# URnetwork vs Hotspot Shield

Hotspot Shield built the original mass-market free VPN, ad-funded and
speed-first; URnetwork splits the path so the exit never learns who you are
and the operator cannot read the sealed session.

**Choose Hotspot Shield** if you want a household-name free VPN, apps with
zero learning curve, and consistent datacenter speed. **Choose URnetwork** if
you want the path split between two relay parties, storage limits enforced in
open code, and residential exits you can aim at a city. Hotspot Shield's
privacy case is a written policy with one commissioned review. URnetwork's is
a structure you can check in public code.

[Hotspot Shield](https://www.hotspotshield.com) launched in 2008 under
AnchorFree and built the ad-supported free funnel that feeds a paid Premium
product. Its proprietary Catapult Hydra transport has a speed reputation
strong enough that rival security vendors have licensed it, and the apps also
offer WireGuard and IKEv2. The brand has had four corporate homes. AnchorFree
became Pango, was acquired by Aura in July 2020, and was spun back out as a
standalone Pango Group in September 2024. In December 2024 Pango Group merged
with Total Security to form Point Wild, which also owns TotalAV. Its privacy
policy is issued by Anchorfree LLC in Boston and Pango GmbH in Switzerland.

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | Hotspot Shield | URnetwork |
|---|---|---|
| Free tier | 500 MB/day at up to 2 Mbps, one US location, ad-supported; eight ad and attribution partners named in its own policy | Free daily data allowance funded by Pro subscriptions; no ads |
| Setup | Install and connect; refined since 2008 | Instant Account in one tap; a model that takes a minute to learn |
| Speed | Consistent datacenter throughput; Hydra engineered for long, lossy links | Member uplinks; URnetwork's own average streaming figure is 40 Mbps+ |
| Trust model | One company's servers see who you are and where you go; a policy governs what is kept | Two relay parties; the exit never sees your IP, and the operator cannot read the sealed session |
| Verification | Closed source, Hydra unpublished; one commissioned review of two policy sentences (Aon, 2023) | Open client and server code; storage limits enforced in code |
| Exit address | Datacenter ranges, rented largely from M247, Latitude.sh, and DataCamp | Residential addresses; ordinary traffic to the sites that receive it |

Caveats below the table:

- Post-quantum encryption is URnetwork-side here: the X25519MLKEM768
  client-to-provider session is default in the native apps, skipping any
  provider it cannot seal to rather than downgrading. Hotspot Shield
  advertises no post-quantum feature. The browser extension has no sealed
  session; there, the operator's data path logs nothing, pinned by a test in
  the open code.
- Hotspot Shield ships polished consumer apps and offers Hydra, IKEv2, and
  WireGuard as protocol choices. URnetwork ships native apps on Android, iOS,
  macOS, Windows, and Linux plus a browser extension paired with its web app,
  each with an explicit kill switch.
- Hotspot Shield's paid plans run about $7–12 a month on annual billing as of
  August 2026, and its promotional pricing moves. URnetwork Pro is $5/month
  or $40/year on top of the free daily allowance. Current numbers are at
  [ur.io/products](https://ur.io/products).

## The FTC complaint and the ad-supported free tier

On 7 August 2017 the Center for Democracy & Technology asked the US FTC to
investigate AnchorFree over the free tier. The complaint alleged that the app
injected JavaScript through iframes for advertising and tracking, used "more
than five different third-party tracking libraries," and could "intercept and
redirect HTTP requests" for retail domains including target.com and macys.com
to advertising partners. The technical evidence rested substantially on a
static analysis of the Android app, using Carnegie Mellon's Mobile App
Compliance System. These were allegations by an advocacy group; they were
never tested, and no public FTC action followed.

The free tier's economics are stated on the vendor's own pages today. The
free-VPN page reads "We're ad supported, giving you total privacy with no
charges." The policy names eight advertising and attribution partners: Unity
Ads, Ironsource, Digital Turbine, InMobi, Kochava, Mintegral, Meta, and
Appsflyer. Their SDKs "may collect… Device or mobile advertising identifiers"
and the "Internet Protocol (IP) Address," the identifier a VPN exists to
hide. One client bug also belongs on the record: CVE-2018-6460, disclosed by
Paulos Yibelo in January 2018, a local web server in the Windows client that
exposed configuration data over JSONP. AnchorFree fixed it.

