Top10VPN is editorially independent. Buying a VPN through our links supports our work.
What a VPN Can and Can’t Hide
Follow us:
Simon Migliano
Simon Migliano is a recognized world expert in VPNs. He's tested hundreds of apps and his research has been featured on the BBC, The New York Times, and more. Read full bio
A VPN encrypts and hides all internet traffic leaving your device. It hides your IP address and location from the websites you visit, and it hides which sites and apps you connect to, from your Internet Service Provider (ISP) and Wi-Fi admin. HTTPS already stops them reading what you do on those sites – a VPN is what stops them seeing which sites you go to in the first place. It won’t hide your MAC address, and only a handful of VPNs can spoof your GPS location. Advertisers can still follow you through cookies and fingerprinting, and governments can still identify you if your VPN leaks or your provider keeps logs.
A virtual private network (VPN) is one of the best tools you can use to protect your privacy, security, and freedom online.
A good VPN hides which sites you visit, what you download, and how you spend your time online from your Internet Service Provider (ISP), from cybercriminals, from the websites and apps you use, and – in most circumstances – from government agencies too.
If you don’t use a VPN, each of these entities will know a lot more about who you are and what you do online.
What exactly a VPN hides depends on who you’re trying to hide it from. You should know that a VPN won’t hide all your internet activity from everyone.
A good VPN hides the following:
Your personal IP address
Your geographic location
The websites you visit
The apps you use
How long you spend on websites and apps
The files you download or upload
Torrenting and P2P activity
The fact you’re using a VPN – but only if it offers obfuscation
Different entities have access to various pieces of the information listed above.
Your ISP, for instance, won’t see your browsing or download activity when you use a VPN, but it still knows your real IP address and your geographic location, because it assigned that IP address in the first place. Unless you use a VPN with advanced obfuscation technology, your ISP will also be able to see that you’re using a VPN.
A VPN won’t make you completely anonymous, either. It hides some of your online identity and activity, but there are still ways for advertisers, tech companies, and government agencies to work out who you are – which I cover in detail later in this guide.
Why Trust Us?
We’re fully independent and have been reviewing VPNs since 2016. Our ratings are based on our own testing results and are unaffected by financial incentives. Learn who we are and how we test VPNs.
What a VPN Actually Hides
A well-configured VPN hides information like your IP address and geographic location from the websites and apps you use, and your web browsing activity and DNS lookups from your ISP.
It does this by encrypting your traffic, and using a remote VPN server as the middleman between your device and the server hosting the destination website or data for your app.
Here’s a table summarizing exactly what a VPN hides, and who it hides it from:
Data Type
Your ISP
The Websites & Apps You Use
Governments & Police
Hackers (on Public Wi-Fi)
Employers & Other Wi-Fi Admins
Your IP Address
No
Yes
Sometimes
No
No
Your Physical Location
No
Yes, if it’s based on your IP address
Sometimes
No
No
Websites/Apps You Visit
Yes
No
Mostly
Yes
Yes, unless it’s a managed device
Time Spent on Websites/Apps
Yes
No
Mostly
Yes
Yes, unless it’s a managed device
Search History
Yes
No
Mostly
Yes
Yes, unless it’s a managed device
Downloads
Yes
No
Mostly
Yes
Yes, unless it’s a managed device
Torrenting
Yes
Yes*
Mostly
Yes
Yes, unless it’s a managed device
The Fact You’re Using a VPN
Yes, with obfuscation
Yes, with obfuscation
Yes, with obfuscation
Yes, with obfuscation
Yes, with obfuscation
* When you torrent through a VPN, both the tracker site and the other peers in the ‘swarm’ see the VPN server’s IP address rather than your own. The exception is a static or dedicated IP – an address assigned to you alone, or shared with only a handful of other subscribers who’ve paid for the same service. Because that address is tied to you, activity from it can be linked back to your account, and you’re then relying on your provider not to retain those records, or to hand them over if subpoenaed.
One important qualifier on the ISP column. Almost everything you do online today already travels over HTTPS, which means your ISP can’t read your search terms, your messages, or the contents of the files you download – encryption at the website’s end took care of that long before you installed a VPN. However, what your ISP can see without a VPN are the domain names of the websites you’re connecting to, when you connected, and how much data moved. By using a VPN, you remove that last layer.
The tricky part is understanding who can and can’t see each piece of information.
