You have probably been told, several times, that you need a VPN. Perhaps by a video sponsor reading ad copy about hackers in coffee shops. Perhaps by a “best VPNs of the year” article that seemed helpful until you noticed every button on it was a tracking link.
So it is worth saying plainly, at the top: this site does not sell VPNs. We are not paid to recommend one. We will not link to one, anywhere in this article, and we will not name a single provider. There is no affiliate code buried in a link below. We have nothing to gain from your answer being yes.
Hold that against the other pages you have read on this question. Almost every one either sells VPN subscriptions or earns a commission per signup. That does not automatically make them wrong, but it does mean they all arrive at the same conclusion, and it is worth knowing why.
Our answer, for most people most of the time, is no — and more importantly, the specific reasons usually given for yes are largely out of date. Here is what a VPN actually does, what it genuinely cannot do, and how to decide for yourself.
What does a VPN actually do?
Strip away the marketing and a VPN does exactly one thing: it moves the point where your traffic enters the internet.
Normally, loading a website sends your request from your device to your router, then to your internet service provider — the company you pay for broadband or mobile data — and out onto the wider internet from there. Your ISP sees which sites you connect to. The site sees your IP address, a number identifying your connection and roughly indicating your location.
With a VPN switched on, your device first builds an encrypted tunnel to a server run by the VPN company. Everything travels through that tunnel and leaves for the internet from that server instead.
Two consequences follow, and they are the only two:
- Your ISP, and anyone else on the network between you and the VPN server, can see that you are connected to a VPN and how much data is flowing. They cannot see which individual sites you visit.
- The sites you visit see the VPN server’s IP address and location instead of yours.
That is the entire mechanism. Everything true about VPNs follows from it, and so does everything false. If a claimed benefit cannot be traced back to “my traffic enters the internet somewhere else,” it is not a real benefit.
What does a VPN not do?
This is where the marketing lives. A VPN is a legitimate tool. It is also sold as a general-purpose safety product, which it is not.
It does not make you anonymous
Anonymity would mean nobody can connect your activity to you. A VPN moves the observation point; it does not remove it. The VPN company sees what your ISP used to. And the moment you log in to anything, you have identified yourself by name regardless of which IP address you arrived from — and most of what you do online involves being logged in.
It does not stop tracking
The most consequential misunderstanding. Advertising and analytics tracking barely relies on IP addresses. It works primarily through:
- Cookies — small files a site stores in your browser, which follow you as you move around.
- Browser fingerprinting — building an identifier from the combination of your screen size, operating system, installed fonts, time zone, browser version and dozens of similar details, which together are often distinctive enough to recognise you again.
- Your logged-in accounts — by far the richest source. If you are signed in, the platform knows exactly who you are.
None of these care where your traffic entered the internet. Turning on a VPN and expecting the ads to stop is like changing your postal address to stop someone recognising your face.
It does not stop viruses or malware
A VPN encrypts a connection; it does not inspect what travels through it. Download a malicious file and the VPN faithfully delivers it. Some providers bundle a blocklist that filters known-bad domains — a separate product sold alongside, and generally a weaker version of what your browser already does.
It does not stop phishing
Phishing works by convincing you to hand something over voluntarily. The connection to a fake login page is encrypted exactly as reliably as the connection to the real one. Encryption tells you nobody is eavesdropping; it says nothing about who is on the other end. For a real defence here, understanding how modern scams actually work is worth more than any subscription.
It does not protect a compromised device
If something malicious is already running on your laptop or phone, it sits inside the tunnel with you. It reads your screen, your keystrokes and your files before any of it is encrypted. A VPN protects data in transit between two points. It has nothing to say about either endpoint.
It does not hide anything from a site you are logged into
Obvious once stated, routinely forgotten. Your bank knows it is you. A shopping site with your delivery address knows it is you. The only thing a VPN changes is the location stamp on the visit — and an unexpected location can trigger a security alert or lock you out.
