Note: This article is not sponsored by or affiliated with any company. We are providing this information for free, with no sponsorships, to increase internet privacy. You can support our work by sharing this article. Cheers! ModemGuides Team
Short answer: A VPN does not make you invisible. It hides your browsing from your internet provider by sending it through the VPN company's servers, which means the VPN company can now see what your ISP used to see: which sites you visit and when. You are trading one middleman for another, so the trade only helps if the VPN keeps no records and can prove it. Mullvad, Proton VPN, and IVPN are three providers with evidence behind that claim.
Key Takeaways
- Your ISP can see which websites you visit. In 2017 Congress repealed the FCC privacy rules that would have required providers to ask your permission before using or sharing that history.
- A VPN moves that visibility from your ISP to the VPN provider. "No-logs" is a marketing phrase, not a legal definition.
- Free VPNs are the riskiest category. Several have sold their users' bandwidth, harvested their data, or enrolled their computers in a botnet.
- Look for three things in a provider: servers with nothing worth seizing, outside audits published in full, and a track record of having nothing to hand over.
The Sales Pitch vs. How the Internet Works
We've all heard the sales pitch: "Turn on a VPN and become invisible."
Marketing campaigns for Virtual Private Networks (VPNs) often paint a picture of total anonymity. They tell you that your Internet Service Provider (ISP), whether it's Comcast, AT&T, or Verizon, is spying on you, and the only way to stop them is to route your traffic through a VPN.
They aren't lying about the ISP part. Your ISP can see the websites you visit. But what VPN marketing leaves out is a critical detail about how the internet works:
You aren't eliminating the middleman. You are just hiring a different one.
When you turn on a VPN, you are taking the data that your ISP used to see and handing it over to a private company, often based in another country. If that company isn't trustworthy, you might be safer just sticking with your ISP.
The Tunnel Analogy: What Changes Hands
To understand the privacy shift, imagine your internet traffic is a physical letter you are mailing.
- Without a VPN: You hand your letter to your mail carrier (your ISP). The carrier looks at the address on the envelope (the website you are visiting) to know where to deliver it. On a secure HTTPS site the carrier cannot read the letter inside, but knows exactly who you are writing to and how often.
- With a VPN: You put your letter inside a secure steel box and mail that box to a VPN provider. Your mail carrier only sees the steel box going to the VPN company, and has no idea where the letter inside is headed.
Here is the catch: once the box arrives at the VPN company, they have to open it to send your letter on.
This means the VPN provider can see what your ISP used to see: the sites you visit, when you connect, how much data you move, and the home IP address it all came from. If the provider is malicious, or is forced by a government to start recording, it has a complete map of where you go online.
For a plain-English breakdown of the tunnel itself and what happens when it drops, see our guide to VPN kill switches, tunnels, and providers.
What Your ISP Can See, With and Without a VPN
Most websites now use HTTPS, which scrambles the contents of each page. That protects what you read and type, but not where you went. Here is who sees what:
| What is visible | Your ISP, no VPN | Your ISP, VPN on | The VPN provider |
|---|---|---|---|
| Which sites you visit (the domain names) | Your ISP, no VPN: Yes | Your ISP, VPN on: No, only the VPN server's address | The VPN provider: Yes |
| Pages, searches, and passwords on HTTPS sites | Your ISP, no VPN: No | Your ISP, VPN on: No | The VPN provider: No |
| Everything on older sites without HTTPS | Your ISP, no VPN: Yes | Your ISP, VPN on: No | The VPN provider: Yes |
| Your home IP address | Your ISP, no VPN: Yes | Your ISP, VPN on: Yes | The VPN provider: Yes |
| When you are online and how much data you use | Your ISP, no VPN: Yes | Your ISP, VPN on: Yes | The VPN provider: Yes |
Your ISP has reasons to look. Congress repealed the FCC's broadband privacy rules in 2017, before they took effect, so providers do not need your opt-in consent to use or share your browsing history. In October 2021 an FTC staff report on six major providers found that several combine browsing and app-usage data to target ads, sort customers into sensitive categories such as race and sexual orientation, and share location data with third parties.
The ISP's reach does not stop at the wire outside your house. If you rent the provider's gateway, the provider also manages the box your whole home network runs through. Xfinity and AT&T gateways, for example, do not let you change the DNS servers they use, and rented gateways generally have no VPN client built in. With your own modem and router you can change DNS at the router, run a VPN for the whole house, and stop paying the rental fee.
One more monthly fee to kill
Renting your modem? That's $120+ a year.
Own it instead. It pays for itself in months. 90-day warranty and 30-day returns.
Pick your provider:
The "No-Logs" Myth
Almost every VPN claims to have a "Strict No-Logs Policy." Unfortunately, in the tech world, "No Logs" is a marketing term, not a legal definition.
