Home Reviews About
Twenty of Time

What a VPN actually hides (and what it doesn’t)

A virtual private network is often presented as a privacy switch: turn it on, and your online activity disappears from view. That description is attractive, simple, and wrong. A VPN changes who can observe certain parts of your connection, but it does not erase the identity signals that browsers, apps, websites, and data brokers collect every day.

The useful question is not whether a VPN makes you anonymous. It is what information moves out of sight, whose view changes, and which observers can still connect your activity to you. Once those distinctions are clear, a VPN becomes easier to evaluate without treating it as either a miracle tool or a pointless one.

A VPN can be valuable for people using public Wi-Fi, avoiding network-level monitoring, reducing the visibility of an internet service provider, or reaching services that are restricted by location. Its protection has real limits, however, and those limits matter more than the marketing language used by many VPN companies.

What the VPN changes

Without a VPN, your internet service provider can generally see which domains your device contacts, along with connection times, data volumes, and the IP addresses involved. HTTPS usually protects the contents of your web sessions, such as passwords and page text, but it does not make all connection metadata private. The provider can still learn a great deal from patterns of use.

When a VPN is active, your device creates an encrypted tunnel to a VPN server. Your local network and ISP can see that you are connected to a VPN, but they should not be able to read the traffic inside that tunnel. Websites then see the VPN server’s IP address rather than the public IP address assigned to your home connection.

This arrangement shifts trust rather than eliminating it. Your ISP has less visibility into your destinations, while the VPN operator becomes an important intermediary. A provider may be able to observe connection times, bandwidth use, DNS requests, and other metadata. Depending on the protocol, configuration, and the use of HTTPS, it may also have varying opportunities to inspect traffic. A “no logs” promise is therefore a claim to investigate, not a technical guarantee to accept blindly.

What remains visible to your network

A VPN does not make the connection itself invisible. Your ISP can usually identify the VPN server, estimate how much data you exchange, and record when the encrypted connection is active. In countries or networks that restrict VPN use, that fact alone may attract attention. Obfuscation features can make VPN traffic harder to classify, but they do not create perfect concealment.

The local network also still knows that your device is communicating. A school, employer, hotel, or coffee shop may be able to enforce its own rules, block the VPN, or record device-level information before the traffic enters the tunnel. A VPN cannot protect a device from an administrator who controls the device, the Wi-Fi infrastructure, or the software installed on it.

There are also configuration failures. DNS requests can leak outside the tunnel, an IPv6 connection can bypass an incomplete setup, and a dropped VPN connection can expose the ordinary network address if there is no kill switch. Reputable apps reduce these risks, but users should still test their setup rather than assuming the icon in the menu proves everything is covered.

Websites still recognize you

A website does not need your home IP address to recognize you. If you sign in to Google, Facebook, an online shop, or a work platform, the service already has a direct account-level identifier. Changing your apparent location does not separate activity from an account that you voluntarily use.

Cookies, tracking pixels, local storage, advertising IDs, and browser fingerprints create additional links. A fingerprint can include details such as screen dimensions, installed fonts, language settings, time zone, operating system, and browser behavior. A VPN changes the network address, but it usually leaves these characteristics untouched. Trackers can therefore connect sessions even when the IP address changes repeatedly.

The same applies to mobile apps. An app may use account details, device identifiers, advertising IDs, location permissions, contact lists, and behavioral patterns. A VPN may hide the destination of the connection from the network provider, but the app can still report information directly to its own servers. It also does nothing to remove data already collected in the past.

That distinction becomes clearer when looking at search and browsing histories. A VPN may prevent an ISP from seeing the exact content of an encrypted search session, but it does not delete records held by a search engine. The consequences of removing those records are explored in a month without Google, which illustrates why account-level data and network-level privacy are separate issues.

A clearer view of the privacy boundary

The following comparison shows which observers typically gain or lose visibility when a VPN is used. Exact details depend on HTTPS, DNS settings, the VPN protocol, the provider’s infrastructure, and the policies of the services involved.