Is public Wi-Fi actually dangerous?
This is the scenario that sells more VPN subscriptions than every other argument combined: a stranger two tables away, laptop open, quietly harvesting your passwords out of the air while you check your bank balance.
That scenario was real. It described an earlier internet, when a great deal of web traffic travelled unencrypted, in plain readable text, and anyone on the same network with modest technical skill genuinely could scoop it up.
Then the web fixed it. The fix is called HTTPS, and it is worth understanding properly, because it dismantles most of what you have been told.
What HTTPS actually means
The S stands for secure. When your browser connects to a site over HTTPS, two things happen before any of your data moves:
- The site proves who it is. It presents a certificate, issued by an independent authority, confirming it genuinely controls that domain name. If the certificate is missing, expired, or does not match, your browser stops and warns you.
- An encrypted channel is established between your device and that specific site’s server. Everything after that — your password, your messages, the pages you read, what you type into forms — is scrambled in a way only your device and that server can unscramble.
Here is the part that matters: that encryption runs end to end, from your device to the website, and it does not care what network it crosses on the way. Coffee shop Wi-Fi, airport Wi-Fi, hotel Wi-Fi, a network run by someone actively hostile — the operator can see that you connected to a particular site, and how much data passed. They cannot read what you sent or received. The encryption was established before your data ever touched their equipment.
HTTPS is now overwhelmingly the norm across the web. Browsers actively push it: they mark plain HTTP pages as not secure, upgrade connections where possible, and interrupt you with a full-page warning if a certificate does not check out. Free automated certificates removed the last practical reason not to use it.
So the honest version of the public Wi-Fi warning is this: on a network you do not control, someone can see which sites you visit, but not what you do on them. That is a meaningfully smaller problem than the one the advertising describes, and for most people on most days, it is not a problem worth a monthly subscription.
A caveat, in fairness: the network operator does see the domain names you connect to, and a list of sites can be revealing even without contents. And if you click through a browser certificate warning, you throw away the protection entirely. Do not click through those warnings.
Who can see your traffic — and does a VPN really fix that?
Here is the argument that almost never appears on page one of the search results, and it is the one that should shape your decision.
A VPN does not remove the party who can see your browsing. It changes who that party is.
Without a VPN, your ISP can see the sites you connect to. With a VPN, your ISP sees only an encrypted tunnel — and the VPN company sees the sites instead. The visibility did not disappear. It moved.
So the real question is never “should I get a VPN?” It is: do I trust this VPN company more than I trust my internet provider?
That is a genuine question, and the answer differs by person and place. Your ISP is usually a large regulated company in your own country, with a legal relationship with you — and depending where you live, it may be permitted to build advertising profiles from your browsing, or required to retain records. Some people have concrete reasons to be unhappy about that. The VPN company, meanwhile, is often incorporated somewhere you have never dealt with, under laws you have not read, owned by a parent you may not easily identify. You have handed it your entire browsing visibility on the strength of its own marketing.
About “no logs”
Every provider says it keeps no logs. It is the industry’s baseline claim, which means it carries almost no information. Consider three things:
- It is a claim, not a mechanism. Unlike HTTPS, which works because of mathematics you do not have to trust anyone about, “no logs” works only if the company is telling the truth and continues to.
- Audits vary enormously in rigour. Some are serious independent examinations of infrastructure. Others are a brief snapshot of configuration at one moment, commissioned and paid for by the provider, with the scope defined by the provider. “Independently audited” on a landing page tells you very little without reading what was actually examined.
- Ownership changes. The policy you signed up under belongs to a company that can be acquired.
About free VPNs
Running a VPN is genuinely expensive: servers, bandwidth and staff, in many countries at once. If you are not paying, that cost is met some other way — advertising, data collection and resale, injecting content, selling your idle connection as an exit point for other people’s traffic, or funding that will eventually become one of those.