Several "private" VPNs have been caught handing user data to authorities despite claiming they kept no records. What they kept was usually "metadata" such as:
- Connection timestamps: exactly when you logged on and off.
- Bandwidth usage: how much data you downloaded.
- Original IP address: the address your ISP assigned to your home, which points straight back to you.
None of that is your browsing history, and all of it is enough to identify you. If a VPN holds onto this data, your privacy is an illusion.
The Hall of Shame: VPNs That Broke Their Promises
Marketing is easy; keeping promises is hard. Over the years, several VPN services have been caught handing over user data, selling it, or collecting far more than they admitted, all while advertising privacy. Here are the cautionary tales that show why a slick website is not proof of anything.
Hola VPN: the "botnet" trap
Hola built its free VPN on a peer-to-peer network instead of servers, which means other people browse the web using your internet connection. In 2015 it came out that Hola was selling its free users' bandwidth to paying customers through a sister brand called Luminati (now Bright Data). If someone uses your connection to do something illegal, it looks like you did it.
IPVanish: the "zero-logs" illusion
In 2016 IPVanish advertised a strict zero-logs policy. When Homeland Security investigators sent its then-owner, Highwinds, a summons in a criminal case, the company first said it had no data, then handed over the customer's name, email address, home IP address, and connection times. IPVanish has been sold twice since (to StackPath in 2017 and Ziff Davis in 2019) and has commissioned outside no-logs audits. Worth knowing when you read VPN rankings: Ziff Davis also owns PCMag and CNET.
PureVPN: the FBI logging case
PureVPN advertised a "Zero-Log" policy for years. In a 2017 Massachusetts cyberstalking case, an FBI affidavit described PureVPN records showing the same customer connecting from two different originating IP addresses, one at home and one at work. Catching the stalker was the right outcome (he was sentenced to 17 and a half years), but the case proved the company was logging enough to identify a user.
Onavo Protect: the Facebook data vacuum
Facebook bought Onavo in 2013 and marketed its free "VPN" as a way to keep your data safe. In practice it reported which apps people used back to Facebook, which used the data to track competitors. Apple had it removed from the App Store in 2018, Facebook shut it down in 2019, and in 2023 an Australian court ordered two Meta subsidiaries to pay A$20 million for misleading users about it.
911 S5: free VPN apps that built a botnet
In May 2024 the U.S. Justice Department dismantled the 911 S5 botnet, which spread through free VPN apps for Windows: MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN, and ShineVPN. Computers that installed them were rented out to criminals as proxies, covering more than 19 million IP addresses in over 190 countries, so crimes committed through those connections looked like they came from the victims' own devices. If any of those names look familiar, the FBI posted Windows removal instructions at fbi.gov/911S5.
Urban VPN Proxy: reading your AI chats
In December 2025, researchers at Koi Security reported that Urban VPN Proxy, a free browser extension with more than 6 million Chrome users and a "Featured" badge from Google, had been capturing users' conversations with ChatGPT, Claude, Gemini, and other AI chatbots since July 2025 and sharing them with an affiliated data broker. The collection ran whether the VPN was switched on or off. Sister extensions from the same publisher brought the total past 8 million users.
SplitVPN: a breach and a disputed log file
In July 2026 a breach at SplitVPN (formerly NotVPN) exposed about 865,000 accounts, a figure confirmed by the breach-tracking service Have I Been Pwned. Researchers at Mysterium VPN, a competing VPN company, say the stolen database also holds nearly 58 million connection records, which would contradict SplitVPN's no-logs promise. SplitVPN says those records are fabricated. Either way, the emails, IP addresses, and partial payment details the company did hold are now in criminal hands.
Who Can You Trust? The "Good Guys"
So, is everyone lying? Not quite. If you want to stop your ISP from profiting from your browsing but don't want to hand it to a shady VPN, look for three specific things:
- Servers with nothing worth seizing. Either the VPN runs on RAM-only servers with no hard drives, so everything is wiped the moment power is cut, or every disk is fully encrypted with the keys stored somewhere else.
- Outside audits, published in full. An independent security firm such as Cure53 or Securitum has inspected the servers themselves, not only the written policy, and anyone can read the report. An audit is a snapshot of one moment, so repeat audits count for more than a single old one.
- A proven track record. When police or courts came asking, the company had nothing to give them.
Based on these criteria, here are the VPNs that are "privacy-focused" rather than "marketing-focused."
Mullvad VPN: the privacy purist
Mullvad, based in Sweden, is widely considered the gold standard for privacy enthusiasts.
- Why it's trustworthy: It doesn't ask for your email address. Signing up generates a random account number, and you can pay with cash, crypto, or a voucher. Every Mullvad server runs from RAM with no disks, and its outside audits are published in full. In April 2023 Swedish police arrived at its office with a search warrant for customer data and, by Mullvad's account, left without taking anything because there was nothing to take.
