Internet Tracking, cookies and what follows you around
What a VPN does, and the three things it cannot do
An honest account of VPNs: what the encryption protects, who you are trusting instead, when one is genuinely useful, and the marketing claims to ignore.
The short answer
- A VPN encrypts the link between your device and a server run by a company, so the network you are on sees only that connection and the sites you visit see the server's address instead of yours.
- It does not remove the party who can see where you go, it replaces your internet provider with a VPN provider, which is only an improvement if you trust the second one more.
- It cannot stop cross site tracking, because cookies, logins and device fingerprints are untouched by a change of network address.
- It cannot make you anonymous, because the provider sees both ends of the connection and knows who is paying for the account.
- It cannot protect you from malware or phishing, which arrive through the tunnel exactly as they would without it.
- It is genuinely worth having for networks you do not control, for reaching your own home or office systems, and for keeping your home address out of a site's logs.
A VPN builds an encrypted tunnel between your device and a server run by some company, and your traffic enters the internet from that server instead of from your own connection. Two things change and nothing else does. The network you are sitting on, whether a cafe, a hotel or your own provider, can no longer see which sites you reach, only that you are connected to a VPN and how much data is moving. The sites you visit see the server's address and location rather than yours. That is the entire product. Every other claim is either a consequence of those two facts or is not true.
What actually changes when you turn it on
Start with what your provider could see before. Because nearly every site is encrypted, it could not read your traffic, the pages you opened or what you typed. It could see the names you looked up and the addresses you connected to, which is enough to know you visited a particular bank, forum or clinic. With a VPN on, that drops to one destination: the VPN server.
Lookups should travel inside the tunnel too. When they do not, your provider still receives the name of every site you visit, a failure known as a DNS leak. Any VPN worth using resolves names on its own servers, and understanding how DNS lookups work is what lets you test that rather than take it on trust.
There is a cost, and it is physics. Your traffic takes a detour, so delay rises by the round trip to the server, which matters for calls and games, and throughput drops a little from encryption and from sharing the server with other users. A server in a distant country multiplies both. Sluggishness with the tunnel on is normal rather than a fault, though rule out the ordinary causes of a slow connection first.
The trust transfer nobody mentions
A VPN does not remove the party that can see your traffic. It swaps one for another. You go from an internet provider, a licensed company in your own country with a public complaints process and usually no interest in you, to a company you may know nothing about, in a jurisdiction you did not choose, funded in a way you cannot see. Sometimes that is a good trade and sometimes it is a terrible one. The question is never whether a VPN is private. It is: private from whom.
On the standard no logs claim, be precise. It is a policy, not a property of the technology. The provider is technically able to record what passes through, so the promise is only as strong as the operator and the law where it sits. Two things make it credible: an independent audit of the running systems, which tells you about one date and ages fast, and a track record of answering legal demands with nothing to hand over, which is far stronger. Separate connection logs from activity logs too, since most providers keep some connection data to enforce device limits and fight abuse.
Free consumer VPNs deserve blunt treatment. Servers and bandwidth for millions of people cost real money, so something pays for them. In the worst documented cases that has meant injecting content, selling traffic data, or reselling users' spare bandwidth as an exit point for strangers. If you cannot explain how a free service is funded, assume you are the funding.
The three things a VPN cannot do
These gaps are inherent. None is fixable by choosing a better provider.
It cannot stop you being tracked. Your network address is one weak signal, and the easiest to replace. Cookies survive a tunnel. Signing in identifies you by name instantly. Fingerprinting reads your screen, fonts and graphics hardware, none of which change. Everything in how cross site tracking works runs exactly the same with the tunnel up.
It cannot make you anonymous. You have an account, you paid for it somehow, and the provider sees both ends of the connection at once. That is a single point that knows who you are and where you went, which is the opposite of anonymous. Onion routing tools such as Tor remove that single point by splitting the knowledge across separate relays, at a serious cost in speed. A VPN is a privacy tool against your network and the sites you visit, not protection from a determined investigator.
It cannot protect you from malware or scams. A hostile download travels through an encrypted tunnel perfectly well and is not made safer by the encryption. A fake login page works the same whatever address you appear from, so nothing in a VPN interferes with a convincing phishing message or with the families of malware. Many providers bundle a domain blocklist, which is ordinary DNS filtering: mildly useful, and nothing to do with the tunnel.
When a VPN is genuinely the right tool
The real uses are specific rather than general.
- Networks you do not control. Hotel, airport and shared building wifi, where you have no idea who runs the equipment. Encryption covers most of the risk already, but a tunnel removes the rest and stops the operator logging your destinations. The realistic version of that risk is set out in what is actually dangerous on a public network.
- Reaching your own network. The original purpose. A VPN into your home or office lets you use a file server or an internal tool as though you were there, without exposing it to the open internet.