This is arithmetic, not conspiracy. A free VPN asks you to route all your browsing through a company whose revenue model you cannot see — a worse position than not using one at all. If you conclude you need a VPN, budget for paying for it.
When is a VPN genuinely worth having?
Having spent that long on what VPNs are oversold as, it would be dishonest not to be equally clear about what they are legitimately good for. These uses are real.
- Connecting to a workplace or university network. The original purpose, and still the least ambiguous. A corporate VPN puts your device logically inside a private network so you can reach internal systems from outside. If your employer requires one, use it — it is a completely different product from the consumer subscriptions advertised to you.
- A network you have specific reason to distrust. Not “public Wi-Fi” as a vague category, but a particular network you have concrete reason to think is hostile or intrusive. If you believe someone is inspecting or interfering with traffic there, routing around it makes sense.
- Keeping browsing private from your ISP or your household. If you do not want your provider building a profile of your browsing, or would rather others on your home network could not see which sites you visit, a VPN addresses that directly. This is a real benefit — the trust transfer working in your favour.
- Reaching your home country’s services while travelling. Some banks, government portals and subscriptions behave badly or block access entirely from abroad. Connecting through a server at home is a practical fix for a practical annoyance.
- Some protection from IP-based tracking. Partial, not complete. It removes one signal among many — worth something in combination with browser-level protections, worth little on its own.
- Circumventing censorship. Where a government blocks access to news, communication tools or information, a VPN can restore it, and that is a genuinely important use. A serious caveat belongs here. In some countries, using or possessing VPN software carries real legal and personal risk, and consumer VPN traffic can often be detected as such even when its contents cannot be read. If that is your situation, a general article on the internet is not adequate guidance. Seek out digital-rights and press-freedom organisations that publish current, country-specific advice for people at risk. Your safety depends on details that change and that we are not in a position to advise on.
What about streaming and region-locked content?
Streaming services license content country by country, so their catalogues differ, and they restrict access based on where your connection appears to originate. Because a VPN changes that apparent origin, it can change which catalogue you are offered.
Two factual points. First, this generally violates the streaming service’s terms of use, and the consequences are theirs to apply. Second, it is an ongoing technical contest: services detect and block the IP ranges providers use, providers rotate, and whether any given combination works this month is not something anyone can promise. Those are the facts; what you do with them is your business.
So do you need one?
Consider one if:
- Your employer or university requires it for remote access.
- You have a specific, articulable reason not to want your ISP or your household network to see the sites you visit.
- You travel and need reliable access to services from home.
- You live somewhere with internet censorship — with the caveat above about seeking specialist guidance first.
- You regularly use networks you have concrete reason to distrust, not merely networks that are public.
You probably do not need one if:
- Your reason is “public Wi-Fi is dangerous.” HTTPS already covers the danger being described.
- Your reason is stopping ads, tracking or data collection. It will not do that.
- Your reason is viruses, malware or scams. It does not address any of them.
- Your reason is “being anonymous online.” It does not provide that.
- Your reason is a general feeling that you ought to be doing more about security. That instinct is good. This is the wrong purchase for it.
That last case is the common one, and it deserves a better answer than a subscription.
What actually makes you safer instead?
If your real goal is being safer online rather than owning a VPN specifically, the following all outrank it, and they cost nothing or close to it.
- Use a unique password for every account, kept in a password manager. The single highest-value change available. Most real account compromises happen because a password leaked from one site and the same password worked elsewhere. A manager makes uniqueness practical rather than heroic. If you are hesitant about putting every password in one place, that is a reasonable instinct — we looked at whether password managers are actually safe in detail.
- Turn on two-factor authentication, at minimum on email and banking. A second step at login means a stolen password alone is not enough. Your email account matters most, because password resets for everything else land there. An app-based code or a hardware key is stronger than a text message, but a text message is far better than nothing.
- Keep your devices and browser updated. Unglamorous and genuinely effective. Many real-world attacks exploit flaws fixed months ago in an update people postponed. Turn on automatic updates and stop thinking about it.
