VSVPNScorecard
← All VPNs

Hotspot Shield

A long-running US-based VPN built on the proprietary Catapult Hydra protocol, now operated by Point Wild, offering fast speeds but a checkered privacy history.

www.hotspotshield.com/
49/100Overall score
Jurisdiction
United States (five eyes)
Founded
2008
Owner
Point Wild
Best price
$2.99/mo
Devices
10
Free tier
Yes
Privacy41
Security80
Transparency35
Value100
Ethics0

Best for

  • · Users prioritizing raw connection speed over maximum privacy
  • · Casual streaming and general browsing on a trusted network
  • · People wanting a free ad-supported VPN tier to try before paying

Not ideal for

  • · Privacy-critical users, journalists, or activists needing a court-tested no-logs provider
  • · Anyone wanting anonymous/crypto payment or open-source, independently audited clients
  • · Users in a non-Five-Eyes jurisdiction seeking strong legal protection from data requests

Strengths

  • Proprietary Catapult Hydra protocol delivers consistently fast, high-throughput speeds
  • Has a no-logs validation by Aon (Aug 25, 2023) covering its privacy-policy data-collection claims across free and paid tiers
  • Generous 45-day money-back guarantee plus a genuinely free (ad-supported) tier
  • Large brand with apps across all major platforms and up to 10 simultaneous connections

Weaknesses

  • US jurisdiction (Five Eyes) and a 2017 FTC/CDT complaint alleging undisclosed data sharing with ad networks and traffic redirection/JavaScript injection
  • Privacy policy admits collecting bandwidth, session duration, device hashes and IP-derived location despite no-logs marketing
  • Core Hydra protocol is closed-source and clients are not open source; the Aon audit reviewed only the privacy policy, not Hydra's code or app security
  • No public transparency report since 2022, no RAM-only servers, no port forwarding or multi-hop

Full data sheet

Every attribute we track, coloured by whether it helps or hurts your privacy.

Company & jurisdiction
Based inUnited States
Eyes alliance5 Eyes
Enemy of the InternetNo
OwnerPoint Wild
ConglomeratePoint Wild
Founded2008
Logging
Traffic / activityNone kept
DNS requestsUnknown
TimestampsSome
BandwidthLogged
Source IP addressSome

Markets itself as no-logs and the policy (held by Anchorfree, LLC) states it does not record which sites/apps you access or tie session activity to your identity. However, the privacy policy admits it collects session duration, bandwidth consumed, a per-install device hash, and uses your IP to derive approximate location. The Aug 2023 Aon report's own data-classification table lists timestamps, bandwidth, device hash and approximate location among collected data. DNS-query logging is not addressed. US jurisdiction (Five Eyes) and a 2017 FTC complaint over undisclosed ad-network data sharing weigh against the no-logs marketing.

Payment & anonymity
Anonymous signupNo
Accepts cashNo
Accepts cryptoNo
PGP keyUnknown
Protocols & features
OpenVPNNo
WireGuardYes
Proprietary protocolCatapult Hydra
Multi-hopNo
ObfuscationUnknown
Kill switchYes
First-party DNSUnknown
RAM-only serversNo
Port forwardingNo
P2P / torrentingYes
IPv6Unknown
Encryption
Data cipherAES-256
HandshakeTLS (Catapult Hydra)
Transparency
Open-source clientsNo
Independent audits1
Transparency reportNo
Court / seizure-testedUnknown

No documented server seizure, raid, or subpoena outcome demonstrating an absence of usable user data. Last public law-enforcement transparency report referenced is 2022 (per the Aon report); no published transparency report found since.

Infrastructure
Simultaneous devices10
Countries80
Servers1800
Linux supportCLI / config
Pricing
Month-to-month$12.99
Best $/mo$2.99
On plan3-year
Free trialNone
Refund window45 days
Free tierYes
Ethics
Logging policyContradictory
Marketing honestyOverclaims

Independent audits

  • Aon· 2023 · Technical security review of the Hotspot Shield VPN privacy policy, scoped strictly to data-collection and logging claims (no-logs validation) across free and paid tiers and client- and server-side components; methodology included VPN node server log review, client analysis, and review of the 2022 transparency report. Not a Hydra source-code audit or app penetration test, and explicitly excluded review of security measures/best practices across the hosting environment.report ↗

Ownership timeline: AnchorFree (founded 2005; Hotspot Shield product launched 2008) -> rebranded Pango -> folded into Aura (Dec 2020) -> Aura split, VPN/security side spun out (Sep 2024) -> Pango Group merged with Total Security to form Point Wild (12 Dec 2024, confirmed via PRNewswire). Hotspot Shield, Betternet, UltraAV, VPN360 and TotalAV are sibling Point Wild brands (the Dec 2024 release also names UltraAV, CyEx, Simpluris and Comparitech). The privacy policy is held by Anchorfree, LLC (250 Northern Ave, Boston, MA) with Pango GmbH (Stans, Switzerland) as an associated entity, but operational control and HQ are US. The Aon report PDF on the official security-audit page is dated 25 August 2023 (PDF metadata created 2023-10-27), confirmed by direct extraction; firm = Aon, scope = privacy-policy/logging validation only.

Sources

Last verified 2026-06-17. Point-in-time data, so always confirm on the provider's own site.

Summarise this site with AI