It isn’t enough to know that a VPN hides your location – you also need to know who it’s hidden from, and who it isn’t. Otherwise you could put yourself at risk by assuming you’re protected when you’re not.
Let’s look at each of these in more depth.
1. Your IP Address from Websites & Apps
A virtual private network (VPN), if working properly, hides your public IP address from the websites and applications you use.
Your IP address is tied to sensitive information, such as your Internet Service Provider (ISP) and your rough geographic location.
It also gives attackers something to aim at: anyone who knows your IP address can scan your router for open ports and probe them for weaknesses.
Your IP address reveals sensitive information such as your approximate location.
Websites and apps can log your IP address when you use their site. This means they can record your activity and then link it back to you each time you return. They typically use your IP and additional information available from your browser, such as cookies and fingerprinting.
Websites regularly share this information with other websites, advertising networks, data brokers and online trackers, too. Collectively, they build profiles of you and your browsing habits, using your IP address as a thread that ties it all together.
These entities can then track you across the internet, targeting you with personalized ads, gathering more information about you, and monitoring what you do.
A VPN cuts that thread by hiding your IP address as you browse. Your traffic travels via a VPN server on its way to the site you’re using, so it appears to originate from the server rather than from you.
When you use a VPN, the websites you visit see the IP address of the VPN server.
Using a VPN doesn’t stop websites and advertisers from seeing what you do online, but it does stop them from linking that activity back to you via your IP address, and makes building a profile of you far harder.
Hiding your IP address also lets you get around IP bans. Forums, and other sites, often use your IP address to suspend individual users, so if you’ve been banned by mistake, a VPN will restore your access by giving you a fresh IP address.
2. Your Real Location from Websites & Apps
By replacing your IP address with the VPN server’s IP address, a VPN will hide your real location from the websites you visit – which is what lets you convince a streaming service you’re geographically sitting wherever the server is.
Websites and apps can vary their content based on your geographic location. Netflix, for example, has a different catalog of movies and TV shows for US users than it does for UK users.
Streaming websites use your IP address to determine which country-specific content to show you, so changing that IP address with a VPN lets you change your Netflix region and watch content that isn’t available where you live. I see this with HBO Max: when I connected through Surfshark’s servers in different countries, the app’s library changed each time to match the server location rather than mine.
I accessed different HBO Max regions using Surfshark.
Streaming isn’t the only reason to hide your physical location. Most other forms of internet censorship typically rely on IP-based geolocation too. For example, Microsoft Bing has been found to censor autofill suggestions whenever the user’s IP address places them in China.
EXPERT ADVICE: IP-based geolocation isn’t the only way that websites and apps can track where you are. Apps like Uber and Google Maps use GPS data to determine your location. Most VPNs don’t spoof your GPS location, although there are some exceptions, which I cover further down.
3. Your Browsing Activity from Your ISP
Before I get to what a VPN hides here, it’s worth laying out what your ISP can actually see without one – because a lot of guides on this subject are describing the internet of fifteen years ago.
Almost every website and app now connects over HTTPS, which encrypts the contents of the connection at the website’s end. Your ISP cannot read the pages you load, the search terms you type, the messages you send, or the specific URLs you request. That was true before you ever installed a VPN.
What HTTPS doesn’t encrypt is the addressing information needed to deliver your traffic in the first place. So without a VPN, your ISP can still see:
The domain behind every site and app you connect to – that you opened netflix.com, though not which show you watched
The timestamps for when each connection started and ended
How long you stayed connected
How much data you sent and received
The broad category of what you’re doing – streaming, gaming, or P2P – which it can infer from connection patterns and destination networks
Your ISP picks up the domain in one of three ways: your DNS lookups, the Server Name Indication field that your browser sends unencrypted during the TLS handshake, or simply the destination IP address. Switching to encrypted DNS (DoH or DoT) closes the first of those. The other two still give the game away.
That’s more restricted than “your ISP sees everything you do online” – but don’t mistake this for harmless. A list of every domain you’ve connected to, timestamped and measured, still exposes your bank, your health worries, your politics, your dating life, and the shape of your day. It’s exactly the sort of data that advertisers pay for.
A VPN fixes this. It encrypts your traffic a second time, and routes all of it through one server, so the addressing information HTTPS leaves exposed disappears along with everything else. Instead of a list of domains, your ISP sees a single continuous connection to one VPN server IP, and a running total of data transferred. It can’t tell whether you’re streaming, banking, or just reading the news.