![In their own words — each vendor's marketing headline next to its own disclosure page](/docs-assets/infographic-own-admissions.svg)

*Each vendor's own disclosure page, set beside the headline it markets.*

## The policy, the Aon review, and the transparency report

The current policy (version 1.0.0, effective 31 October 2024) states that the
VPN products "do not log any information that associates your account
credentials or identity with your VPN session activity" and that no records
are kept of "what websites you were browsing or apps accessed through a VPN
connection." The claim turns on the word associates. The same policy permits
collection of account, billing, device (including a per-install device hash),
diagnostic, and IP-derived location data for the life of the account.

Aon, commissioned by Pango, checked the two logging statements above in
August 2023. It reported that it "was unable to identify any indication that
users' browsing activity may be correlated or identified back to a unique
user identity," and that it found no logging of plaintext IP addresses. Its
stated scope excluded the security of the hosting environment, and part of
the work ran on a development VPN node. It is a real review,
vendor-commissioned, scoped to two sentences of the vendor's own policy, at
one point in time.

Pango's 2023 transparency report records 30 US and 52 international
government requests for user data, with zero disclosures. The figures are
self-reported, and they point the right way. A policy binds whoever owns the
company at the time, and this brand has had four owners.

![How you verify a privacy claim — point-in-time audits vs court and raid evidence vs open continuous verification](/docs-assets/infographic-verification.svg)

*What each kind of evidence proves: a paid snapshot, a court test, or code
anyone can check.*

## Hydra and the location map

Hydra earned its reputation as a transport engineered for throughput on long,
lossy links, and the licensing by rival security vendors is real third-party
respect. Hotspot Shield describes the security layer as conventional TLS 1.2
with ECDHE and RSA-2048 certificates; the patented part is how the payload
moves inside the tunnel. No specification or code is published, so nobody
outside the licensee circle can check that the implementation matches the
description. The stated substitute is evaluation by the security companies
that license the SDK, which is review under commercial agreements, never
published.

The location numbers repay a close read. The homepage markets "over 115+
virtual locations," and the plan page shows the sum: "115+ locations,
including 80+ countries and 35+ cities." Elsewhere in the industry a virtual
location means an IP registered to one country while the hardware sits in
another. Hotspot Shield uses the looser sense of a place you can appear to
be, labels even the free tier's single US exit a virtual location, and
publishes no physical-versus-virtual breakdown. Independent observation finds
its exit ranges in about 27 countries and 49 cities (netify.ai, read August
2026). The observed city count exceeds the advertised "35+"; the observed
country count is far below the advertised "80+".

URnetwork counts differently: a location exists only while a member's device
is online in it, and the platform geolocates the connection it observes
rather than accepting a declared city. Presence cannot be fabricated the way
a registered IP range can, though an address that looks like a datacenter or
a VPN is detected and demoted, not excluded. The 2,000+ real cities figure is
URnetwork's own count, and no outside party has measured it.

## Where Hotspot Shield wins

- A free tier anyone can install and understand, refined since 2008.
- A speed-engineered transport with consistent datacenter performance,
  validated by licensing to rival security vendors.
- More paperwork than URnetwork has produced: a published transparency report
  and a commissioned review of its logging claims.

## Where URnetwork wins

- The split. The exit never learns who you are, and the operator cannot read
  the sealed session. No single party holds identity and destinations
  together.
- Verification: storage limits enforced in code anyone can read, versus a
  policy reviewed once, at the vendor's request and scope.
- Whole-stack source: the apps, SDK, and server platform are public, where
  Hotspot Shield publishes neither client nor server code.
- Residential exits that blend in where datacenter ranges are flagged,
  targetable down to a city.
- A free tier with no ads attached, and an Instant Account that takes one tap
  and no email.
- The people carrying your traffic opted in and are paid under signed,
  metered contracts as participants in the [UR protocol](https://ur.xyz),
  with file-sharing and attack traffic dropped at each exit by an open-source
  filter.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, the operator
  could itself run providers, and no outside party has measured the fleet.
  See the [threat model](/docs/threat-model), §6.1.
- Coverage counts are self-published. Outside observers have mapped Hotspot
  Shield's exit ranges; nobody has run that kind of measurement on URnetwork.
- URnetwork is the younger network, and speed moves with the providers in
  your window.

Hotspot Shield's limit is structural. Its servers terminate your tunnel, so
one company can see your real IP and your destinations together, and what it
keeps is a policy choice. The policy's no-logs claims were reviewed once, in
2023, at the vendor's request and scope, and the closed code means neither
the promise nor Hydra itself can be checked from outside. On the free tier,
the ad partners named in the policy receive the device advertising identifier
and the IP address.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, so you can test both free tiers against your own sites before paying
for either product. More questions are answered in the [FAQ](/docs/faq).
