A VPN is often marketed as an invisibility switch, which creates the wrong expectations. A more accurate model is that it changes what certain network observers can see and shifts trust away from the local access network toward the VPN service and destination sites. It does not erase every identifier left by accounts, browsers and devices.

What a VPN normally protects

After connection, traffic between the device and VPN server is encrypted. A local hotspot or access ISP has less visibility into the content, and destination sites normally see the server's public IP rather than the access IP. This is useful on untrusted networks and for reducing coarse IP-based location exposure.

  • Reduce local-network observation
  • Hide the access network's public IP from destinations
  • Reduce ISP visibility into page contents
  • Create a consistent encrypted path on untrusted networks

Identifiers a VPN does not automatically hide

A service still knows the signed-in account. Cookies, advertising IDs, payment records and submitted personal data can link sessions. Browser fingerprinting may combine display size, fonts, language, time zone and behavior even after the IP changes.

It is not antivirus or anti-phishing software

A VPN does not decide whether an attachment is malicious, a login page is fake or an unpatched app is vulnerable. Downloading unknown software, ignoring certificate warnings or giving a phishing page an MFA code can still compromise the account and device.

Interpret no-logs, DNS and leak protection carefully

A no-logs statement should be read alongside the privacy policy, technical design and operating practice. DNS routing, behavior during tunnel failure and diagnostic data collection all affect real privacy. Review the policy and enable relevant client safeguards.

Build a realistic privacy stack

Combine a VPN with MFA, a password manager, updates, browser privacy controls and careful permissions. People with stronger anonymity needs must also separate browser identities and avoid signing into identifying accounts.

  • VPN: protects the path and changes the exit IP
  • HTTPS: protects content exchanged with a site
  • MFA and password manager: protect accounts
  • Updates and security tools: protect the endpoint
  • Permission and tracking controls: reduce app and browser exposure

Define the threat before choosing the tool

A VPN helps with local-network observation, access-IP exposure and untrusted networks. Phishing, malware and account theft require different controls.

Privacy policy · Product features · FAQ

Video reference

This guide draws on a public expert video about VPN privacy boundaries and reorganizes the topic as a practical threat model: What Does a VPN Actually Hide — and What Isn't Hidden.