The same is true of anyone else with router-level access, including employers, parents, landlords, and school and college administrators.
That matters because ISPs keep records of the connections you make whenever you don’t use a VPN, and in some countries they’re legally required to. UK ISPs, for instance, must retain 12 months of Internet Connection Records under the Investigatory Powers Act – logged at domain level precisely because HTTPS puts anything more granular out of reach.
Those records create several distinct risks:
Privacy. ISPs can share their connection logs with whoever they choose. In practice, your ISP is likely passing information about your browsing habits to data brokers, who then sell it on to willing buyers – usually advertising companies. The list of domains you visit is enough to place you in an advertising segment without anyone ever reading a word you typed.
Freedom. ISPs can be compelled to share those records with government agencies and police forces. That not only facilitates mass surveillance, it also lets governments run censorship regimes that limit your freedom online. Blocking works at the same level the logging does: an ISP doesn’t need to read your traffic to stop you reaching a domain, which is why domain-level visibility is worth removing.
Security. Your ISP likely holds those connection records in a database, and if cybercriminals break into it, they gain access to all of them.
Unfortunately, these breaches are far from unheard of. Austria’s largest ISP, A1 Telekom, suffered one in 2019, and in 2017, a breach at a Russian ISP exposed the data of 8.7 million people.
Performance. ISPs have been known to throttle the speeds of internet users engaging in high-bandwidth activity, such as online gaming and P2P file-sharing. There are suspicions that ISPs sometimes use throttling to undermine competitors.
If your ISP can’t see what you’re doing online, it can’t single out your gaming traffic for throttling, work with governments to implement censorship measures, or let police track you in real-time. And because a VPN stops your ISP from logging your browsing history in the first place, there’s simply less data available to be breached, sold to advertising networks, or handed to government agencies.
There are two limits worth being clear about. A VPN can’t erase any records your ISP has already collected from your unprotected browsing. And while it can help stop activity-based throttling, your ISP can still see the total volume of data you’re moving – so if it throttles heavy users regardless of what they’re doing, a VPN won’t get you around that.
4. Your Sensitive Data from Hackers & Cybercriminals
A VPN helps keep your personal and sensitive data hidden from hackers and cybercriminals in several ways.
I’ve already covered two of them: hiding your browsing from your ISP reduces the amount of data that can be stolen in a breach, and hiding your IP address makes it much harder for anyone to scan your router, dox you, or hit you with a DDoS attack.
The third is what a VPN does on open Wi-Fi networks, where it protects you from two main forms of man-in-the-middle attack:
DNS Spoofing: On unsecured public Wi-Fi networks, it’s relatively easy for attackers to hijack your DNS requests and re-route your connection to a website under their control, without you noticing.
A good VPN for public Wi-Fi can protect you from DNS spoofing by encrypting your requests and resolving them on the VPN provider’s own DNS servers. The attacker can’t see your DNS request, let alone spoof it.
Session Hijacking: Hackers might also steal the ‘session cookies’ that appear temporarily while you’re connected to a website’s server. These are small text files stored in your browser that authenticate and facilitate an individual session on that website.
On unsecured Wi-Fi networks, attackers can use packet sniffing or fake hotspots to steal these cookies and take over your session, for any site that doesn’t use HTTPS.
By encrypting your connection, a VPN makes your traffic unreadable to everyone except the VPN server. This includes hackers on a public Wi-Fi connection. It therefore keeps your personal information safe and hidden from criminals.
5. Your Torrenting Activity from Your ISP, Police, & Copyright Holders
Torrenting is the one area where the HTTPS caveat above doesn’t apply, and where your ISP can genuinely see a great deal. BitTorrent doesn’t have the blanket encryption the web does: your ISP can identify P2P traffic by its distinctive connection pattern, see the trackers and peers you’re talking to, and in many cases work out what you’re sharing. Using a VPN can make a big practical difference.
A good VPN hides your torrenting downloads and P2P file-sharing activity from your ISP entirely. This is helpful because ISPs often throttle (or even block) P2P traffic on account of how bandwidth-hungry it is.
Encrypting and rerouting prevents your ISP from identifying your traffic as torrenting, so it can’t be singled out for throttling. (Bear in mind that an ISP which throttles based on total data volume can still act on that, since it can always see how much you’re transferring.)
