Google One VPN Is Gone. Clean Up What It Left.
- Google Ended One VPN, Not Every Google VPN
- A Dead Profile Can Still Control a Live Route
- VPN by Google Lives on Eligible Pixel Devices
- Remove the Old Route Without Wiping the New Ones
- A Home Gateway Replaces the Multi-Device Part
- Name the Job Before You Buy a Replacement
- One Phone App Doesn't Replace a Household Service
- Evaluate the Next Intermediary From Zero
- A Bundle Needs an Exit Plan
Google One VPN is gone. The old toggle may still be visible, and a stale profile may still break the internet, but neither can bring the service back. The useful job now is to identify the route left behind.
Open a laptop that used the old bundle. The Google One app still sits in a folder.
A VPN entry still sits in network settings. You press Connect and wait for a server that stopped being a product on June 20, 2024.
Don't install another app yet. First make the old path understandable.
Google Ended One VPN, Not Every Google VPN
VPN by Google One was a multi-platform benefit for eligible Google One members. Google discontinued that service on June 20, 2024 and removed it from the membership experience.
An old app, help page, status icon, or configuration file can't recreate its server-side endpoint.
Google now offers a separate built-in product called VPN by Google on eligible Pixel hardware.
The names sound related because they are. They aren't interchangeable.
The shutdown didn't remove Android's general VPN support, workplace tunnels, Google Fi protections, or third-party VPN apps. It ended one Google-operated consumer service tied to Google One.
A Dead Profile Can Still Control a Live Route
Before the shutdown, covered traffic entered an encrypted tunnel to a Google VPN server. The local network and ISP saw the connection to Google, Google operated the intermediary hop, and destinations saw the VPN server's public IP while still seeing any account, cookies, and data the user supplied.
After shutdown, a stale profile can fail in two different ways.
If the device falls back, it sends traffic through the local network directly to the ISP; the Google VPN is no longer an intermediary, and destinations see the household's or carrier's public IP. If “always-on” or “block connections without VPN” still binds traffic to the dead profile, the local network sees no onward app connection and neither Google nor the destination receives that traffic.
Same obsolete configuration. Two very different outcomes.
A status key or grayed-out toggle doesn't prove which route exists. Check the operating system's active VPN, always-on, kill-switch, DNS, and proxy settings.
VPN by Google Lives on Eligible Pixel Devices
Google's current Pixel VPN guidance says Pixel 7 and later phones and the Pixel Tablet can use VPN by Google at no added charge in supported countries. A personal Google Account or Workspace account is required, and an administrator can restrict Workspace access.
Eligibility can also fail when the region isn't supported, the account is supervised or otherwise ineligible, the device is rooted, the bootloader is unlocked, security updates are missing, or the phone runs beta or unofficial software. Check the current list rather than copying an old launch-day list into your travel plan.
Find the feature in Android Settings under Network & internet, VPN, and VPN by Google. It doesn't live in the old Google One benefit screen.
Google also says the Pixel service isn't designed to change the IP location for content unavailable in your region. It protects a network route; it isn't a country picker.
Remove the Old Route Without Wiping the New Ones
Search the device's VPN and profile settings for the old Google One entry. Confirm the exact name and owner before removing it.
A similar-looking profile may belong to work, school, another VPN, or device management.
On Windows, macOS, iOS, or iPadOS, uninstall the discontinued client through the normal application flow, then inspect remaining VPN configurations and network extensions. Preserve organization-managed settings.
If a work profile controls the device, ask the administrator rather than fighting the policy.
On Android, Google's VPN settings guide shows where to edit a profile and turn off an always-on assignment. Record the current Wi-Fi, DNS, proxy, and work settings before changing anything.
Don't reset every network setting because one obsolete row looks suspicious.
Restart after cleanup. Check that ordinary sites load, then note the public IP and run a DNS test.
This baseline shows which provider and resolver the device uses with no VPN active.
If the internet remains blocked, look again for an always-on VPN or “block connections without VPN” rule pointing at the removed profile. A kill switch that once prevented unsafe fallback can become the thing holding a retired route shut.
A Home Gateway Replaces the Multi-Device Part
Google One VPN once covered supported computers and phones under the same benefit. VPN by Google doesn't replace that footprint: it stays tied to eligible Pixel hardware, accounts, software, and regions.
