What Your VPN Provider Can See That Your ISP Cannot

Turning on a VPN transfers a specific bundle of visibility from your internet provider to your VPN provider: the destinations you connect to, the names you look up, and the timing and volume of it all — now paired with your real network address on the other side. Nothing is deleted. It changes hands. Deciding whether a VPN improves your privacy is therefore a question about which of those two parties you would rather have that bundle.

This post lays out both sides of the swap explicitly, because most VPN marketing describes only the half that flatters it.

What your ISP sees without a VPN

Your identity, definitively. You have an account, a billing address, and usually a piece of their hardware in your home. There is no ambiguity about who you are.

Every destination you connect to. Addresses are visible by necessity, and usually resolvable to an organisation.

Your DNS lookups, if you use their resolver and have not enabled encrypted DNS. This is the cleanest possible log of the hostnames you visited.

Timing and volume, continuously, and typically the fact that you were online at all.

Not your content, because transport encryption handles that, as the HTTPS relationship explains.

What they may do with it varies enormously by jurisdiction: mandated retention periods, lawful access processes, commercial use of aggregated browsing data where permitted, and traffic management based on destination.

What your VPN provider sees when you connect

Your real network address, because the tunnel has to be built from somewhere.

Every destination you connect to, because forwarding traffic on your behalf is the entire service.

Your DNS lookups, since the client normally directs them through the tunnel to the provider’s resolver — that being one of the things a VPN is supposed to fix.

Timing, volume, and session duration, in the same detail as your ISP had.

Your account identity, which for a paid service usually includes an email address and a payment record. For a free service, funding has to come from somewhere, which is a question the sibling site imfreevpn.net exists to answer.

Not your content, again — HTTPS still protects it end to end, right through the provider’s server.

Read those two lists next to each other and the structure is plain: the categories are nearly identical. What differs is who holds them, under what law, under what commercial incentives, and with what retention.

The one thing the VPN provider has that the ISP does not

It sits at the join. Your ISP knows who you are and sees an encrypted stream to one address. A destination site sees a connection from a datacentre address with no idea who you are. The VPN provider is the only party holding both halves at once: this person, this destination, this moment.

That is a stronger position than either of the parties it replaced. It is also unavoidable — a service that forwards your traffic must know both ends, which is why what data a VPN must hold treats it as a structural fact rather than a scandal. But it means the phrase “we don’t log” carries more weight here than in almost any other consumer service, and deserves the scrutiny in what a no-logs claim is worth.

What each party can be compelled to produce

Neither is outside the law, and this is where the differences are real rather than rhetorical.

Your ISP operates in your own jurisdiction, is often subject to explicit retention requirements, and has a well-established process for handling requests. The data will generally exist because the law says it must.

Your VPN provider operates under the law where it is incorporated, and its servers additionally sit under the law wherever they are located. The relevant question is not what the marketing says about privacy-friendly jurisdictions but what data exists to hand over. A provider genuinely holding nothing relevant has nothing to produce, whatever the jurisdiction. A provider holding connection records has them wherever it is registered.

Both may be barred from telling you about a specific demand, which is why warrant canaries and transparency reports became a thing and why their limits matter.

Who you should prefer, honestly

There is no universal answer, but the inputs are clear.

Prefer the VPN provider when: you are on a network you do not control, your ISP operates in a market where browsing data is commercially exploited or broadly retained, you have a specific concern about destination-based throttling, or the network operator has a personal interest in your affairs.

Prefer your ISP when: you are on your own connection, your ISP is a regulated utility with clear obligations and no particular incentive to look, and the VPN provider is a company you know nothing about beyond its own advertising. A regulated telecommunications provider under audited retention rules is not obviously a worse custodian than an unaudited startup whose entire marketing budget goes on telling you it keeps no records.

Neither, when your risk is serious. If your adversary is a state, this swap does not help you enough to matter, and treating it as protection is dangerous. See why a commercial VPN isn’t enough against a state adversary.

The question to keep asking

Every VPN claim can be tested against one sentence: does this reduce the data that exists, or does it move who holds it?

Almost everything in the category does the second. The features that genuinely do the first — architectures that limit what persists, resolvers that see less, policies that specify short retention with detail — are the ones worth paying attention to, and they are rarely the ones in the advertisement. Start with what a VPN actually protects against for the full scope, then judge providers on their answers to this question rather than on their server counts.