A useful way to think about VPN privacy: it doesn't make your traffic invisible to everyone — it changes who's positioned to see what. Mapping out each party's actual visibility clarifies what a VPN genuinely accomplishes.

Mapping the visibility

  • Your ISP. Without a VPN, sees your traffic's destinations and content (for unencrypted traffic). With a VPN, sees only that you're connected to a VPN server and how much data flows — not the destinations or content within the tunnel.
  • Your VPN provider. Now occupies the position your ISP previously held — capable of seeing your traffic's destinations and, for unencrypted content, the content itself. This is exactly why the provider's own logging policy and trustworthiness matter so much.
  • The destination site. Sees the VPN's IP instead of yours, but still sees everything about your interaction with that specific site — logins, form submissions, browsing behavior on that site.
  • Your browser. Unaffected by the VPN — fingerprinting, cookies, and stored data all function exactly as they would without one.
  • Any account you're logged into. Knows it's you, VPN or not.

The core insight: trust moves, it doesn't disappear

A VPN is fundamentally a decision about who to trust with visibility into your traffic — moving that trust from your ISP to your VPN provider, not eliminating the need for trust altogether. Choosing a VPN provider is, in large part, a decision about which entity you're more comfortable holding that position.

FAQ

Does a "no-logs" VPN policy solve this concern?

It's meant to, but ultimately relies on trusting the provider's claim (or an independent audit, where one exists) — it's a real mitigating factor, not an absolute guarantee, since verifying a negative (that logs genuinely don't exist) is inherently difficult from outside the company.