- Travel in a country that filters heavily. A tunnel can restore access to normal services. Check the law first, since a small number of countries restrict or ban VPN use, and connections may be blocked whatever the rules say.
- Keeping your home address out of a site's logs. Useful when dealing with a marketplace, a forum or a stranger who does not need your approximate location.
- Region shifting for streaming. Sometimes it works. Services detect and block the address ranges VPN servers use, it is an endless back and forth, and it usually breaks the terms you agreed to. Treat it as unreliable rather than a feature.
Matching the tool to the actual risk
| What you are worried about | Does a VPN help | What actually fixes it |
|---|---|---|
| Someone on the cafe wifi reading your traffic | Yes, fully | Encryption already covers most of it; a VPN closes the rest |
| Your provider building a list of sites you visit | Yes, it moves to the VPN instead | Choosing which company holds that record |
| A website logging your home address | Yes | Nothing else does this as easily |
| Ads and profiles following you between sites | No | Tracking protection, one content blocker, a separate email address |
| Being identified by a site you log into | No | Not logging in, or using a separate browser profile |
| Malware from a download | No | Updates, care with sources, and the built in system protections |
| Phishing and fake login pages | No | Never acting from an inbound link; passkeys or two factor sign in |
| Being anonymous to a serious investigator | No | A tool designed for it, and a different way of working entirely |
Read the no column as the honest limit of the category rather than a failing of any one product. It doubles as a filter for marketing: a service that claims the bottom five rows is telling you something untrue.
How to judge a provider without being sold to
Ignore ranked lists and scores, which are frequently paid placements. Test a provider against things you can check.
- Who owns it and where it is based. A named parent company and a clear jurisdiction beat a brand with no visible owner.
- Has the no logs claim been audited by an outside firm, how recently, and was the full report published.
- What it has actually done when served a legal demand. Transparency reports and real cases outweigh any promise.
- Does it use current protocols. WireGuard and OpenVPN are open and well inspected. A proprietary protocol with a marketing name and no documentation is a reason for caution.
- Is there a kill switch that blocks traffic when the tunnel drops, and are lookups resolved inside the tunnel by default.
- How it is paid for. A plain subscription price aligns the incentives; free at consumer scale rarely does.
Two alternatives are worth knowing. Browser features labeled as a VPN are usually proxies covering that browser only, leaving everything else on your normal connection. Running your own server gives you a tunnel you fully control, which is excellent for reaching your own network and poor for privacy, because the traffic on that address is all yours with no crowd to blend into.
What to set up today
Decide the use case before you pay for anything. For travel and untrusted networks, a subscription you switch on when you leave home is enough, and leaving it off at home avoids the speed cost for no benefit. For reaching your own files from elsewhere, you want a VPN into your home rather than a commercial one. For stopping ads following you around, a VPN is the wrong purchase and the browser settings in managing cookies and consent do more.
Once it runs, do three checks. Confirm your visible address changed. Run a DNS leak test and confirm lookups resolve through the provider. Drop the tunnel deliberately and see whether the kill switch really blocks traffic. Then leave your other defenses alone, because the padlock and what HTTPS proves do more for your security on an average day than the tunnel does.
One last note: VPN legality and the rules on what you may access differ by country, and this is general information rather than advice about your situation. If you are traveling somewhere with strict rules, check them before you go.
Common questions
Do I really need a VPN at home?
Usually not. On your own connection the main thing a VPN changes is that your internet provider can no longer see which sites you reach, and that record moves to the VPN company instead. If you are comfortable with your provider holding it, the tunnel buys you a slower connection for little gain. Turn it on when you travel or use networks you do not control.
Can my internet provider see what I do with a VPN on?
It can see that you are connected to a VPN, which server address you are using, when, and roughly how much data is moving. It cannot see the sites beyond it or the contents. If lookups are not going through the tunnel, a fault known as a DNS leak, your provider still sees every site name, so test for that before assuming you are covered.
Is a free VPN safe to use?
Treat it with suspicion. Bandwidth and servers cost real money, so a service with no price has another source of income, and the documented cases include selling traffic data and reselling users' connections to other people. A free tier from a provider with a paid product is a different thing and can be reasonable, though it is usually limited on purpose.
Will a VPN let me watch a different country's streaming catalog?
Sometimes, and unpredictably. Streaming services detect the address ranges VPN servers use and block them, providers rotate addresses, and the state of play changes week to week. It also typically breaks the terms of service you agreed to. If this is your only reason for buying one, expect it to stop working without warning.
Does a VPN hide me from Google or Facebook?
No. Those companies identify you by your account, and you are signed in. Even signed out, cookies and device fingerprinting do most of the work, and your address is a minor signal they will happily ignore. Changing where your traffic appears to come from has almost no effect on a company you have an account with.