# URnetwork vs Hola VPN

Hola is one of the most installed unblocking tools ever made, and its free
tier is paid for by enrolling users' devices as peers in the Bright Data
proxy network; URnetwork is the same residential idea rebuilt on explicit
opt-in, metered contracts, and a filter at each member's exit.

**Choose Hola** if you want one-click unblocking in a browser, no account or
payment, and the most established residential peer network. **Choose
URnetwork** if you want exits that opted in, protection engineered for the
member at each exit, and open code you can verify. Both route traffic
through real household addresses. The difference is what surrounds the
person carrying it.

[Hola VPN](https://hola.org) is built by Hola VPN Ltd. of Israel and
pioneered the peer-to-peer residential model in consumer software. Its
homepage advertises "more than 324 million members" alongside "263 million
Downloads" (hola.org, August 2026; both figures are the company's own). Its
FAQ describes today's architecture as a datacenter front end: clients reach
"our standard data center proxy servers", and a request then goes to the
proxy itself, to another datacenter, or "to our P2P network". Paid tiers
exist as well.

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | Hola | URnetwork |
|---|---|---|
| Setup | One click in the browser; no account or sign-in | Instant Account in one tap; the extension pairs with the ur.io web app |
| Funding the free tier | Free users "may be a peer on the Bright Data network"; Premium is the documented opt-out | Free daily allowance funded by Pro subscriptions; no peering attached |
| Network scale | Self-reported: "more than 324 million members" and "263 million Downloads" on one homepage | Young member network; live counts in the app, 2,000+ real cities by URnetwork's own count |
| Joining the exit pool | A condition of free use, stated in the legal and help pages | An in-app switch, off by default; share publicly or with your own devices only |
| Protection at the exit | Policy controls: peers route "only ... specific requests from whitelisted sites", drawn on while idle | An open-source filter on the member's device drops file-sharing and attack traffic before it leaves their line |
| Verifiability | Closed source; no published independent audit | Open client and server code |

Caveats below the table:

- Post-quantum encryption is URnetwork-side here: the X25519MLKEM768
  client-to-provider session is default in the native apps, skipping any
  provider it cannot seal to rather than downgrading. Hola advertises no
  equivalent. The browser extension has no sealed session; there, the
  operator's data path logs nothing, pinned by a test in the open code.
- Hola states its transport as "https proxy or IKEv2" with AES ciphers; the
  same FAQ also lists PPTP and DES3, both long deprecated. The code is
  closed, with no published independent audit, so no encryption claim can be
  checked from outside.
- Hola is browser-first, with mobile products. URnetwork ships native apps
  on Android, iOS, macOS, Windows, and Linux plus the extension and web app,
  each with an explicit kill switch.
- Hola's free tier costs no money, and Premium prices vary. URnetwork's free
  tier is a daily data allowance; Pro is $5/month or $40/year. Current
  numbers are at [ur.io/products](https://ur.io/products).
- Hola advertises "195 countries to browse from", a marketing count no
  outside party has measured.

## The Bright Data record

Three dates carry the history, and most of the paperwork is Hola's own.

- May and June 2015: 8chan's operator traced a flood of junk requests,
  heavy enough to crash the site's PHP backend, to a paying customer of
  Luminati, Hola's commercial bandwidth-resale arm at the time. Hola
  confirmed it had been selling free users' bandwidth, and its founder said
  most users were "probably not aware of this". In the same weeks,
  researchers published six client vulnerabilities, including remote code
  execution, privilege escalation, arbitrary local file read, and persistent
  tracking, and disputed Hola's claim to have fixed them; Vectra Networks
  documented a console that stayed active while Hola was idle and a Hola
  code-signing certificate installed into Windows' trusted-publisher store.
  These events are a decade old and the client has been rewritten since;
  they defined the risks of low-visibility peering rather than describing
  today's software.
- August 2017: Hola sold a majority stake in Luminati to EMK Capital, a
  London private-equity firm. Luminati became Bright Data in 2021, remains
  an EMK company, and lists Hola's founders as its own. The corporate
  separation is real. The supply relationship continues.
- 14 April 2026, the date on the current privacy policy: "In return for free
  usage of Hola Product and services ... you may be a peer on the Bright
  Data network ... You may opt out by becoming a Premium user."

The disclosure has a location pattern. The peer arrangement is stated in the
privacy policy, the terms, a dedicated Bright Data SDK page, the public FAQ,
and a June 2026 help article. It appears nowhere on the homepage, the about
page, the mobile product page, or the Chrome Web Store listing (all checked
August 2026). What peers receive is the free service itself: compensation in
kind, not in money, and not metered.