It also means your torrenting activity stays hidden from police and copyright holders, too. Ordinarily, your ISP would typically work with law enforcement to issue you with DMCA notices, fines and legal action, should you ever mistakenly download any copyrighted material. VPN encryption stops your ISP from logging your P2P activity in the first place, which means it has no relevant information to pass on to these authorities.
A VPN protects you from other torrent users, too. Downloading and uploading torrent files normally exposes your IP address to everyone in the ‘torrent swarm’. With a VPN, the address visible in the swarm – and the one associated with the files you download – is the VPN server’s, not yours. The exception is a static or dedicated IP address – a service you would sign up to with the VPN provider. Because it’s assigned to you alone, it can be traced back to you in a way a shared server IP can’t.
6. The VPN Traffic Itself from Your ISP
ISPs and Wi-Fi administrators can’t see the details of your browsing activity when you use a VPN, but they can see that a VPN is being used. They do this by checking the connection’s port number, or more commonly, by using a tool known as Deep Packet Inspection.
Deep Packet Inspection (DPI) is an advanced method for analyzing network traffic. It uses sophisticated pattern-matching to classify the ‘type’ of data being transmitted over the network, and is very effective at identifying normal VPN traffic.
The best VPN services can hide the fact you’re using a VPN from your ISP. They do it with VPN obfuscation, which disguises your traffic as regular HTTPS traffic, so that DPI has nothing distinctive to latch onto.
I tested this myself with a packet inspection tool, first on a standard connection, and then with obfuscation enabled.
The packet inspection tool detects an OpenVPN connection.
And my DPI analysis of VPN traffic with obfuscation:
The packet inspection tool perceives a regular HTTP, TLS, or TCP connection.
As you can see, my DPI tool identified the OpenVPN connection immediately, and saw nothing but normal web traffic once obfuscation was switched on.
Obfuscation is therefore how a VPN hides itself from ISPs, governments, employers and Wi-Fi administrators.
What a VPN Doesn't Hide
A VPN can hide everything listed above, but it can’t make you completely anonymous online.
Here’s an overview of what a VPN can’t hide, and who from.
Your IP Address or Physical Location from Your ISP
To supply you with an internet connection, your ISP has to know your physical address and assign you an IP address. There is no way to hide those details from your ISP – not even with a VPN. You also pay them for service, so they have your billing information.
In many countries, there is very little stopping them from sharing that information with governments, police, and any other third-parties willing to pay for it.
What a VPN does do is stop your ISP from monitoring and recording what sites and apps you’re connecting to. With a VPN running, your ISP knows who you are, but not what you’re doing.
Your Browsing Activity from the Websites and Apps You Visit
A VPN hides your browsing activity from your ISP and Wi-Fi administrator, but it doesn’t hide that activity from the website or app you’re using. They can still see exactly what you do on their service.
They can also track your browsing behavior using cookies – small files placed in your web browser when you visit a site, which send information back when you return and let the site re-identify you.
A VPN doesn’t protect you from cookie-based tracking, because cookies aren’t tied to your IP address. They are part of your browser and are sent to the website you’re accessing with every request. That’s why it’s important to delete them regularly, or browse in a private window that discards them when you close it.
Even so, with a VPN turned on, websites and apps are much less likely to trace your activity back to you, because they can’t see your IP address. They can see what you do, but not who you are.
Your account details do the same job as a cookie, and more reliably. The region you signed up in and the country your payment card was issued in stay attached to your account whatever your IP address says, which is why switching servers alone often isn’t enough to change what a service shows you.
NOTE: Websites, advertisers and governments can also work out your identity from your browsing activity itself. If you’re logged into a social media account while browsing with a VPN, or signed up to websites using your email address, it won’t matter that your IP address is hidden – it will be possible to trace your online activity back to you.
Your GPS Location or Wi-Fi Location
Plenty of websites and services use your IP address to determine your physical location, but they can also use your device’s GPS data or Wi-Fi location tracking. It’s how navigation apps and food delivery services find you.
Most VPNs work purely by changing your IP address, so they won’t hide your location from websites and apps that use GPS tracking.
Of the VPNs I’ve tested, only four are capable of overriding your GPS location: Surfshark VPN, Windscribe, IVPN, and TorGuard. Of these, I prefer Surfshark – its GPS spoofing setting on Android was the most reliable of the four in my testing, holding the spoofed location consistently rather than reverting after a few minutes.
You can override your GPS location with Surfshark VPN.
