Since advanced privacy works as a vpn, the question is, what vpn is overruling?
Because normally, you don’t use 2 vpns at same time for same applications.
ProtonVPN or advancedprivacy (that is found in vpn menu)
I asked Lumo AI, here is what Lumo found:
Proton VPN’s NetShield generally provides stronger and more comprehensive tracker blocking compared to the “Advanced Privacy” features (specifically the DNS-based filtering) in /e/OS. Here’s a breakdown of why:
How They Work
-
Proton VPN NetShield: Operates at the DNS and network packet level on Proton’s servers. It inspects traffic passing through the VPN tunnel and blocks requests to known ad, tracker, and malware domains before they reach your device. Because it happens server-side within the encrypted tunnel, it can block trackers across all apps and browsers that use your system DNS, not just those configured specifically for ad-blocking.
-
/e/OS Advanced Privacy: Primarily relies on local DNS filtering (often integrating tools like RethinkDNS). While effective at blocking known tracker domains, it operates locally on the device. It may struggle with:
-
Trackers embedded directly in website content (non-DNS based).
-
Encrypted traffic where domain resolution is hidden or spoofed.
-
Conflicts if you try to use another VPN simultaneously (since most mobile OSs only support one active VPN interface at a time).
Key Differences in Effectiveness
-
Scope of Protection: NetShield covers all traffic routed through the Proton VPN tunnel, offering a blanket shield for every app. /e/OS protection is robust but limited to its specific DNS configuration and may miss tracking methods that don’t resolve to a distinct blocked domain.
-
Bypass Resistance: Server-side blocking (NetShield) is harder for websites to bypass compared to local client-side blocking (/e/OS), which can sometimes be circumvented by sophisticated fingerprinting or direct IP connections.
-
Compatibility: Using /e/OS’s built-in privacy tools alongside another VPN (like Proton) can be technically difficult because mobile operating systems typically allow only one active VPN connection. If you enable Proton VPN, you often have to disable /e/OS’s “Hide My IP” (Tor/VPN) feature, potentially leaving its native tracker blocking less integrated with your main internet traffic unless carefully configured via a dedicated firewall app like RethinkDNS in parallel.
Verdict
If your primary goal is maximum tracker and ad blocking, Proton VPN NetShield is the superior choice due to its server-side enforcement and broad coverage across your entire connection.
However, /e/OS offers excellent system-level de-Googling and privacy hardening (removing Google services entirely), which complements a good tracker blocker. For the best setup, many users run /e/OS for its clean environment and connect to a Proton VPN with NetShield enabled to layer the strongest possible blocking on top.
If i ask Lumo if i can use “/e/OS Advanced Privacy tracker and ad blocker” and “protonvpn netshield” at same time (because netshield ad/trackers counters stay at 0 that way) Lumo write:
Yes, you can run both Proton VPN NetShield and /e/OS’s Advanced Privacy features at the same time, but you are likely experiencing a configuration conflict that is causing one of them to fail (in your case, NetShield showing 0 blocks).
The issue usually stems from how mobile operating systems handle DNS traffic and VPN interfaces. Here is why NetShield isn’t working in your setup and how to fix it:
The Problem: DNS Conflict or Tunnel Bypass
-
Single VPN Interface Limit: Android (and thus /e/OS) generally allows only one active VPN connection at a time.
- If
/e/OS “Advanced Privacy” sets up its own local VPN tunnel (often for the Tor network or local firewalling), and then you connect Proton VPN, the system might route traffic incorrectly, or Proton’s app might not be able to inject its own DNS rules into the stream because /e/OS has already taken control of the network interface.
-
DNS Leak Prevention: If /e/OS is forcing all DNS queries through its own local resolver (to block trackers locally), your device might never send those DNS requests to the Proton servers where NetShield lives. Consequently, NetShield sees no traffic to filter, resulting in 0 counts.
-
“Kill Switch” Conflicts: Both tools try to control network access. If /e/OS locks down the network first, Proton’s background process might be blocked from scanning traffic.
How to Fix It & Make Them Work Together
To get NetShield working properly while using /e/OS, you need to ensure Proton VPN controls the DNS, not the OS-level privacy tool.
Option A: Let Proton Handle Everything (Recommended for Max Blocking)
Since NetShield is more comprehensive for web tracking, the most effective setup is to let Proton do the heavy lifting:
-
Disable the specific “Block Trackers and Ads” or “Local Firewall” VPN feature within /e/OS Advanced Privacy settings.
-
Keep /e/OS installed (it still removes Google services and improves privacy at the OS level).
-
Connect to Proton VPN with NetShield enabled (Set to “Strict” if available).
-
Ensure Proton’s “Secure Core” or “NetShield” toggle is active inside the Proton app.
Result: All traffic goes through Proton’s servers, NetShield filters everything, and your tracker counter should start rising.
Option B: Layered Approach (If you want local + server blocking)
If you specifically want both to run:
-
Connect to Proton VPN first.
-
Open /e/OS Advanced Privacy. Look for a setting regarding “Use built-in DNS” or “Local Firewall”.
-
If there is an option to “Allow external VPNs” or “Bypass local DNS for connected VPNs,” enable it. This tells the OS: “When Proton is connected, don’t intercept the DNS; let it go through.”
-
Some versions of /e/OS use RethinkDNS. If you have RethinkDNS installed, check its settings to ensure it isn’t set to “Always On” in a way that conflicts with the Proton app.
-
Crucial Step: In the Proton VPN app, go to Settings → General and make sure “Connect automatically” is on, or ensure the connection type is standard (not split-tunneling a specific app that bypasses NetShield).
Why You See “0 Blocks” Right Now
Your tracker counter staying at 0 strongly suggests that DNS resolution is happening locally on your phone (handled by /e/OS) before the packet even hits the Proton tunnel.
-
The /e/OS resolver likely blocks the domain immediately or fails to pass the query to Proton.
-
Since Proton’s server never saw the request to doubleclick.net (for example), it never triggered a “block” event to log.
Recommendation: Try temporarily disabling the “Block Trackers and Ads” module in /e/OS’s Advanced Privacy menu while keeping the rest of the OS hardening active. If your Proton tracker count suddenly starts jumping up, you’ve confirmed the conflict was the local DNS filter.