Advanced Privacy and ProtonVPN

Being new to Android and searching online I am unable to determine if my privacy is in a better place using the Advanced Privacy settings e.g. Online Privacy Protected, managing my internet address so that my real IP address is hidden, and my location is faked instead of my real position OR turning these to the OFF position and using ProtonVPN. Which service is more conducive for me? Pro’s and Con’s?
I would hope that the /e/ OS would be more secure than a pay service such as ProtonMail, ProtonVPN, and ProtonCalendar. Do not have the experience and knowledge to be aware of that but the tech’s here on this forum would and explain it in detail.

Thank you!

Regain your privacy! Adopt /e/ the unGoogled mobile OS and online servicesphone

I don’t use Advanced Privacy yet because I use Tracker Control + Proton VPN but I’ll certainly start using AP as soon as it gets more “mature”.

You can learn something from here: Advanced Privacy - know all about it

And other members will probably take some time to suggest you some more readings.
Cheers

I would also like to know more about this. I currently use Proton VPN on my computers and phone.
I might be wrong or be over-simplifying it, but I think a VPN does 4 different things:

  1. It hides some of your metadata from websites and apps. So a website or app thinks you are in the Netherlands when you are really in the UK. (This can be for privacy because you think it is none of their business, or to trick them into thinking you are in a specific country/location to access streaming services.)
  2. It stops your ISP from knowing what you are doing, your ISP provides your access to the internet but all they see is that you are connected to a server (they might know it is a Proton server). So your home broadband or mobile provider thinks you are spending all your time connected to one website and they don’t know what is going back and forth. This also means that they don’t have any useful data to sell or to share with government agencies.
  3. VPNs can also block ads, trackers, malware etc.,
  4. They provide extra security when connected to WiFi in a cafe or airport where someone might be able to intercept the traffic in between your device and the router. All they would see is gobbledegook.

From what I have read, it looks like Advanced Privacy helps with the 1st and 3rd. Your apps won’t know where you are and it blocks ads and trackers.
If those are you main concerns, then it is great to have that built-in to the system and that you don’t have to pay a subscription for it.

From what I can tell, it does nothing for 2 and 4. It won’t stop your ISP from knowing (and sharing) what you are doing on the internet. I don’t think it helps with security on open WiFi networks either.

If you use both, it means that even if your VPN is switched off, whether by mistake or manually, you still have 1 and 3.

I would like to know which one overrides the other, so if you are in the UK and your VPN is set to Germany and in AP you have an app set for France. What will the app see? Or can you not have both trying to hide your IP address?

Please let me know if I have misunderstood something or if it could be explained more clearly.

I have question about same topic.

In /e/OS settings / Network and Internet / VPN

i have

-Proton VPN

-Advanced Privacy.

My question is:

Is advanced privacy working as a kind of vpn to filter traffic (block app trackers & ads, fake geolocation, hide IP address).

If so, i have both on. Is internet traffic go trough both, or parallel?

So is upload data going from Fairphone to advanced privacy and then to proton vpn?

Or upload from proton vpn to advanced privacy? Or is it working parallel (so it uses both at same time and choose earliest connection?

And download?

I see that advanced privacy does block things, and in proton vpn the counter of ads blocked and trackers stopped stay both on 0, protonvpn is in always on mode(stay connected to vpn at all times).

In advanced privacy, the blocked leaks is that same as protonvpn trackers , so same things stopped?

What is recommended? I think advanced privacy can be disabled, because proton vpn (not free account) has ads blocked and trackers stopped.

At Coffeecraig: i did test on fairphone /e/OS gen6.

Proton vpn on, it uses proton vpn/location at mylocation.org , advanced privacy geo location is not in use when on together with protonvpn on.

Advanced privacy Real IP address only works if proton vpn is off.

if i switch off proton vpn it uses advanced privacy settings.

So i disable advanced privacy, and switch on protonVPN for now. (proton vpn netshield count now, because advanced privacy is off)

Protonvpn works for all traffic, advanced privacy only for traffic from selected applications?

