What a VPN Actually Does
A VPN creates an encrypted tunnel between your device and a server operated by the VPN provider. All your internet traffic passes through that tunnel before reaching the open internet, which accomplishes two concrete things: it prevents your ISP from reading your browsing activity, and it makes websites see the VPN server's IP address instead of yours.
Those are genuine, meaningful protections — especially on untrusted networks. As we explain in our look at public Wi-Fi risks, encrypting your connection on an open café or airport network limits what a potential eavesdropper can intercept. That's a real benefit, not marketing fiction.
But VPN marketing often stops there, leaving consumers with an inflated picture of what the technology delivers. The myths below address the gaps.
Myth
A VPN makes me completely anonymous online.
Fact
A VPN hides your IP address but does not prevent websites, advertisers, or platforms from identifying you through account logins, browser fingerprinting, or cookies.
Anonymity requires that no party can link your actions back to you. A VPN removes your IP address from that equation, but the moment you log into Google, Facebook, or any other account, that platform knows exactly who you are — IP or not. Browser fingerprinting, which identifies your device by its unique combination of settings, fonts, and plugins, works independently of your IP address entirely. A VPN is a pseudonymity tool at best, not an anonymity guarantee.
Myth
A VPN protects me from hackers and malware.
Fact
VPNs encrypt traffic in transit but offer no protection against malware you download, phishing links you click, or software vulnerabilities on your device.
Encryption shields data moving between your device and the VPN server from interception. It does nothing to scan files, block malicious downloads, or stop a phishing page from stealing your credentials. Those threats require separate tools — up-to-date operating systems, reputable security software, and careful clicking habits. Conflating network-layer encryption with endpoint security is a common and costly misunderstanding.
Myth
My VPN provider can't see what I'm doing.
Fact
Your VPN provider can see all the traffic you route through its servers; you are essentially shifting trust from your ISP to the VPN company.
When you use a VPN, your ISP sees only that you're connected to a VPN server — it can't read your traffic. That's genuinely useful. However, the VPN server itself receives and forwards all your unencrypted requests (for sites not using HTTPS) and knows your real IP address. A provider with a verified, independently audited no-logs policy reduces this risk, but the trust relationship doesn't disappear — it moves. Researching a provider's logging practices, jurisdiction, and audit history matters.
Myth
A VPN stops websites from tracking me.
Fact
Most modern web tracking relies on cookies, login sessions, and device fingerprinting — none of which a VPN blocks.
Ad networks and analytics platforms have largely moved beyond IP-based tracking because IPs are imprecise and change frequently. Tracking today is driven by persistent cookies, cross-site identifiers, and behavioral profiles tied to your accounts. A VPN does not clear cookies, block trackers, or log you out of services. Browser privacy settings, tracker-blocking extensions, and selective use of private browsing sessions address tracking more directly than a VPN does.
Myth
Using a VPN is always legal and risk-free.
Fact
VPN legality varies by country, and using one does not shield you from the legal consequences of illegal activity in your jurisdiction.
In the United States, using a VPN is legal for everyday consumers. In several other countries, VPN use is restricted or banned outright. More importantly, a VPN does not provide legal immunity — law enforcement can subpoena VPN providers, and providers subject to court orders may be compelled to produce records. The technology changes what third parties can observe passively; it does not change applicable law or eliminate accountability.
Where VPNs Fall Short — and What to Do Instead
Understanding a VPN's limits helps you build a realistic privacy strategy. A VPN is one layer, not the whole wall. For a fuller picture of how encryption works at the website level, see our guide on HTTPS and what the padlock in your browser actually means.
Free VPNs Carry Unique Risks
Free VPN services must generate revenue somehow. Several have been documented collecting and selling user data, injecting ads, or providing weak encryption. If you choose to use a VPN, understanding how the provider's business model works — and who funds it — is a necessary step before routing your private traffic through it.
The most durable privacy habits involve multiple practices working together: using a reputable VPN on public networks, keeping software updated, reviewing app permissions, and being deliberate about the accounts and services you log into. No single tool covers all the ground, and several widely-held privacy myths — including beliefs about VPNs — give people a false sense of security that leaves real gaps unaddressed.
This article is for general informational purposes. Technology capabilities and provider policies can change; verify specifics with your chosen service's current documentation.




