Why we cannot just analyse these apps by reverse engineering and look it inside, there are already one research about MAX messenger which includes specific API requests to detect tun vpn through private space and profiles, pinging websites including .com domains to check if its available and if user are uses vpn with split tunneling, unauthorised acess to files or geo location, its reveals big problem for all the apps, which we cannot know, and only the solution to give the root rights for the user to prevent it really.