Untill someone can exactly explain what is overruling exaclty , is what setting situation of payed VPN versus advanced security vpn build in.

This is an old thread, AP has pages linked from Support topics like

Personally I keep Trackers mostly engaged and the other two mostly off.

2 Likes

Since advanced privacy works as a vpn, the question is, what vpn is overruling?

Because normally, you don’t use 2 vpns at same time for same applications.

ProtonVPN or advancedprivacy (that is found in vpn menu)

I asked Lumo AI, here is what Lumo found:

Proton VPN’s NetShield generally provides stronger and more comprehensive tracker blocking compared to the “Advanced Privacy” features (specifically the DNS-based filtering) in /e/OS. Here’s a breakdown of why:

How They Work

  • Proton VPN NetShield: Operates at the DNS and network packet level on Proton’s servers. It inspects traffic passing through the VPN tunnel and blocks requests to known ad, tracker, and malware domains before they reach your device. Because it happens server-side within the encrypted tunnel, it can block trackers across all apps and browsers that use your system DNS, not just those configured specifically for ad-blocking.

  • /e/OS Advanced Privacy: Primarily relies on local DNS filtering (often integrating tools like RethinkDNS). While effective at blocking known tracker domains, it operates locally on the device. It may struggle with:

    • Trackers embedded directly in website content (non-DNS based).

    • Encrypted traffic where domain resolution is hidden or spoofed.

    • Conflicts if you try to use another VPN simultaneously (since most mobile OSs only support one active VPN interface at a time).

Key Differences in Effectiveness

  1. Scope of Protection: NetShield covers all traffic routed through the Proton VPN tunnel, offering a blanket shield for every app. /e/OS protection is robust but limited to its specific DNS configuration and may miss tracking methods that don’t resolve to a distinct blocked domain.

  2. Bypass Resistance: Server-side blocking (NetShield) is harder for websites to bypass compared to local client-side blocking (/e/OS), which can sometimes be circumvented by sophisticated fingerprinting or direct IP connections.

  3. Compatibility: Using /e/OS’s built-in privacy tools alongside another VPN (like Proton) can be technically difficult because mobile operating systems typically allow only one active VPN connection. If you enable Proton VPN, you often have to disable /e/OS’s “Hide My IP” (Tor/VPN) feature, potentially leaving its native tracker blocking less integrated with your main internet traffic unless carefully configured via a dedicated firewall app like RethinkDNS in parallel.

Verdict

If your primary goal is maximum tracker and ad blocking, Proton VPN NetShield is the superior choice due to its server-side enforcement and broad coverage across your entire connection.

However, /e/OS offers excellent system-level de-Googling and privacy hardening (removing Google services entirely), which complements a good tracker blocker. For the best setup, many users run /e/OS for its clean environment and connect to a Proton VPN with NetShield enabled to layer the strongest possible blocking on top.

If i ask Lumo if i can use “/e/OS Advanced Privacy tracker and ad blocker” and “protonvpn netshield” at same time (because netshield ad/trackers counters stay at 0 that way) Lumo write:

Yes, you can run both Proton VPN NetShield and /e/OS’s Advanced Privacy features at the same time, but you are likely experiencing a configuration conflict that is causing one of them to fail (in your case, NetShield showing 0 blocks).

The issue usually stems from how mobile operating systems handle DNS traffic and VPN interfaces. Here is why NetShield isn’t working in your setup and how to fix it:

The Problem: DNS Conflict or Tunnel Bypass

  1. Single VPN Interface Limit: Android (and thus /e/OS) generally allows only one active VPN connection at a time.

    • If /e/OS “Advanced Privacy” sets up its own local VPN tunnel (often for the Tor network or local firewalling), and then you connect Proton VPN, the system might route traffic incorrectly, or Proton’s app might not be able to inject its own DNS rules into the stream because /e/OS has already taken control of the network interface.
  2. DNS Leak Prevention: If /e/OS is forcing all DNS queries through its own local resolver (to block trackers locally), your device might never send those DNS requests to the Proton servers where NetShield lives. Consequently, NetShield sees no traffic to filter, resulting in 0 counts.