Wi-Fi Location Tracking is a different matter. It triangulates your position using the Wi-Fi access points around your device – routers and smart devices – and it’s both precise and difficult to defeat. Google and Apple both use it in their operating systems, and there are currently no VPN apps that can hide you from it. Apps on mobile devices take their geolocation from the operating system, but there are extensions that can override geolocation within your web browser, such as the Spoof Geolocation and ExpressVPN Browser Extension for Chrome, which work inside your browser to alter the GPS location it resolves.
Your MAC Address
Your device’s MAC address (Media Access Control address) is the unique, 12-character code that identifies the device on your local network. It’s used to coordinate the transmission of information between local devices and to help prevent unauthorized access to the network.
No VPN hides your MAC address. The good news is that it doesn’t need to: even without a VPN, your MAC address isn’t visible to anyone outside your local network as your router strips it out when it forwards packets to the internet, so it isn’t something to worry about. The only caveat to that statement is if you directly connect your device to the internet, without using a router, then your MAC address will be visible to your ISP.
Your Total Data Usage from Your ISP or Mobile Carrier
VPN encryption stops cell phone carriers and ISPs from being able to monitor your online activity. With a VPN turned on, they can no longer see which websites you visit, when you visited them, and how long you spent there.
What a VPN doesn’t hide is how much data you’re consuming. ISPs and mobile carriers can see exactly how much data moves along your connection. Inside or outside a VPN tunnel – it’s just data. In fact, our research has shown that using a VPN can increase cellular data consumption by 4-20%.
You therefore can’t use a VPN to hide from monthly data caps or get unlimited roaming data. If anything, you’ll actually hit your cap sooner, and rack up more expensive data charges.
Your Identity & Activity from the VPN Service Itself
When you use a high-quality VPN, your provider is the one entity that knows what you do online and potentially knows who you are based on billing records. In effect, when using a VPN, you’re choosing to show everything to the VPN company in order to stay hidden from everyone else.
This makes your choice of provider the most consequential decision you’ll make here, because if it wanted to, it could see:
Your name
Your email address
Your IP address
Information about your devices
Which websites and apps you use
The timestamps for each session on these websites and apps
Your download activity
Any P2P and torrenting traffic
The contents of any HTTP traffic (incl. usernames and passwords)
Look at that list again – it’s almost exactly what you stopped your ISP seeing at the top of this guide. That’s the difference a VPN actually makes: it doesn’t remove the visibility, it moves it to a company you chose. Which is why the choice of VPN provider matters so much.
An untrustworthy provider might then sell that information on to criminals and advertisers, or even use it to attack you. This is precisely the business model for many unsafe free VPNs.
Some VPNs have also been known to install backdoors into their service so that governments and law enforcement agencies can spy on user traffic. This is particularly common in countries where VPN use is restricted, such as in China.
Can VPNs Be Tracked?
By encrypting your traffic and tunneling it through a remote server, a VPN hides a great deal from a great many people.
But can you still be tracked while using one? The short answer is yes, it’s possible.
VPNs aren’t bulletproof, and they don’t make you anonymous. There are three main ways your activity can be traced back to you:
1. Your VPN Isn’t Working Properly
If your VPN stops working or is poorly configured, your real IP address can escape the tunnel without you noticing. This is called a leak, and it’s the most common reason a VPN fails to hide what it promises to hide.
There are three kinds of leak worth knowing about, and they fail in different ways.
DNS leaks: Every time you type a domain, your device asks a DNS server to translate it into an IP address. Your VPN is supposed to route that request through its own encrypted tunnel and resolve it on its own servers. When it doesn’t, the request goes straight to your ISP’s DNS resolver in plaintext instead – handing your ISP the list of domains you thought you’d hidden. Your traffic is still encrypted, so this is easy to miss: everything looks like it’s working.
WebRTC leaks: WebRTC is the browser technology behind video calls and live chat, and it works by discovering your device’s real IP address so two browsers can connect directly. It does this at the browser level, underneath the VPN, so it can expose your true IP to any website that asks – even with the tunnel up and running. Chrome, Edge and Firefox are all affected by default.
IPv6 leaks: Your ISP most likely assigns you two addresses: an older IPv4 address and a newer IPv6 one. Plenty of VPNs only route IPv4 traffic through the tunnel, which means any connection your device makes over IPv6 travels outside it, carrying your real address.
