Why a VPN Does Almost Nothing About Ad Tracking
Commercial tracking works at the application layer, and a VPN operates below it. Cookies, embedded scripts, advertising identifiers, and browser fingerprints all continue to function exactly as before when you switch a tunnel on. Hiding your IP address removes one weak signal from a system that has many strong ones.
This is the single most common misunderstanding about what these products do, and it is worth being precise about why, because the reason also tells you which tools do help.
How tracking actually identifies you
An advertising or analytics network needs to recognise the same person across pages, sites, and sessions. It has several ways to do that, and IP address is the least of them.
Cookies and equivalent storage. A tracker embedded on many sites sets an identifier in your browser and reads it back on every site that includes the same tracker. The identifier is stable, unique, and travels with your browser regardless of which network you are on. Third-party cookies have been constrained by browsers in recent years, but first-party storage, local storage, and server-set identifiers do similar work.
Your own logins. The moment you sign into a large platform, everything that platform’s scripts observe elsewhere on the web can be attached to your actual account. No inference required.
Browser fingerprinting. Your screen dimensions, timezone, installed fonts, language settings, graphics rendering quirks, and dozens of similar properties combine into a value that is often close to unique. It requires no storage at all, which is precisely why it grew in importance as cookies got harder.
Mobile advertising identifiers. On phones, apps often use a platform-provided advertising ID. That is a deliberate cross-app identifier handed out by the operating system. A VPN does not touch it.
Email addresses and hashed identifiers. Increasingly, tracking is keyed to a hashed version of something you typed in yourself at checkout or signup.
Notice what all of these have in common: none of them need your IP address, and all of them survive a VPN connection unchanged.
What the IP address contributed in the first place
It was never useless, just weak.
As an identifier, an IP address is unreliable. Residential addresses change, are shared across a household, and are shared far more widely on mobile networks. Tracking systems treat it as a supporting signal, not a primary key.
As location data, it is genuinely informative — roughly which city or region you are in. That is the part a VPN does change, and it changes it into “wherever the VPN server is”, which is itself a signal.
As a linking hint, it helps connect devices in the same home, or connect an anonymous session to a known one seen from the same address minutes earlier.
So a VPN degrades a moderately useful geographic signal and a weak linking signal. It leaves the strong identifiers untouched.
The ways it can make things slightly worse
Not much worse, but worth knowing.
Shared exit addresses look unusual. Traffic from a datacentre address used by thousands of people is a distinctive property, and it is one more thing a fingerprint can incorporate. It does not identify you, but it does not blend in either.
Location signals become inconsistent. A browser reporting one timezone while its network address suggests a different continent is a mismatch that some systems record.
More friction, not more privacy. Additional login challenges and blocked sign-ins are a common experience on shared addresses, which pushes people into verifying more about themselves rather than less. Why sites react this way is covered in VPN detection.
What does reduce tracking
The honest answer is that the tools which work are boring and unrelated to VPNs.
A browser that blocks third-party tracking by default, or a content blocker that removes tracker scripts before they run. Blocking the script is the difference in kind — an identifier that is never set cannot be read.
Separating identities. Different browsers or browser profiles for different purposes, so a signed-in session on one service cannot be joined to unrelated browsing. Container features formalise this.
Being sparing with logins. Not signing into a platform you do not need to be signed into is more effective than any network-layer measure.
Resetting or disabling the mobile advertising identifier, which the operating system exposes as a setting on both major platforms.
Reducing fingerprint surface — fewer extensions, default window sizes, browsers that actively normalise the properties scripts can read. Note the paradox here: aggressive customisation aimed at privacy often makes you more distinctive, not less.
Declining tracking where you are offered the choice, and taking the regulatory opt-outs seriously where they exist. Unglamorous, but they operate on the actual mechanism.
How to think about it
The general rule is that a defence has to sit between you and the thing you are defending against. A VPN sits between you and your network provider. Trackers are not there — they are inside the pages you load and the apps you run, on the far side of the tunnel, invited in by the site itself.
That does not make a VPN worthless. It makes it a tool with a specific job: changing who can observe your traffic in transit, as what a VPN protects against sets out. Buying one to escape advertising is buying a lock for a door the advertisers were never using.
If tracking is your actual concern, spend the effort on your browser and your account habits first. Then, if you still want a VPN for the network-level reasons, choose it on the merits of what its privacy policy says rather than on a claim it cannot deliver.