  3. “Kill Switch” Conflicts: Both tools try to control network access. If /e/OS locks down the network first, Proton’s background process might be blocked from scanning traffic.

How to Fix It & Make Them Work Together

To get NetShield working properly while using /e/OS, you need to ensure Proton VPN controls the DNS, not the OS-level privacy tool.

Option A: Let Proton Handle Everything (Recommended for Max Blocking)

Since NetShield is more comprehensive for web tracking, the most effective setup is to let Proton do the heavy lifting:

  1. Disable the specific “Block Trackers and Ads” or “Local Firewall” VPN feature within /e/OS Advanced Privacy settings.

  2. Keep /e/OS installed (it still removes Google services and improves privacy at the OS level).

  3. Connect to Proton VPN with NetShield enabled (Set to “Strict” if available).

  4. Ensure Proton’s “Secure Core” or “NetShield” toggle is active inside the Proton app.

Result: All traffic goes through Proton’s servers, NetShield filters everything, and your tracker counter should start rising.

Option B: Layered Approach (If you want local + server blocking)

If you specifically want both to run:

  1. Connect to Proton VPN first.

  2. Open /e/OS Advanced Privacy. Look for a setting regarding “Use built-in DNS” or “Local Firewall”.

    • If there is an option to “Allow external VPNs” or “Bypass local DNS for connected VPNs,” enable it. This tells the OS: “When Proton is connected, don’t intercept the DNS; let it go through.”

    • Some versions of /e/OS use RethinkDNS. If you have RethinkDNS installed, check its settings to ensure it isn’t set to “Always On” in a way that conflicts with the Proton app.

  3. Crucial Step: In the Proton VPN app, go to Settings → General and make sure “Connect automatically” is on, or ensure the connection type is standard (not split-tunneling a specific app that bypasses NetShield).

Why You See “0 Blocks” Right Now

Your tracker counter staying at 0 strongly suggests that DNS resolution is happening locally on your phone (handled by /e/OS) before the packet even hits the Proton tunnel.

  • The /e/OS resolver likely blocks the domain immediately or fails to pass the query to Proton.

  • Since Proton’s server never saw the request to doubleclick.net (for example), it never triggered a “block” event to log.

Recommendation: Try temporarily disabling the “Block Trackers and Ads” module in /e/OS’s Advanced Privacy menu while keeping the rest of the OS hardening active. If your Proton tracker count suddenly starts jumping up, you’ve confirmed the conflict was the local DNS filter.

1 Like

hmm … elaborated ai-mumble… not sure if it hits the point…(Edit: I’ve had a quick skim… it’s actually wrong in places)

a dns filter via vpn (like proton) and AP´s tracker blocker act on different levels, AP´s tracker blocker hits first on a low system level (given the tracker or adress in question is on it´s blacklist) and the traffic will never leave the device whereas for proton the traffic will leave the device and is stopped @ proton.

Not all of AP is using the vpn-interface of the device, only the hide my ip function of AP acts as a vpn → if you want to use proton vpn just switch off AP´s hide my ip and you can still make use of the other 2 AP-modules: fake location + tracker blocker
It´s not complicated, just follow one of the links in what @aibd has linked for you and read, e.g.:

Nope: one VPN interface on the device = only one VPN service at a time
In terms of “overruling”: the VPN you activate deactivates the one currently running, and so on … This naturally leads to disruptions and malfunctions if one of them is set to ‘always on’ or if you’re constantly switching back and forth, etc.
proton does what proton does … and AP’s hide my ip uses the VPN interface to simply tunnel through Tor, thereby masking your IP address.
your choice

4 Likes

Also in my opinion you don’t necessarily need vpn but that depends on in what jurisdiction you’re living (if providers are gathering and selling data about you as well and/or are secure or free enough) and/or what apps you’re using.

The only reason for me has been to bypass region restrictions for a few services so far.

The hassle it brings weighs more heavily for me in general.