IPv6 leaks are the most damaging of the three, and the least well known. Most home IPv4 addresses are shared between hundreds of subscribers behind carrier-grade NAT, so on its own an IPv4 address is a blunt identifier. An IPv6 prefix usually isn’t shared – it’s assigned to your household. A leaked IPv6 address points at your front door in a way a leaked IPv4 address often doesn’t.
There are two acceptable ways to fix this: a VPN either routes your IPv6 traffic through the tunnel properly, or it disables IPv6 on your device for the duration of the connection. Both work. What isn’t acceptable is doing neither and saying nothing, which is still common practice among many VPNs I’ve tested.
You can check all three in about a minute using our What is My IP tool while connected to your VPN. If you see your real IP address, your own city, or your ISP’s name, you have a leak. There’s a full walkthrough of how to diagnose and fix each type in our guide to VPN leaks.
Leaks can be caused by errors in the VPN’s setup or by the VPN connection dropping. To protect against the latter, you need a VPN with a kill switch that actually works – it’s one of the first things I test, because a kill switch that fails without notifying you is worse than none at all.
Your VPN may also use weak encryption protocols that allow ISPs, government agents, and hackers to decrypt your internet activity. I only recommend VPNs running WireGuard, OpenVPN, or an equivalent proprietary protocol, with the corresponding AES-256 or ChaCha20 encryption.
2. Alternative Means of Tracking
A VPN is one of the most important tools for safeguarding your online privacy and security, but it isn’t a catch-all solution.
There are plenty of other ways for ISPs, governments, advertisers, hackers, and tech companies to keep tabs on what you do online. A VPN usually makes that harder, but it rarely makes it impossible.
Your own browsing behavior is the easiest route of all. When you sign in to a personal account with Google or Facebook, you hand those companies permission to monitor your activity, and because you gave them personal information when you created the account, they can easily link everything you do straight back to you. No amount of encryption undoes that.
Other methods of tracking you online that work even when you’re using a VPN include:
Cookies and tracking scripts
Device fingerprinting, browser fingerprinting, and traffic fingerprinting
Spyware and stalkerware
Social media posts (including the metadata on images)
3. Your VPN Service Is Tracking You
Finally, as I’ve explained, a VPN service doesn’t guarantee your privacy on its own – it moves your trust from your ISP to your VPN provider. That makes the provider itself the point at which you’re most exposed.
For that reason, you should never use a VPN without researching it thoroughly first. My team and I have reviewed 59 VPN services to make your research a lot less work.
When No-Logs Policies Have Actually Been Tested
Every VPN claims it keeps no logs. The claim can’t be trusted until someone with a court order tries to extract information.
That has now happened enough times to separate the providers whose policies survived contact with law enforcement from the ones whose didn’t.
Windscribe – Greece, 2025. Greek authorities traced activity to a Windscribe server in Finland and, rather than approach the company, subpoenaed the data center. All it produced was billing information naming Windscribe’s CEO, who was then personally charged under Greek cybercrime law. The case was dismissed in April 2025, with the court accepting that the company could not produce data it had never collected.
Mullvad – Sweden, 2023. Six officers from Sweden’s National Operations Department arrived at Mullvad’s Gothenburg office in April 2023 with a search warrant, intending to seize customer data. After Mullvad demonstrated how the service works, the officers consulted the prosecutor and left with nothing.
ExpressVPN – Turkey, 2017. Investigators seized an ExpressVPN server in Turkey as part of the inquiry into the assassination of the Russian ambassador. The seized hardware yielded nothing usable. ExpressVPN subsequently stopped running physical servers in the country.
Private Internet Access – US, 2016 and 2018. Subpoenaed twice in separate federal cases. On both occasions the most it could produce was the rough region an IP cluster was assigned to.
On the point about trusting what a provider states –
PureVPN – 2017. PureVPN’s privacy policy stated it kept no logs capable of identifying a user. It then supplied the FBI with connection timestamps and IP addresses that identified a cyberstalking suspect precisely. It didn’t hand over browsing history — it didn’t need to. Connection metadata was enough.
IPVanish – 2016. Under previous ownership, IPVanish advertised a “strict zero-logs policy” and then produced logs on a specific user in response to a Homeland Security subpoena.
Two lessons come out of this.
The first is that connection logs are enough. Providers often draw a distinction between “activity logs” and “connection logs” and quietly retain the second. PureVPN is what that distinction looks like when it’s tested: timestamps and an IP address identified a user just as effectively as a browsing history would have.
