How to Keep Your Web Activity Private With a VPN
A step-by-step guide to using a VPN for privacy: what it hides and what it doesn't, how to pick a provider, the settings to turn on, how to test for leaks, and what else to do.
A step-by-step guide to using a VPN for privacy: what it hides and what it doesn't, how to pick a provider, the settings to turn on, how to test for leaks, and what else to do.

A VPN hides your browsing from your internet provider and the local network, and it hides your real IP address from the sites you visit. It doesn't make you anonymous.
The VPN company can see the traffic your internet provider used to see, so choosing one you trust is the biggest decision you'll make.
Look for an independent no-logs audit, a WireGuard or OpenVPN connection, and a way to pay that doesn't tie the account to your name if that matters to you.
Turn on the kill switch and DNS leak protection, then test the connection for IP, DNS and WebRTC leaks before you rely on it.
Accounts, cookies and browser fingerprinting still identify you behind a VPN, so pair it with tracker blocking and a browser you keep logged out of.
A VPN (virtual private network) encrypts your traffic and sends it through a server the VPN company runs. Your internet provider, and whoever runs the Wi-Fi you're on, sees only that you're connected to a VPN. The websites you visit see the VPN server's IP address instead of yours.
That covers less than many people expect. The Electronic Frontier Foundation's Surveillance Self-Defense guide puts it plainly: a VPN isn't an anonymity tool. Here's what still gets through:
Accounts: when you're logged in to Google, a social network or an AI chatbot, the service knows it's you, whatever IP address you arrive from.
Cookies and tracking pixels: they follow your browser, not your IP address.
Browser fingerprinting: sites can recognize a browser from its settings, fonts and screen size.
The VPN company: it sits where your internet provider used to and can see the same traffic.
Legal requests: a provider can be ordered to hand over what it has, which is why what it stores matters.
A VPN is good at one job: keeping your browsing away from your internet provider and the local network, and keeping your home IP address away from the sites you visit.
Because the provider can see your traffic, its policies matter more than its speed or server count. Check these things before you pay:
An independent no-logs audit: a "no logs" claim on a homepage isn't proof. Look for an outside firm's audit report, and check how recent it is.
Jurisdiction: the country a provider is based in decides which laws and data demands apply to it.
Modern protocols: WireGuard or OpenVPN. Avoid PPTP, which is outdated and insecure.
Payment and sign-up: a card payment links the account to your name. Some providers let you sign up without an email and pay in cash or cryptocurrency.
A transparency report: some providers publish the legal requests they receive and what they could hand over.
Three providers that do well on these points:
Mullvad costs a flat €5 a month. You don't give an email address: the account is a random number, and you can pay with cash or Monero. It runs its VPN servers from memory only, with no hard drives, and its Android app and payment systems were audited again in 2026.
Proton VPN is based in Switzerland and has a free plan with no data cap, limited to one device. Its no-logs policy has been audited five years running, most recently in May 2026, and the audit covers its free servers too.
IVPN costs $6 a month or $60 a year, needs no email address, and takes cash and Monero. It had a no-logs audit in 2019 and now commissions an annual security audit of its apps and servers instead.
Running a VPN costs money, so a free one has to pay for itself somehow, and many do it with ads or by sharing user data. VPN apps in general have a patchy record: a 2016 study of 283 Android VPN apps by researchers at CSIRO, UNSW and ICSI found that 84% leaked IPv6 traffic, 66% leaked DNS queries and 18% didn't encrypt traffic at all. More recently, the Tech Transparency Project found in 2025 that one in five of the top 100 free VPNs in Apple's US App Store in 2024 were secretly owned by Chinese companies.
A free plan from a provider that sells paid plans and publishes audits, like Proton VPN's, is a different thing from an unknown free app. If you go free, go with one of those.
Download the provider's app from its own website or your device's official app store, not from a link in an ad or a search result you haven't checked. Then:
Set the protocol to WireGuard if the app lets you choose. It's fast and has a small, well-reviewed codebase. OpenVPN is the other good option.
Pick a server near you for speed, unless you have a reason to appear somewhere else.