- The catch: It is very simple. No streaming unblocking or "Netflix features," and no port forwarding. Since January 2026 Mullvad supports only the WireGuard protocol, so an older router that connects with OpenVPN needs to be set up again with WireGuard.
Proton VPN: the Swiss vault
Proton VPN comes from the team behind Proton Mail, founded by scientists who met at CERN, and is controlled by the nonprofit Proton Foundation in Switzerland.
- Why it's trustworthy: Its apps are open-source, meaning anyone can inspect the code. In 2026 it passed its fifth consecutive annual no-logs audit by the security firm Securitum, and it publishes each report in full. Its "Secure Core" option routes your traffic through Proton-owned servers in hardened data centers before it reaches the open internet. It also runs a free tier with no data cap under the same audited policy.
- The catch: Proton does not use RAM-only servers. It relies on full-disk encryption with the keys stored off-site, and explains its reasoning here. Swiss law is also in motion: a proposed surveillance rule that would have made services identify their users was sent back for a second round of consultation in early 2026 after heavy criticism, and Proton has started moving some infrastructure out of Switzerland. Paid plans cost more than budget VPNs.
IVPN: the transparent choice
IVPN is smaller but unusually open. It tells you exactly who owns and runs the company and publishes a transparency report.
- Why it's trustworthy: Like Mullvad, it does not require an email address to sign up, and its apps are open-source. It has commissioned a security audit from Cure53 every year since 2019. It has also taken a hard stance against affiliate marketing, which is why you rarely see it on "Top 10" lists: it doesn't pay commissions to reviewers.
- The catch: A smaller server network, and its one dedicated no-logs audit dates from 2019. IVPN says it will not commission another, arguing that a no-logs stamp only describes a single day.
What a VPN Won't Hide
Even a trustworthy VPN only covers the path between you and the VPN server. It does not stop:
- Accounts you are logged into. Google, Facebook, and Amazon know who you are the moment you sign in, VPN or not.
- Cookies and browser fingerprinting. Ad networks recognize your browser without needing your IP address.
- Software that reports home. Apps and operating systems can send their own identifiers from inside the tunnel. Our article on Microsoft's GDID covers one case where that identified a user across several VPNs.
- Leaks when the tunnel drops. Without a kill switch, your device falls back to your normal connection and your ISP's DNS servers. Our DNS servers guide shows how to check for leaks.
Running the VPN on Your Router
A VPN app protects one device. A VPN client on your router protects everything in the house at once, including smart TVs and consoles that cannot run an app, and it counts as a single device on your plan. Mullvad and Proton VPN both let you generate WireGuard configuration files for a router. ISP-rented gateways cannot do this, so it takes a router you own. Our hardware VPN router guide covers which routers are fast enough to be worth it.
Summary: Should You Use a VPN?
Yes, but be picky.
Using a well-chosen VPN is still better than letting your ISP build an advertising profile from your browsing history. However, don't grab the first free VPN you see in the App Store.
The Golden Rule: If a service is free, you are the product. Pay for a service like Mullvad or Proton, and rest easy knowing your "digital tunnel" is private.
Related on ModemGuides
What Is a VPN Kill Switch? Tunnels and Providers Explained
Hardware VPN Routers: How to Encrypt Your Entire Home Network at the Gateway
Frequently Asked Questions
Can my ISP see what I do when I use a VPN?
No. With a VPN on, your ISP sees that you are connected to a VPN server, when you connected, and how much data you moved. It cannot see which websites you visit or what you do on them.
Can a VPN provider see my browsing history?
It can see the same things your ISP could see without a VPN: the sites you connect to and when. It cannot read the contents of pages on HTTPS sites. Whether it records any of that is the whole question, which is why audits and track record matter more than the words "no-logs" on a homepage.
Is it safer to trust my ISP or a VPN?
It depends on the VPN. An audited provider that keeps no records is a better custodian than an ISP that uses browsing data for advertising. A free or unproven VPN can be worse than your ISP, because it sees the same traffic with less regulation and less to lose.
Are free VPNs safe?
Most are not. Running VPN servers costs money, and free services have covered that cost by selling bandwidth, selling data, or worse. The main exception is a free tier offered by an audited paid provider, such as Proton VPN's.
What does "no-logs" mean?
It means the provider says it keeps no record of what you do or when you connect. There is no legal standard behind the phrase, so it is only as good as the evidence: outside audits of the servers, published reports, and cases where authorities asked for data and the company had none.
Does a VPN make me anonymous?
No. A VPN hides your browsing from your ISP and hides your home IP address from the sites you visit. It does not hide you from accounts you log into, from cookies and browser fingerprinting, or from software on your own device.
If websites already use HTTPS, do I still need a VPN?
HTTPS hides what you do on a site. It does not hide which site you are on. A VPN hides the list of sites from your ISP, which is the part ISPs can use for advertising.

