Privacy & Security

What a VPN Actually Does — and What It Doesn't Protect You From

VPNs are marketed as comprehensive privacy shields. The actual protection is more specific — and understanding where it ends matters for anyone who relies on one as a primary privacy tool.

✍ By ⏱ 10 min read
In This Guide
  1. What a VPN Actually Is
  2. How It Works Technically
  3. What a VPN Does Protect
  4. What a VPN Does NOT Protect
  5. The Trust Transfer Problem
  6. When a VPN Is Genuinely Useful
  7. What "No Logs" Actually Means
  8. What to Look For in a VPN

What a VPN Actually Is

A VPN — Virtual Private Network — is a tool that creates an encrypted tunnel between your device and a server operated by the VPN provider. All your internet traffic flows through that tunnel, which does two things: it encrypts the traffic so that anyone between you and the VPN server can't read it, and it makes your traffic appear to originate from the VPN server's location rather than your actual location.

That's the complete core function. Everything a VPN does — and everything it doesn't — flows from those two mechanics. Source: Cybersecurity and Infrastructure Security Agency.

📡 Definition: VPN Tunnel

When you connect to a VPN, your device establishes an encrypted connection to the VPN provider's server. Your internet requests travel through this encrypted "tunnel" to the VPN server, which then forwards them to the destination website or service. The destination sees the VPN server's IP address, not yours. Your ISP sees encrypted traffic going to the VPN server, but cannot see what specific sites you're visiting or what data you're sending.

How It Works Technically

Without a VPN, your internet traffic flows from your device to your ISP, which routes it to the destination. Your ISP can see which sites you visit, when, and how much data is involved. The destination site sees your real IP address. Anyone on the same network (on public Wi-Fi, for example) may be able to intercept unencrypted traffic.

With a VPN: your device encrypts all traffic before it leaves. Your ISP sees only encrypted data going to the VPN server — they can't see the destinations. The destination site sees the VPN server's IP address. The VPN provider, however, can now see everything your ISP used to see — which is the core trust transfer problem discussed below.

What a VPN Does Protect

VPN Protection: What It Covers
What it protectsProtected?
Your ISP seeing which sites you visitYes
Your ISP seeing content of your trafficYes
Others on public Wi-Fi intercepting your trafficYes
Websites seeing your real IP addressYes
Your geographic location (approximate)Yes — replaced with VPN server location
Network-level surveillance by ISP or network adminYes

What a VPN Does NOT Protect

VPN Gaps: What It Doesn't Cover
What it doesn't protectProtected?
Websites tracking you via cookies or browser fingerprintNo
Google/Facebook seeing your activity on their platformsNo — you're logged in
Malware or viruses on your deviceNo
Phishing attacksNo
Your activity on sites where you're logged inNo — your account identifies you
DNS leaks (if VPN is misconfigured)Only with proper DNS leak protection
What the VPN provider itself seesNo — you must trust them instead of your ISP
Legal requests to the VPN provider for your recordsDepends entirely on provider's logs and jurisdiction

The Trust Transfer Problem

This is the most important limitation to understand. A VPN doesn't make your traffic private — it transfers who can see your traffic from your ISP to your VPN provider. You're replacing one party's visibility with another's.

Your ISP is a regulated entity in a known jurisdiction with legal obligations. Your VPN provider may be based anywhere, may have any data retention policy, and may respond to legal requests in ways you can't verify. When you use a VPN, you are making a bet that your VPN provider is more trustworthy than your ISP. That may or may not be a good bet, depending on the specific provider.

⚠️ Many Free VPNs Monetize Your Traffic Data

Free VPN services have to make money somehow. Many do so by logging and selling user data — the exact activity a privacy-conscious user is trying to protect. Some free VPNs have been caught selling browsing data to advertisers, injecting tracking scripts into web traffic, or operating as data collection tools under a privacy mask. Free VPNs should be approached with significant skepticism by anyone using a VPN for actual privacy. Source: FTC.

When a VPN Is Genuinely Useful

A VPN is the right tool for specific, well-defined situations:

💡 HTTPS Already Encrypts Most of What You Care About

Most modern websites use HTTPS, which encrypts the content of your communications with that site regardless of whether you're on a VPN. Without a VPN on your home network, your ISP can see that you visited a particular domain — but not the specific pages or content. A VPN hides even the domain. For most people's threat models, the incremental privacy benefit of a VPN on a trusted home network is modest. The value is much clearer on untrusted public networks.

What "No Logs" Actually Means

"No logs" is a marketing claim made by virtually every VPN provider. In practice, "no logs" can mean many different things:

The only "no logs" claims worth crediting are those backed by independent technical audits from credible security firms — not marketing copy. Source: CISA VPN Security Guidance.

What to Look For in a VPN

🎯 Bottom Line

A VPN is a specific tool for a specific problem: hiding your traffic from your ISP and others on your local network. It does not make you anonymous online, does not protect you from tracking by sites you're logged into, does not block malware, and does not prevent phishing. It transfers trust from your ISP to your VPN provider — which is only useful if your VPN provider is actually more trustworthy. Used correctly, for the right use cases, a VPN is a genuinely useful privacy tool. Treated as a comprehensive privacy solution, it creates false confidence. Source: Cybersecurity and Infrastructure Security Agency.