A VPN Won’t Save You. Here’s What It Will Do.

Advertisements

The VPN industry is worth over $45 billion and growing. Most of that money is built on a single belief: that turning on a VPN makes you private online. That belief is mostly wrong — not because VPNs don’t work, but because people are using them to solve problems they don’t actually solve.

If you use a VPN, you should know exactly what it’s protecting. Because what it’s not protecting is where most of the real risk lives.

"person walking through encrypted VPN tunnel while surveillance cameras track them at the exit"

What a VPN Actually Does

Advertisements

A VPN does one thing well: it creates an encrypted tunnel between your device and a VPN server. Everything you send goes through that tunnel before reaching the open internet.

This means three things in practice.

Your ISP can’t see which sites you visit. Without a VPN, your internet provider sees every domain you connect to. With a VPN, they see encrypted traffic going to one server. They know you’re using a VPN but not what you’re doing.

Your IP address is hidden from websites. The sites you visit see the VPN server’s IP address, not yours. This is what lets you access content from other regions and is why streaming services have always had a complicated relationship with VPN users.

Your traffic is protected on public networks. On a coffee shop or airport WiFi, someone on the same network could potentially intercept unencrypted traffic. A VPN prevents this.

That’s a real and useful set of protections. The problem isn’t that VPNs fail at these things — it’s that most people think they do much more.

The 5 Things a VPN Can’t Do

"split diagram showing what VPN protects versus what bypasses VPN protection"

1. Hide you from Google, Amazon, or Facebook

If you’re signed into your Google account, Google knows it’s you — regardless of your IP address or whether you’re running a VPN. Account-based tracking doesn’t use your IP. It uses your session cookies and authentication tokens. A VPN tunnels your traffic but doesn’t touch the layer where this tracking happens.

2. Stop cookie-based tracking

Most of the advertising surveillance you encounter online works through cookies stored in your browser. When you visit a site and click “Accept All,” those cookies follow you across the web. Your IP changing doesn’t matter. The cookies travel with your browser.

3. Protect you from malware or phishing

A VPN routes your traffic — it doesn’t inspect it. If you click a phishing link or download malicious software, the VPN doesn’t intervene. Some VPNs offer optional threat protection features as add-ons, but that’s a separate layer from the core VPN function.

4. Hide your activity from your VPN provider

This is the part the marketing never emphasizes. When you use a VPN, you shift your trust from your ISP to your VPN provider. Your VPN provider can technically see all the traffic passing through their servers. “No-log” policies matter here — but more on that below.

5. Protect you from browser fingerprinting

Your browser has a unique fingerprint based on its combination of version, installed fonts, screen resolution, timezone, and dozens of other signals. This fingerprint identifies you across websites without any cookies or login. VPN doesn’t touch this. A site that uses fingerprinting sees the same fingerprint whether your IP is your home address or a server in Amsterdam.

When a VPN Actually Helps

Given all that, when does a VPN earn its monthly fee?

Public WiFi is the clearest use case. Airport networks, hotel WiFi, coffee shop hotspots — these are shared networks where poorly secured traffic could be intercepted. While HTTPS has dramatically reduced this risk for most browsing, a VPN adds a complete protection layer at the network level. If you travel frequently or work in public spaces, this alone justifies using one.

ISP surveillance is a real concern in the US. Since Congress rolled back the FCC’s broadband privacy rules in 2017, US internet providers can legally collect and sell subscribers’ browsing data. A 2023 FTC report on ISP data practices confirmed that major providers collect and monetize detailed browsing histories. If you’re concerned about this, a VPN is the direct solution.

Geo-restrictions are the third legitimate use. Accessing content not available in your region — a legitimate use that streaming services and content platforms have increasingly tried to block, with mixed results.

No-Log Policies: What to Actually Look For

The phrase “no-log VPN” appears in almost every VPN marketing pitch. What matters is whether that claim has been independently verified.

ProviderIndependent AuditWarrant CanaryNotable
Mullvad✅ Cure53 (annual)Accepts cash, no account email required
ProtonVPN✅ SEC ConsultSwiss jurisdiction, open source
ExpressVPN✅ KPMGOwned by Kape Technologies since 2021
NordVPN✅ DeloittePanama jurisdiction
Surfshark✅ DeloitteOwned by Nord Security

The audit column is the only one that matters. A policy is a document — an audit is independent verification. Mullvad and ProtonVPN are consistently regarded as the most privacy-focused options, with Mullvad’s anonymous account model (no email required, accepts cash) being the most thorough implementation.