A wired VPN gateway can put selected home devices behind one provider without replacing an existing Wi-Fi system. That helps when a television or computer can't run the chosen app, but the gateway still needs a separate VPN subscription, a supported profile, and a working access point or router.
- Sits on a wired network as a dedicated gateway for OpenVPN or WireGuard traffic
- Can run VPN client and server roles together for remote access and protected outbound browsing
- Has no Wi-Fi radio, making it best for pairing with an existing router or access point
Follow one home device through both choices. Assigned to the gateway VPN, it sends covered traffic through the local router into an encrypted connection; the ISP sees the VPN server, the provider forwards the traffic, and the destination sees the server's public IP.
Bypass the gateway and the local router sends the device directly through the ISP. The VPN provider receives nothing from that route, and the destination sees the home's public IP.
Name the Job Before You Buy a Replacement
The old feature may have been enabled because it came with storage, not because anyone chose it for a specific threat. Write down the actual need now:
- Reduce what an ISP or unfamiliar network can see about covered destinations
- Protect traffic before work apps reach a company gateway
- Give a laptop, phone, television, or router a different public IP
- Keep a whole household on one managed route
- Reach private devices or office resources remotely
Those jobs don't all call for the same VPN. A company remote-access client and a consumer privacy VPN can both create tunnels while sending traffic to different operators for different reasons.
An eligible Pixel user may decide the built-in Google option covers the phone's ordinary network-privacy goal. Someone who also needs laptops, Apple devices, TVs, manual locations, or router control needs a broader design.
One Phone App Doesn't Replace a Household Service
Count the screens that lost coverage when Google One VPN ended. If several devices need one repeatable route, a compatible travel router can share a VPN connection with laptops, phones, and streaming hardware that support the network.
That convenience creates a larger switch. With the router VPN active, the hotel network sees an encrypted connection to the provider's server, the VPN becomes the intermediary, and destinations see the server's public IP.
Bypass the router VPN and those devices send traffic through the hotel network and its upstream provider. The VPN receives nothing from that route, destinations see the hotel's public exit IP, and several devices can lose protection together if the box fails.
Confirm that the chosen VPN provider supplies a protocol and configuration the exact router supports. Practice captive-portal sign-in, direct bypass, and profile removal before travel.
- Combines Wi-Fi 6 with a 2.5-gigabit WAN port in a compact travel-friendly body
- Runs OpenVPN and WireGuard profiles from compatible VPN providers across connected devices
- Adds WPA3, encrypted DNS, captive-portal support, and a configurable privacy switch
The Beryl supplies a network control point, not a VPN subscription or protection after a phone leaves its Wi-Fi. Keep the provider app configured on mobile devices that need coverage away from the travel router.
Evaluate the Next Intermediary From Zero
A familiar technology brand shouldn't have been the only trust test for Google One VPN. An unfamiliar VPN shouldn't receive automatic trust because it promises to replace the feature.
Check the legal operator, ultimate owner, account data, activity and connection logging, diagnostic choices, retention periods, server design, app maintenance, kill switch, DNS and IPv6 handling, independent reviews, and public incident response. Read the scope and date of an audit instead of counting its badge.
Install from the provider's official site or a verified store listing. Test the exact device and network during the evaluation period.
Force a tunnel failure, sleep and wake the device, switch Wi-Fi, check IP and DNS results, and open the bank, work tools, email, and permitted media services you actually use.
The local network should see the encrypted VPN-server connection while the tunnel is healthy. The destination should see the VPN server's IP.
If the tunnel fails, traffic should block or return to the direct route exactly as you chose—not whichever behavior you discover later.
A Bundle Needs an Exit Plan
Bundled security features can disappear when the larger subscription changes direction. That doesn't make every bundle a poor choice.
It means the privacy feature may have less control over its own product life.
Keep the official removal steps for any VPN, DNS filter, certificate, or security profile you install. Record where always-on and failure-blocking controls live.
A privacy tool should be easy to identify, verify, and remove when support ends.
Google One VPN can't be revived. VPN by Google is a separate Pixel option with its own device, account, software, and regional limits.
Clean the old route, prove the direct baseline, and replace it only if a named job remains. The shutdown is over.
The configuration may not be.

