Does a VPN hide what you do online from everyone?
Summary
No. A VPN hides your traffic from your internet provider and from whoever runs the Wi-Fi you're on, but everything it hides from them becomes visible to the VPN company instead. So a VPN doesn't remove the watcher so much as swap one for another, and the value of a "no logs" promise depends on whether anyone outside the company has checked it.
Your ISP loses the view, and the VPN provider gets it
The Electronic Frontier Foundation's guide describes a VPN as an encrypted tunnel between your devices and the VPN server that carries all of your web traffic. That keeps it away from your ISP and from the local network owner, such as a coffee shop or hotel.
The same guide puts the catch in bold: the browsing data you've hidden from your ISP is "all visible to the VPN provider." If you use a commercial VPN, the people who run it see your traffic.
EFF is also blunt that a VPN is "not a tool for anonymity." VPN providers receive law enforcement requests like anyone else, and EFF says many of them store as much information as ISPs do.
Where HTTPS already covers you
Sites that load over HTTPS are protected whether or not a VPN is running. According to MDN, the TLS layer behind HTTPS encrypts data in transit so it can't be read, and stops an attacker from changing it undetected.
What HTTPS leaves exposed is the metadata: which sites you connect to and when. EFF notes that a VPN can shield that metadata from someone listening on your local network, but the VPN provider still sees all of it.
"No logs" is a claim until someone checks it
EFF's advice here is short: a claim is not a guarantee. A VPN company might log your data if its privacy policy doesn't specifically rule it out, and even a company that says it doesn't log connection data isn't guaranteed to behave well.
Some providers pay outside firms to look:
- Proton VPN has had its no-logs policy audited by Securitum for five years running, most recently in 2026.
- NordVPN says Deloitte Lithuania carried out its sixth no-logs assurance engagement between November 10 and December 12, 2025. NordVPN doesn't publish excerpts from the report, citing its technical nature.
- Mullvad's most recent infrastructure audit, its fourth, was done by Cure53 in June 2024.
EFF adds a caveat of its own: there's no certainty that practices don't change after an audit, especially under government pressure. EFF also states that it can't vouch for any VPN or any VPN rating.
Sources
- https://ssd.eff.org/module/choosing-vpn-thats-right-you
- https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Transport_Layer_Security
- https://protonvpn.com/blog/no-logs-audit
- https://nordvpn.com/blog/nordvpn-no-logs-assurance-engagement-2025/
- https://mullvad.net/en/blog/tag/audits
Related on this site
- What does "My IP" show once you're connected to a VPN?
- What does a VPN kill switch actually stop when the connection drops?
- Is a free VPN really free, or is there a catch?
- How do you choose a VPN for personal use?
- What's the difference between a VPN protocol, a cipher, and post-quantum encryption?
- Business VPN pricing: what teams actually pay per user
Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.