The second is that a passed test is only a snapshot, not a warranty. It tells you what a provider held on one date, under one ownership, in one jurisdiction. Providers get acquired, policies get rewritten, and laws change. That’s why I value an independent audit and a published transparency report alongside these cases rather than instead of them – and why I go through VPN logging policies line by line in every review.
FAQs
Does a VPN Hide Your Browsing History from Network Admins?
Yes – and it hides more than you might assume, because a network administrator is in the same position as your ISP. HTTPS already stops them reading what you do on a website, but it leaves them the domain, the timing, and the volume. Using a VPN removes these from their purview.
A VPN hides your browsing from network administrators such as:
Employers
Parents
Landlords
School & College IT Technicians
Public Wi-Fi owners (e.g. Starbucks and airport staff)
Anyone with router-level access can see that your traffic is going to a VPN server, but they can’t see where it goes after that. If your VPN offers obfuscation, they won’t even see that much.
A VPN has the added benefit of getting you past any firewalls on the router, which may allow you to unblock websites on a workplace network.
One important caveat: a VPN is unlikely to hide your browsing activity when using a work or school computer. Administrators of managed devices can monitor your screen directly through remote access software, keylogging, or a screen monitoring program pre-installed on the machine. Encryption protects your traffic in transit; it can’t protect you from software watching the screen itself.
Does a VPN Hide Your Search History from Search Engines?
No. A VPN won’t hide your search history from Google or any other search engine, because you’re using their service to make those searches in the first place.
The real question is whether Google can link those searches back to you.
If you’re signed in to your Google account, it can. If you’re not, and are using a VPN, it becomes much harder for Google to link your search history back to you.
Even then, Google likely uses Chrome browser fingerprinting to connect searches to users. This involves using complex algorithms that use your device type, screen resolution, GPS location, behavioral patterns, and other signals to identify you.
Can the Police Track VPNs?
The police can’t decipher encrypted VPN traffic that uses secure encryption, such as the WireGuard protocol and ChaCha20 cipher.
They can, however, track the activity originating from a given VPN IP address. If you suffer from a leak or log into an identifying account while connected, that activity may be linked to you.
With a court order, the police can also approach your ISP and the VPN company itself for connection or activity logs.
Your ISP will be able to confirm you’ve been using a VPN service, and potentially identify which one, and if your VPN collects logs, it may be legally obliged to hand over what it holds.
That’s why I’m so insistent on logging policies: the very best VPN services don’t collect any personally-identifiable information, so there’s nothing meaningful to hand over.
Does a VPN Delete Your Browsing History?
No. Your browsing history is the list your browser keeps on your own device, and a VPN has nothing to do with it. Anyone who picks up your laptop or phone can read it, VPN or no VPN.
What a VPN hides is your browsing activity in transit – the record your ISP or network admin would otherwise build while you’re connected. To clear the list on your device you have to delete it yourself in your browser settings, or ensure you browse in a private window that discards it when you close.
Does Incognito Mode Hide Your IP Address?
No. Incognito and private browsing modes only stop your browser from saving history, cookies, and form data locally when you close the window. Your IP address is still fully visible to every website you visit, and your ISP still sees every domain you connect to.
The two tools solve different halves of the problem. Incognito hides your activity from other people using your device. A VPN hides it from everyone on the network between you and the site.
Does a VPN Hide You From Malware and Phishing?
No, and treating it as though it does is a genuine risk. A VPN encrypts the connection between your device and the VPN server. It doesn’t inspect what travels down that connection, so it won’t stop you downloading an infected file, entering your password on a convincing fake login page, or installing a malicious app.
Some VPNs bundle a blocklist-based filter that catches known malicious domains, and while those are useful, they’re not antivirus and shouldn’t be relied on as though they were. A VPN and real endpoint protection do separate jobs, and you need both.
Can Netflix and Other Sites Tell You're Using a VPN?
Often, yes. It’s worth being clear that a VPN hiding your location and a VPN going undetected are two different things.
Streaming services, banks, and retailers maintain blocklists of known VPN server IP addresses. When hundreds of accounts connect from a single address, the pattern is obvious. That’s what produces Netflix’s proxy error rather than the content you were expecting.
Your account itself gives you away too. Even with a perfectly clean IP address, the region you registered in and the country your payment method is issued in are both tied to your account and don’t change when your IP does. Obfuscation disguises VPN traffic from your ISP; it doesn’t stop a service recognizing one of its own blocked IPs.