Okay I will look into a solution.
2/ I've tried blocking vpn or proxy users (by ip hosting provider), but found too many false positives. Using a VPN is common for IT professionals or consumers trying to 'protect' their privacy and this impacted the growth of my app.
That good to know, I do not find that I have a lot of false postivies but I would imagine it all depends on audience.
>How is your tool better at detecting a bot vs a human using a vpn?
It does not know the difference as or right now. I was thinking about adding a user-agent validation as well which could add another layer.