I would definitely use a trusted VPN if connecting to public wifi, hotel wifi, or any wifi that I don’t control myself. My VPN provider also includes DNS filtering to block trackers. I enhance the blocking with uBO and other measures, of course.

1 Like

Hi, I am going to use Proton VPN i have a subscription for with VPN accelerator. So, what You said means that I just need to switch off ‘hide my IP’ in AP settings and that will let me use my Proton VPN without any conflicts, plus avoiding Tor’s slowing down effect? Correct? Thanks :slight_smile:

1 Like

What i did:

Protonvpn: disable always on vpn(so advanced privacy start before proton) and killswitch (so their is internet when proton is off).

In advanced privacy: hide my ip and fake location both off (no tor network, it’s slow and you have fast vpn).

So when phone starts, only advanced privacy - tracker blocker is on (so no vpn function)

Then start proton VPN, and connect with your preferred openVPN profile.

Because protonvpn start as last, it is overruling advanced privacy (if their is something using same network source).

I have add the proton VPN widget above the advanced privacy widget(on left swipe of home screen of /e/OS.

This works without any problems so far.

(you only need tor if you want to visit a .onion website)

2 Likes

Thanks. Personally, I will keep those on and follow Obacht’s suggestion just to switch off ‘hide my IP’ in AP settings and see how it goes… (Still waiting for my e/OS handset from Fairphone, so You are 1 step ahead.)

Yes, for permanent use of a third party vpn service deactivate hide my ip in AP settings.
Plus: make sure the AP-vpn is really off in device vpn settings (no always on or else, you can even delete it in device settings as it will reappear in case you reactivate hide my ip).
In device settings → vpn settings I’d always have my specific vpn always on. (But killswitch off, as it just kills everything… an android bug imo)

1 Like

I thought Proton killswitch in VPN is to de-activate internet connection when VPN is temporarily unavailable to avoid browsing the net without it unknowingly. You can always manually switch off that VPN and then killswitch does not apply. I had never any problems with that option to be honest on the normal android system - will it cause problems on e/os?

Sorry for the ambiguity, I do not refer to the killswitch of your vpn app/provider (that will work as expected).
What I meant is in device vpn settings: do not activate “block connections w/o vpn” (or the like)… (Maybe device specific, least in my case it blocks everything completely, I do not think it’s an eos- but an android- issue … but I never deep dived into it…)

1 Like

Thanks for clarifying, that is helpful! :slight_smile:

1 Like

Thanks for the info.

I was already thinking, if i remove advanced privacy vpn (forget vpn), howdo i get it back if i need it in a future (stop proton vpon).

But yes, as soon as you activate hide my ip in advanced privacy, then the advanced privacy vpn setting is back.

So you can easily forget the advanced privacy vpn, so you have only proton vpn.

So always-on-vpn can be on for protonvpn?

I thought it can give conflicts with advanced privacy “block ad trackers and ads” that protonvpn netshield doesn’twork good. (because advanced privacy block trackers and ads start after protonVPN in always on mode).

When Proton always on is disabled, then you manually start protonvpn/netshield, so after advanced privacy trackers and ads is started). Then you see that they both block. Netshield from proton and advanced privacy.

When you want to use killswitch in protonVPN, you get this text:

1 open VPN settings

2 find ProtonVPN settings and tap *

3 enable “Always on VPN” and “Block connections without VPN”

:rofl:

You just give it a try, maybe it works fine in your system.

As said before, they work on different levels, AP strikes first which means less work for proton blacklists, no conflicts expected with regards to blocking trackers etc.

Thanks for your patience obacht. /e/OS is kinda new to me.

I understand now.

So to get back on topic:

1- Advanced privacy: only enable “Block app trackers & ads” (other two off)

2- Phone VPN settings: forget Advanced privacy VPN (so you have only ProtonVPN)

3- Proton VPN settings: enable “Always on VPN” and “Block connections without VPN”.

I’ll let you know if i experience anything unwanted the next days.

Note for people who access LAN devices from their /e/OS smartphone:

Make a ProtonVPN profile where LAN connections is set to active, and disable “Block connections without VPN” in VPN settings on /e/OS.