What I Actually Found

Here’s what most VPN guides won’t tell you because it complicates the sale: for most people’s actual threat model, a VPN is solving a problem that isn’t their biggest risk.

The realistic privacy threats for an average person in 2026 are account-based tracking, data broker profiles, credential theft, and device-level surveillance. A VPN addresses almost none of these. If you’re logged into Google on Chrome, using Gmail, and shopping on Amazon — you are comprehensively tracked by three of the most sophisticated advertising systems ever built, and your VPN is doing nothing about it.

I’ve tested multiple VPN setups alongside browser privacy tools, and the single highest-impact combination for practical privacy isn’t “VPN + regular browser.” It’s a properly configured Firefox with uBlock Origin plus network-level DNS filtering (like NextDNS or Pi-hole) — no VPN required for most browsing.

That said, for the specific threats VPNs do address — public network exposure and ISP data collection — they work exactly as advertised. If you’re on public WiFi regularly, get one. If you’re not, understand that you might be paying $10 a month to feel more protected than you actually are.

The bigger picture: VPN is one tool in a larger privacy setup. Switching your primary accounts to passkeys instead of passwords eliminates the credential attack vector that causes most actual account compromises. Auditing what your home devices are collecting addresses the passive data collection that most people never think about. A VPN fits into that picture — but it doesn’t replace it.

Do You Actually Need One?

Ask yourself two questions.

Do you regularly use public WiFi — airports, hotels, coffee shops? If yes, a VPN is worth having.

Are you concerned about your ISP monitoring and selling your browsing data? If yes, a VPN directly addresses this.

If your answer to both is no, your privacy budget is better spent on a good password manager, enabling passkeys where available, and reviewing the app permissions on your phone. Those changes address the threats that are most likely to actually affect you.

If you do want a VPN: Mullvad ($5/month, no account required) or ProtonVPN (free tier available, independently audited) are the options with the strongest verified no-log track records. Start with ProtonVPN’s free tier to test if you actually use it before committing to a subscription.

Your ISP doesn’t know what you’re reading right now if you’re on a VPN. Google does, because you were already logged in before you got here. That gap is where most people’s privacy attention should actually be focused.

Does a VPN make you completely anonymous online?

No. A VPN hides your IP address and encrypts your traffic in transit, but it doesn’t prevent tracking through cookies, browser fingerprinting, or account-based tracking. If you’re signed into Google, Amazon, or any account while using a VPN, those services can still identify you. Anonymity online requires a much more comprehensive setup than a VPN alone.

Can my ISP see what I’m doing if I use a VPN?

Your ISP can see that you’re using a VPN and how much data you’re transferring, but they cannot see which websites you visit or what you’re doing. They see encrypted traffic going to one server — the VPN server. However, the VPN provider can see your traffic, which is why choosing a provider with independently audited no-log policies matters.

Is a free VPN safe to use?

Most free VPNs monetize by collecting and selling user data — which is the opposite of what you want from a privacy tool. The main exceptions are ProtonVPN’s free tier, which is funded by their paid subscribers and uses the same no-log infrastructure, and Windscribe’s limited free plan. Avoid any free VPN that doesn’t have transparent funding and a verified no-log audit.

Does a VPN protect me from hackers?

A VPN protects against a specific type of attack — network-level eavesdropping on shared WiFi. It does not protect against phishing, malware, data breaches at websites you use, or credential theft. For most hacking scenarios that affect real people, switching to stronger authentication like passkeys provides more meaningful protection than a VPN.

Which VPN actually has a verified no-log policy?

Mullvad and ProtonVPN have the most consistently verified no-log policies through independent third-party audits. Mullvad is particularly notable for requiring no email address to create an account — you can pay with cash and remain completely anonymous even from the VPN provider. NordVPN and ExpressVPN have also completed independent audits but are owned by larger corporate entities.

About the author

Lucas

Lucas writes about privacy, security, AI, and the everyday tech problems people actually run into. He self-hosts his own servers, builds automation for his own crypto and trading workflows, and uses AI tools daily for real work — not demos. Most of what's here he figured out by testing it himself, then wrote down what actually worked.

More from Lucas →

Comment form introduction