HTTPS: mail and passwords are encrypted between your device and the site, and the tunnel changes nothing there. That is why the main question when choosing is not “how fast is it” but “what does this service do with what it sees”.

Logs: three questions instead of a “no logs” slogan

“No logs” is a slogan: it cannot be checked from outside, and the word “logs” means three different things. Ask about each separately:

  • What you open. Whether site addresses and content are kept. An honest answer here is “no”, and it must stand in the policy, not just on a banner.
  • Who connected and when. Address, time, traffic volume: is it recorded, is it tied to the account, how long is it kept. A service may need some of this to run and to fend off attacks; what matters is that the record is named and has a retention period.
  • What leaves the app. Analytics, reports, third-party SDKs and trackers: what is sent, and to whom.

A good answer is written down: a list and retention periods. A policy of three paragraphs about “caring for your privacy” contains no answer.

How it is with us. This is what our privacy policy says (edition of 21.09.2026, sections 2 and 6):

RecordKept forWhy, and what is not in it
Address and time of requests to our servers90 daysrunning the service and defending against attacks
Daily traffic volume per account180 daysbyte counters only: no site addresses, no app names
The app’s action log: “Connect”, outcome, error90 daystied to the account; no site addresses or names of other apps in it
App download from the site: browser, referring page30 daysdeleted automatically
A technical connection log — only if you press “Send log” yourself90 daysused to help with your problem

We do not record the content of traffic or the sites and apps you use, we do not sell data, and there are no advertising trackers. Requests to the DNS server — the questions “what is this site’s address” — are, by the policy, not stored and not linked to an account. We do not write “no logs”: the table above shows why it would be untrue (the same is in the article on VPNs in plain words).

Country: three different questions instead of the word “jurisdiction”

In advertising, “jurisdiction” is a trump card, but the word covers three different questions:

  • Where the company lives. Whose law it works under and who can serve it with a demand.
  • Where the servers stand. Sites see your address from there; that alone says nothing about where data is kept.
  • Where account data and logs are kept. That may be a third country.

A country’s name in an ad guarantees nothing: the law of any country can require a company to keep something or hand it over on request. What exactly is visible not from a slogan but from the policy section on disclosure to third parties.

How it is with us. The operator of personal data is named in section 1 of the policy, with the address support@mayaknetworks.com; data is processed under the Russian Federal Law 152-FZ. Section 7: we do not pass data to third parties except in cases directly provided for by law — on a lawful request of authorised bodies. Only what is kept can be handed over on such a request, that is, the records in the table above; the content of traffic is not among them. There are two technical exceptions: notifications go through Google Firebase Cloud Messaging (a device token, not the message text), and DNS goes by default through Cloudflare and Google (to them the source looks like our node). The exit countries as of 29 September 2026 are the Netherlands, Poland, Russia and Germany; the current list is on the site’s home page.

You do not have to believe us — you can check. The policy is open, Android shows the consent window itself, and the trial is free and needs no card: we ask for no payment details for it. A confirmed email opens the access — 3 free days.

Free ones: what they live on

Servers, links and development cost money every month. If you are not the one paying, somebody else is paying the bill, and it helps to know who. The four documented ways “free” pays for itself are in the article on free extensions; how that compares with paid is in “Paid or free”.

In a CSIRO study (a 2016 paper) 283 Google Play apps with the VPN permission were checked: for 38% at least one antivirus found something. The data is old, but the conclusion holds: having the VPN permission is not a mark of quality, and being paid is not a guarantee.

How it is with us. There is no free plan forever: there is a trial, and we live on subscriptions.

How to spot a trap: six signs you can check

  1. Where the app comes from. An app store or the service’s own site — not a link from a chat or a “file from a channel”. In November 2022 ESET researchers (report) took apart a site posing as a real service and handing out only Android files with spyware code inside; they were never in Google Play.
  2. Is there a policy with a list and retention periods, and is the party responsible for the data named, with an address to write to.
  3. How the service earns its living. “Free forever” with no answer to that question is a warning sign.
  4. What it promises but does not control. “100% anonymous”, “works everywhere, always” — no honest service promises that. We do not, and we wrote about it separately.
  5. Terms of payment and withdrawal. Is there an offer, can you withdraw, and what is refunded. If a card is asked “for verification” of a trial, assume you will be charged at the end (why).
  6. What the app asks for. A tunnel needs one system permission — the “Connection request” window. Contacts, SMS and the call log are not needed for a tunnel: if an app asks for them, ask why.

All six take an evening. What to compare before paying, beyond trust, is in “How to choose a VPN: seven questions before you pay”.

How to check us without taking our word

We do not ask you to take our word for it: here is what you can check yourself.

  1. Open the privacy policy and compare it with the table above: sections 2, 6 and 7. If the edition is newer than 21.09.2026, what the policy says is what holds.
  2. Press “Connect” and read the Android window: the decision is yours, not ours.
  3. Take the trial: it is free and needs no card, and nothing is charged at the end (how it works).

What we tested

  • The privacy policy, edition of 21.09.2026 — read in full on 29 September 2026; the list, the periods and the exceptions above come from sections 2, 6 and 7.
  • The list of exit countries — requested from our server on 29 September 2026: the Netherlands, Poland, Russia, Germany.

What we do not know

  • What other services do. We did not check other apps and do not name them; the criteria above are questions, not verdicts.
  • Whether our policy is followed on the servers. The site carries no independent audit, so the policy is the company’s written statement. By measurement we can show what is visible outside the tunnel (article), but not what sits on the servers.
  • The CSIRO and ESET studies. We cite them by their links and did not reproduce them; the CSIRO data is from 2016.

Short answers

Can I trust a VPN? Only in what has a written answer: what it keeps and for how long, who answers for the data, how it earns its living. Not the word “safe” in an ad.

Is a free VPN safe? Look at how it earns its living. If there is no answer, you are paying — with data or with your connection. More in the article on free extensions.

Does a VPN see which sites I open? Technically yes: site names are what your carrier used to see. The service does not see the content of HTTPS pages. What it keeps is a question for its policy.

Is Mayak safe? Traffic is encrypted from your device to our server; we do not read or store its content — that is what the policy says. What we do keep is in the table above.

Try Mayak

A private network for Android and Android TV. What we keep and for how long is in the privacy policy; what we do not know, we write down as it is. 3 days free after you confirm your email, no card needed.

The account is created right in the app. A confirmed email opens the access — 3 free days.