Observer Without a VPN With a VPN What the VPN does not solve
Internet service provider Sees connection metadata and usually the domains contacted Sees a VPN connection, timing, and volume It can still identify the customer and VPN use
Public Wi-Fi operator May observe or manipulate local traffic and connection details Sees an encrypted connection to the VPN server It can still block access or monitor the device joining its network
VPN provider Not involved in the connection path Can see the tunnel and potentially connection metadata Trust moves to its logging, business model, and technical practices
Website or app Sees your home or mobile IP address and account activity Sees the VPN IP address and account activity Cookies, fingerprints, logins, and app identifiers remain
Advertising broker Receives data through websites, apps, and trackers May see a different IP-related signal It can still build profiles from identifiers and browsing behavior
Employer or school May see activity on managed networks or devices May still control the device and enforce monitoring software A VPN cannot override endpoint administration
Someone monitoring an open Wi-Fi network May capture unencrypted traffic and metadata Usually cannot read traffic inside the tunnel Device compromise, phishing, and malicious downloads remain risks

The table also highlights why privacy is contextual. If your concern is an untrusted café network, a VPN can be a sensible defensive measure. If your concern is an advertising company following you across websites, a VPN addresses only one part of the tracking system. If your concern is an employer-managed laptop, the endpoint may matter much more than the network path.

Why a VPN is not anonymity

Anonymity requires making it difficult to connect an action to a person. A VPN generally offers pseudonymity at the IP layer: a website sees the VPN server rather than your household connection. That can be useful, but the effect is easily undone by logging in, reusing a recognizable browser, sharing personal information, or maintaining a stable pattern of behavior.

VPN providers themselves deserve careful scrutiny. Their business may depend on subscriptions, analytics, partnerships, or advertising. Even when a company has a strong privacy policy, it must still operate servers, handle payment records, respond to legal demands, and protect infrastructure from compromise. Independent audits can provide evidence about specific systems, but they do not prove that every form of monitoring is impossible.

Tor and a VPN solve different problems. Tor routes traffic through multiple volunteer-operated relays and is designed to make tracing more difficult, while a VPN concentrates trust in one commercial or organizational provider. Tor can offer stronger anonymity in some situations, but it is slower, may trigger access restrictions, and cannot protect an account that identifies its user. Neither tool repairs an infected device or prevents careless disclosure.

A VPN also does not provide general security against scams, credential theft, ransomware, or unsafe downloads. Encryption between your device and a VPN server cannot stop you from entering a password into a convincing fake website. Privacy tools reduce certain forms of observation; they do not replace software updates, multi-factor authentication, cautious browsing, or control over the information shared with services.

Use the tool for the right job

The most defensible reason to use a VPN is a specific network privacy need. It can prevent a local Wi-Fi operator from casually inspecting traffic, reduce the amount of browsing metadata available to an ISP, and conceal your home IP address from websites. It may also help when traveling or working from networks whose security and administration you do not control.

Choosing a provider requires more than comparing server counts and subscription discounts. Read the privacy policy for concrete statements about connection logs, source IP addresses, DNS requests, payment information, and retention periods. Look for open-source clients where possible, modern protocols, independent security assessments, a clear corporate identity, and a business model that does not depend on selling user data.

A VPN is less useful when the main problem is aggressive web tracking. In that situation, browser privacy settings, tracker blocking, separate browser profiles, and refusing unnecessary permissions can address more of the collection process. An ad blocker review can help put browser-based defenses in context, since blocking scripts and tracking requests often changes what advertisers can gather more directly than changing an IP address.

Practical habits make the technology more reliable:

Treat privacy as a set of layers

The central trade-off is straightforward: a VPN hides your public IP address from destinations and hides much of your traffic from the local network, while making the VPN provider a more important observer. It does not hide who you are from accounts you use, remove browser fingerprints, stop first-party data collection, or prevent a compromised device from leaking information.

That does not make a VPN useless. It makes it a narrow instrument. For public Wi-Fi, ISP-level visibility, and IP-based location exposure, it can provide meaningful protection. For behavioral advertising, search histories, platform surveillance, and data brokerage, it must be combined with measures aimed at accounts, browsers, apps, and personal choices.

Map the observer you are trying to keep out of the picture before choosing a privacy tool. Install a VPN when its particular protection matches that observer, verify that it is working, and pair it with privacy practices that address the signals the tunnel cannot hide. That approach turns a VPN from a promise of invisibility into a practical part of a broader plan for digital independence.