Sign in with the account number or login the provider gave you, and don't reuse a password from anywhere else.
A VPN only protects traffic that goes through it. These settings stop traffic from slipping out around it:
Kill switch: blocks your internet connection if the VPN drops, so nothing goes out unprotected while it reconnects. Some apps call it "lockdown mode."
DNS leak protection: makes your device look up website addresses through the VPN instead of your internet provider. Without it, your provider can still see a list of the sites you visit.
IPv6 handling: if the VPN doesn't support IPv6, make sure the app blocks it, or IPv6 traffic can go around the tunnel.
Auto-connect: have the VPN connect on its own whenever you join a network you don't control, like hotel or café Wi-Fi.
On Android, you can also turn on Always-on VPN in Settings > Network & internet > VPN, through the gear icon next to your VPN. Be careful with split tunneling, which sends some apps outside the VPN. Every app you exclude is traffic your provider and network can see again.
Local networks can also be a weak spot. A 2024 attack known as TunnelVision showed that someone running a rogue DHCP server on the same network could route traffic around a VPN on Windows, macOS, Linux and iOS while the app still showed it as connected. A standard kill switch may not catch it, so the practical defense is to avoid networks you don't trust, or use your phone's hotspot instead.
Don't assume the settings worked. With the VPN connected, open a leak-test page in your browser:
ipleak.net shows the IP address, location and DNS servers sites can see, and runs a WebRTC check.
browserleaks.com/webrtc shows the IP address your browser exposes through WebRTC.
You should see the VPN server's IP address and location, and DNS servers that belong to the VPN, not your internet provider. If your real IP address appears anywhere, something is leaking.
WebRTC is the usual culprit. It's the browser feature behind video calls, and it can reveal your real IP address even with a VPN running. In Firefox, you can turn it off by setting media.peerconnection.enabled to false in about:config, which also breaks calls in the browser. In Chrome, Google's WebRTC Network Limiter extension restricts it.
To keep sites and advertisers from linking your activity together, change how you browse:
Block trackers with a browser that does it by default or a reputable extension.
Use a separate browser, or a separate browser profile, for anything you don't want tied to your main accounts, and don't log in to those accounts there.
Remember that private browsing windows only stop your own device from saving history. Google's help page for Incognito mode says your school, employer or internet provider may still see what you do.
Turn on HTTPS-only mode in your browser settings.
If anonymity matters more than speed, use Tor Browser instead. Tor sends your traffic through several volunteer-run relays so no single one sees both who you are and where you're going. It's much slower, some sites block it, and logging in to an account still identifies you.
A VPN changes the IP address an AI service records, but it doesn't make your chats anonymous. The prompts, uploaded files and conversation history are stored against your account, and that's what identifies you. If privacy matters for a particular conversation, check whether the service lets you turn off chat history or keep conversations out of model training, and don't paste in anything you wouldn't want stored.
Some AI services also restrict access from countries where they don't operate, and may block VPN connections that appear to come from those places. Using a VPN to get around those limits can break a service's terms.
In the US, the UK, Canada, Australia and most of Europe, yes. A few countries restrict or ban them, including China, where only government-approved VPNs are allowed, and Russia, which blocks unapproved services and, since September 2025, treats VPN use as an aggravating factor in criminal cases. In July 2026, the UK government said it wouldn't age-gate or ban VPNs, in its response to a consultation on children's online safety. What you do over a VPN is still subject to the same laws as anything else you do online.
No. It hides your IP address from sites and your browsing from your internet provider, but accounts, cookies and browser fingerprinting can still identify you, and the VPN company can see your traffic.
It can see that you're connected to a VPN server and how much data you use, but not which sites you visit, as long as DNS leak protection is working.
Many aren't. Researchers have found VPN apps that leak traffic or skip encryption, and free VPNs that hide who owns them. A free plan from an audited provider that also sells paid plans, like Proton VPN, is the safer way to go free.
For privacy from your internet provider and public Wi-Fi, yes, with the kill switch on. Turn it off only for services that block VPNs, and remember those sessions are back on your normal connection.
No. Incognito mode only stops your browser from saving history on your device. Your internet provider and the sites you visit can still see your activity.