What Turning On a VPN Today Does Not Undo

A VPN has no retroactive effect whatsoever. It changes what certain observers can see from the second it connects, and it changes nothing about what they already saw, already stored, or already inferred. This sounds obvious written down, and it is nonetheless the single most common mismatch between what people buy a VPN for and what a VPN does — because privacy marketing describes a state (“you are private”) rather than a start time, and states feel like they apply to the whole picture.

Working out what is already fixed is a useful exercise on its own, because for a lot of people the honest answer is that the thing they were worried about happened before they installed anything.

What already exists and stays existing

Your ISP’s existing records. Whatever your provider retained about destinations you requested before today remains retained on whatever schedule it uses. The tunnel is a change to the current connection, not an edit to a database.

Accounts you already hold. Every service you have logged into knows who you are and has a history attached to your name. Arriving through a different network address does not make you a new person to a service that has your email address — which is the whole argument in does a VPN make you anonymous.

Advertising and analytics profiles already built. These are keyed off identifiers that live in your browser and your logins, not off your address. A profile assembled over years does not reset because one weak signal in it changed today, as why a VPN does almost nothing about ad tracking sets out.

Anything published or shared. Posts, photos, listings, reviews, profiles, public records, and anything that has been scraped and mirrored. This category is not a network problem and never was.

Credentials already exposed. If a password of yours is circulating from some old breach, the exposure is a fact about a stored copy. Rotating it helps; a tunnel does not touch it.

Device and account identifiers. Hardware, operating system, browser configuration and installed fonts do not change when a route does.

The subtler one: continuity across the switch

The retroactivity people miss is not historical, it is immediate.

If you are logged into a service, keep the session open, and switch the VPN on mid-session, that service watches one continuous session change its source address at a known timestamp. From its perspective it has just learned a fact it did not have before: that this account uses this VPN address, and did so starting at this moment, from a session that began at a different address. You have connected the two addresses in the only log where the connection matters.

The same thing happens in reverse when the tunnel drops or you disconnect — which is a large part of why leaks and kill switches get so much attention. A kill switch does not prevent the linkage from being learned; it prevents it from being learned by accident, repeatedly, without you noticing.

Three consequences follow.

Switching on partway through does the least good. The session that mattered already carried the address it started with.

Switching on and off frequently is worse than either state. Each transition is another correlated pair of addresses at a timestamp, and the set of accounts active at each transition narrows the picture further.

A stable habit is more coherent than an occasional one. Always on for a particular device, or off for a particular device, produces a less informative pattern than a tunnel that appears when you feel exposed — because when you feel exposed is itself a signal about what you were doing.

What it does change, starting now

From the moment it connects: the network you are on stops seeing which destinations you request, and your ISP stops seeing them too. Both facts apply to traffic from now onward and to nothing else. In exchange, a new party begins accumulating the record instead, which is the trade described in what your VPN provider can see.

That is the entire scope of the change. It is a genuine improvement against a network operator and an ISP, on a forward-looking basis, and it is not a remedy for anything historical.

If the past is the actual problem

Then the tools are different ones, and none of them is a subscription.

Something specific is already public. Removal and deletion requests to the party holding it, where the law where you live provides for them. Slow, inconsistent, sometimes effective.

An account is the exposure. Close it, or reduce what it holds. A closed account is not an erased one, and what survives varies — the same question as what a provider still holds after you cancel, asked of every other service you use.

Credentials are the exposure. Rotate them, add a second factor, use a manager. This is the highest-value hour of security work available to almost anyone, and it is unrelated to networking.

Someone with access to your device is the exposure. Then the boundary is inside the device and the tunnel is on the wrong side of it — see threats a VPN can never see.

Someone has already obtained information that puts you at risk of harm. Stop treating this as a shopping question. Organisations that support people facing harassment, domestic abuse, or state attention have specific procedures for exactly this situation, and a commercial VPN is not among them.

The framing worth keeping

A VPN is a forward-looking measure with a narrow scope, purchased by people who often want a backward-looking remedy with a broad one. Nothing about the product is dishonest in that gap; the mismatch is created by describing a route change as a condition of privacy.

So when you install one, set the expectation deliberately: the clock starts now. Then go back to the four questions in build a threat model before you buy anything and ask whether the thing you are actually worried about is in the future at all. If it is already in the past, you need a different kind of work — and knowing that is worth more than any configuration change.