## What the policy collects

Hola does not claim "no logs"; its own documents describe collection. The
privacy policy dated 14 April 2026 lists IP address, name and email, payment
details, "names of applications that are installed on the user's device",
operating system and browser type, and "browsing history and access times
and dates", with log data retained "for a period of up to 12 months". The
Chrome Web Store privacy panel for the same product, updated 4 August 2026,
states that the developer does not log browsing activity. Both statements
are current and first-party. With the code closed, neither can be checked
from outside.

![Who can see what — single-party VPN vs Apple Private Relay's closed two-party split vs URnetwork's split knowledge](/docs-assets/infographic-who-sees-what.svg)

*The underlying question: which designs let one party hold your identity and
your activity at once.*

URnetwork's counterpart claims live in code rather than policy. The provider
never receives your source IP on the relayed path, and the operator cannot
read the sealed session, so no single party holds your identity and your
destinations together. What the operator does store is recorded in the
[threat model](/docs/threat-model).

## Carrying strangers' traffic

When traffic exits from a household connection, the question is what
protects the household, and the exposure is symmetrical: strangers'
destinations exit from the peer's address, and outside observers attribute
that activity to the peer's connection. Hola's protections are policy, run
from the network side: peers route "only ... specific requests from
whitelisted sites", devices are drawn on while idle on Windows and Android,
and the terms promise a best effort not to spend battery or roaming data.
The Bright Data SDK page adds that Bright Data "monitors all of its network
traffic to ensure your safety", and that the indexing "runs in the
background even after closing the application". In 2015, peers had no say in
what crossed their lines, and some of that capacity, resold through
Luminati, carried a DDoS attack.

URnetwork's protection runs on the member's own device instead. An
open-source inspection layer at each provider's egress drops file-sharing
and attack traffic before it leaves the member's connection, recording no
destination, domain, or contents. The same filter applies to traffic you
send as a client, so your own torrenting would be dropped too; URnetwork is
deliberately not a torrenting product. Carried bytes use the member's
connection and data plan, and providing can be paused or stopped in the app
at any time. The mechanism is documented in the [overview](/docs/overview).

![Sharing a connection: what protects you — Hola's silent peer monetization vs URnetwork's opt-in, metered, filtered model](/docs-assets/infographic-sharing-safety.svg)

*Consent, a signed contract, and a filter at the member's own exit: the
three protections the 2015 case ran without.*

## Where Hola wins

- Free, casual, one-click unblocking at enormous scale. For a reader who has
  seen how the peer model works and accepts it, nothing is more established
  at that job.
- Nothing to set up: no account, no sign-in, one click in the browser.
  URnetwork's extension requires signing in first.
- The peer arrangement is stated in writing, in the policy, the terms, a
  dedicated SDK page, and the FAQ, and Premium is a real, named opt-out.

## Where URnetwork wins

- Consent. Providing is opt-in and off by default, never a side effect of
  installing a free app.
- Compensation. Members who carry traffic do so under signed, metered
  contracts, as participants in the [UR protocol](https://ur.xyz). On free
  Hola, the free service is the compensation, and the bandwidth is sold on.
- Protection for the participant. The filter runs at the member's own exit,
  dropping file-sharing and attack traffic before it leaves their line, with
  no destination or contents recorded.
- The split. The exit never learns who you are, and the operator cannot read
  the sealed session. No single party holds identity and destinations
  together.
- Verifiability. Open client and server code, versus a closed stack whose
  encryption claims cannot be checked.
- Account anonymity. An Instant Account takes one tap and no email, and is
  restored on a new device by its recovery phrase.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, the operator
  could itself run providers, and no outside party has measured the fleet.
  See the [threat model](/docs/threat-model), §6.1.
- Coverage counts are self-published on both sides. No outside party has
  measured Hola's 195-country claim or URnetwork's city count.
- URnetwork is the younger network, and speed moves with the providers in
  your window.

Hola's limit is structural as well as historical. One company directs the
network and terminates connections at its own proxy servers; the policy
permits broad collection with 12-month retention; and the closed code means
the encryption, the whitelist, and the idle-only rule are promises rather
than anything a user can verify. The record above is Hola's own current
paperwork plus the documented 2015 events.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, so you can test the exits you care about before paying for either
product. More questions are answered in the [FAQ](/docs/faq).
