You see the ad at 11pm, scrolling in the dark. It’s for a specific brand of hiking boots — the exact ones you spent an hour researching last Tuesday. But here’s the thing that makes your stomach tighten: you did that research after you connected to your VPN. You were inside the “private” tunnel. You were supposed to be a ghost. And someone, somewhere, watched you anyway.
The short version: A VPN cannot be more private than the company that owns it. Many popular VPNs are controlled by holding companies, private-equity firms, or antivirus giants whose entire business is monetising data — Kape Technologies alone owns ExpressVPN, CyberGhost, Private Internet Access and ZenMate. That ownership is the real privacy policy. The no-logs promise on the website is only as good as the balance sheet behind it.
Why does your VPN feel leaky? Because your data is their inventory
You’ve done the work. You clear your cookies, you use encrypted messaging, you pay a monthly fee for a Virtual Private Network. It’s your digital shield — the tool that promises to cloak your IP address and wrap your traffic in encryption. You are meant to be invisible.
The 12-point setup for a private, secure, high-output digital life — in one afternoon. No spam, unsubscribe anytime.
And yet. The chill.
That weirdly specific ad. The push for a service that somehow knows the exact problem you were quietly trying to solve. It feels like the walls of your private tunnel are made of glass. So you blame yourself. Maybe you misconfigured a setting. Maybe you’re not “tech-savvy” enough. Maybe you’re just unlucky.
Stop. The problem was never your settings.
It’s not a glitch you missed. The system you’re paying to escape has simply put on a new mask. The villain here isn’t a cartoon bad actor in a hoodie. It’s the silent machinery of corporate ownership that has quietly bought the very companies you trust to protect you. An economy that treats your privacy not as a right, but as an under-monetised asset. They build the tunnel, charge you for entry, and then decide — in a boardroom you’ll never see — what your journey through it is worth.
Which leads to the one thing nobody selling you a VPN wants you to notice.
The real VPN policy isn’t written on the website — it’s on the ownership filing
The promise of a VPN is a simple transaction. You connect, your data is encrypted, you become anonymous. But that anonymity isn’t conjured from thin air. It’s delegated. You are handing your entire digital life to a company and trusting it not to look.
Here is the reframe that changes everything:
You are not buying encryption — you are buying a company’s promise not to profit from you, and that promise is only worth as much as the owner you’ve never heard of.
Read that again, because it inverts the whole checklist. You vet a VPN for its no-logs policy, its AES-256 encryption, its server speed. All real, all worth checking. But a no-logs policy is a sentence on a webpage. It can be rewritten after an acquisition, quietly, on a Tuesday, with no press release. The marketing is the promise. The parent company’s business model is the proof.
This isn’t a conspiracy theory. It’s the boring, documented reality of the industry. The biggest risk signal to your privacy isn’t someone cracking the encryption — that’s expensive and hard. The risk signal is an accountant realising the “anonymised” data flowing through millions of tunnels is a sellable asset. Ownership can pivot overnight. Your private pipe becomes one intake valve in a global harvesting machine.
You paid for a shield. If the shield-maker sells targeting data to the people throwing spears, you were never protected. You were inventory.
How to spot the conflict: the four ownership red flags
You don’t need to become a forensic accountant. You need to recognise four patterns that build a conflict of interest right into the structure — where the company making money one way is fundamentally at war with the thing it promised you another.
Private equity and holding companies: the acquisition machine
A small, principled VPN gets bought by a large holding company whose mandate is not privacy — it’s shareholder return. Your data becomes a line item.
The case study is Kape Technologies. It began life as Crossrider, a firm so associated with adware injection that security tools flagged its software for years. After rebranding to Kape in 2018, it went shopping: it acquired CyberGhost in 2017, ZenMate in 2018, Private Internet Access for around $95 million in 2019, and then bought the industry giant ExpressVPN in 2021 for roughly $936 million.
Four “independent” shields. One owner. A company with adware in its DNA.
The question stopped being does PIA keep logs? The real question is: what does Kape do with the aggregated, portfolio-wide view of millions of users across four brands that all quietly report to the same parent? That consolidation creates surveillance potential no single service could achieve alone.
Antivirus giants: the “ecosystem” trap
Antivirus companies love to bundle a VPN. It looks like a natural fit. But their core business runs on collecting telemetry — behaviour, system data, browsing signals — to “improve the product.” The line between data for security research and data for sale is razor-thin.
