A useful way to think about VPN privacy: it doesn't make your traffic invisible to everyone — it changes who's positioned to see what. Mapping out each party's actual visibility clarifies what a VPN genuinely accomplishes.
Mapping the visibility
- Your ISP. Without a VPN, sees your traffic's destinations and content (for unencrypted traffic). With a VPN, sees only that you're connected to a VPN server and how much data flows — not the destinations or content within the tunnel.
- Your VPN provider. Now occupies the position your ISP previously held — capable of seeing your traffic's destinations and, for unencrypted content, the content itself. This is exactly why the provider's own logging policy and trustworthiness matter so much.
- The destination site. Sees the VPN's IP instead of yours, but still sees everything about your interaction with that specific site — logins, form submissions, browsing behavior on that site.
- Your browser. Unaffected by the VPN — fingerprinting, cookies, and stored data all function exactly as they would without one.
- Any account you're logged into. Knows it's you, VPN or not.
The core insight: trust moves, it doesn't disappear
A VPN is fundamentally a decision about who to trust with visibility into your traffic — moving that trust from your ISP to your VPN provider, not eliminating the need for trust altogether. Choosing a VPN provider is, in large part, a decision about which entity you're more comfortable holding that position.
FAQ
Does a "no-logs" VPN policy solve this concern?
It's meant to, but ultimately relies on trusting the provider's claim (or an independent audit, where one exists) — it's a real mitigating factor, not an absolute guarantee, since verifying a negative (that logs genuinely don't exist) is inherently difficult from outside the company.