Avast is the cautionary tale. The antivirus giant, which also owned AVG and offered VPN services, ran a subsidiary called Jumpshot that packaged and sold the detailed browsing histories of Avast’s own users. A joint Motherboard and PCMag investigation in January 2020 exposed it — click-by-click data, sold to corporate clients, marketed as “anonymised” (a word repeatedly shown to be technically meaningless). Avast shut Jumpshot down within days. In 2024, the US FTC fined Avast $16.5 million and banned it from selling browsing data. The lesson is structural: a business built on collecting data cannot honestly sell you a product built on hiding it.
Adware and data-broker lineage: the wolf at the door
A VPN with direct historical ties to adware, harmful software distribution, or data brokerage is not a reformed sinner. It’s a predator that learned a better hunt. Asking it to guard your privacy is asking the fox to mind the henhouse. These companies rebrand constantly, so the principle matters more than the name: investigate the history of the parent, not the marketing of the brand it just acquired. A business that profited from violating privacy last year didn’t grow a conscience — it changed its strategy.
Hidden jurisdictions: the shell game
A VPN may boast a home in a privacy haven — Panama, the British Virgin Islands. But dig into the corporate structure and the parent may be registered in the United States or the UK, both core members of the Five Eyes intelligence alliance (and its Fourteen Eyes extension).
That’s not an accident. It lets the VPN wear the marketing halo of a privacy-friendly jurisdiction while ultimate financial and strategic control sits somewhere subject to subpoenas, national security letters, and gag orders that bypass the laws where the servers physically sit. The more scattered the ownership, the less accountability survives.
It isn’t always malice. It’s incentives. When a parent company owes a fiduciary duty to shareholders, a subsidiary’s no-logs policy is a feature that can be negotiated away next quarter. The tension is baked into the org chart.
Frequently asked questions
What is a “no-logs” policy, and does ownership affect it?
A no-logs policy is a VPN’s promise not to store data that could identify you or your activity — your real IP address, browsing history, or connection timestamps. Ownership fundamentally affects it. Even if the VPN brand keeps no traffic logs, the parent company can aggregate other data — payment details, account email, telemetry from its other products — to build a profile that undermines the entire point. The policy lives on a webpage; the incentive to break it lives on the parent’s balance sheet. That’s why the only version worth trusting is one confirmed by a recent independent audit, not a marketing bullet point.
How can I research who owns a VPN provider?
Start on the “About Us” page — if it’s vague about ownership, that’s your first red flag. Then search the VPN name plus “acquired by,” “parent company,” or “investors” on Bloomberg, Reuters, or Crunchbase, and look the parent up on a corporate database like OpenCorporates. If you can’t identify the owner in five minutes, assume the worst. Transparency is a choice, and companies that want your trust make ownership easy to find, not buried under a chain of shell entities.
Are free VPNs always a privacy risk?
Almost without exception, yes. Running a global server network costs millions. If you’re not paying with money, you’re paying with data. Free VPNs have been caught injecting ads, selling browsing histories, shipping weak or absent encryption, and in some documented cases acting as data-collection fronts. They aren’t privacy tools that happen to be free — they’re data-collection tools wearing a privacy costume.
Does this mean every large VPN is compromised?
No — but your skepticism should stay high. A provider that publishes transparent ownership and submits to regular, public, independent audits of its no-logs claim can be far safer than an opaque conglomerate. Demand proof, not promises. Look for a named auditor, a recent date, and a report you can actually read. That verifiable trail is the gold standard; everything else is a slogan.
The sovereign choice: own the motive behind your tunnel
This isn’t about making you paranoid. It’s about making you precise.
Knowing who owns your VPN doesn’t disempower you — it does the opposite. It turns you from a passive “user” into someone who audits the system before trusting it. You stop reading marketing and start reading incentives. You understand that a no-logs promise from a company owned by a data broker is worth exactly nothing. You see that real privacy isn’t a feature you buy — it’s a structural integrity you verify.
The private tunnel is only ever as strong as the motives of its owner.
And you can test yours right now, in the next 60 seconds. Open a new tab. Search your VPN’s name plus “parent company.” If the answer is a private-equity firm you’ve never heard of, a tech conglomerate with a data scandal in its past, or a business that used to make adware — you have your answer, and you have it before it costs you anything.
That one search flips the whole board. A minute ago the watching happened to you. Now you’re the one doing the watching. You’re not just connecting to a server anymore — you’re choosing an ally, with your eyes open. And in the fight for your own mind, knowing who owns the tunnel isn’t the last victory.
It’s the first one. You just took it.
The Signal - free dispatch
One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.
Free. No spam. Unsubscribe any time.
Join the Inner Circle
Weekly dispatches. No algorithms. No surveillance. Just sovereign intelligence.
Zero spam · Fully private · Sovereign by design.