- Learn to recognise phishing. Most people who lose money or accounts were not hacked in any technical sense — they were persuaded. Modern attempts are well written and often arrive with plausible context. The reliable habit: never act on a link in an unexpected message, navigate to the site yourself instead.
Every item on that list protects you against things that actually happen to ordinary people. A VPN protects against a narrow scenario that HTTPS has largely already handled. If you only have the attention for one change this month, it should not be the VPN.
What should you look for if you do decide to get one?
If your situation genuinely calls for one, here is how to evaluate it. We will not name providers — not one, not even as an example — because the moment an article starts listing names, you can no longer tell advice from advertising. Judge candidates yourself:
- Jurisdiction. Which country is the company legally based in, and what can authorities there compel it to do or hand over? This is a legal question, not a technical one, and it sits underneath every promise on the website.
- Ownership and business model. Who owns it, and how does it make money? Subscription revenue is the model you want, because it is the only one where you are the customer. Be wary where one parent company owns several providers and also owns the sites reviewing them.
- Audit history. Not whether an audit exists, but who performed it, what they were permitted to examine, how recently, and whether the full report is published rather than summarised in a blog post. Repeated audits over years mean more than one.
- Logging policy, read properly. Open the actual privacy policy, not the landing page. Look for what is retained, for how long, and note that connection metadata and payment records are often treated separately from “activity logs.”
- Track record. Has the company been tested — by a legal request, a server seizure, a breach — and what actually happened? Behaviour under pressure is worth more than any marketing claim.
- The basics. Modern protocols, a kill switch that cuts your connection if the tunnel drops, protection against DNS leaks, and clients for the devices you actually use.
Then pay for it — and keep clear what you have bought: not safety, not anonymity, not invisibility. You have chosen a different company to see your browsing, for reasons you can articulate. That is perfectly sensible. It is just much smaller than what the advertising promised.
The same logic applies to the other product sold on fear. Antivirus is mostly already on your machine, and a slow phone is usually a battery rather than a virus.
The National Cyber Security Centre and the US CISA both publish security advice with nothing to sell, and neither puts a VPN near the top of the list.
For what actually happens to your personal data online, the Information Commissioner’s Office is a better guide than any VPN comparison page.
Frequently asked questions
Is it safe to use my bank’s app or website on public Wi-Fi without a VPN?
Yes, in ordinary circumstances. Banking sites and apps use HTTPS and usually additional protections on top, so the connection is encrypted between your device and the bank regardless of network. The operator can see that you connected to your bank; not your credentials or balance. The one thing that breaks this is clicking through a browser security warning — never do that.
Does a VPN hide my browsing from my employer?
On a device your employer owns or manages, assume not. Managed devices commonly have monitoring software installed, and a company may install a certificate that allows inspection of encrypted traffic on its own equipment. A VPN protects data in transit; it does not protect you from software running on the device itself. Installing a personal VPN on a work machine may also breach your employer’s policy.
Will a VPN make my internet slower?
Usually a little. Your traffic takes a longer route and is encrypted and decrypted along the way, so expect added latency — more noticeably on a distant server. A nearby server may be barely perceptible for browsing, but it is never faster. The exception is an ISP that deliberately throttles certain traffic types, where a VPN can occasionally help.
Do I need a VPN on my phone?
The reasoning is identical to a computer, and mobile carriers already encrypt the connection between your phone and the network. The larger privacy issue on a phone is not the network at all — it is app permissions and the data apps collect directly. Reviewing which apps have location, contacts and microphone access does more for your privacy than a VPN.
Is using a VPN legal?
In most countries, yes, and they are standard business tools. A minority of countries restrict or ban them, and in some places their use carries real legal risk. Legality also does not cover what you do while connected — a VPN does not make an otherwise illegal act legal. If you are unsure about your own country, check current local guidance rather than assuming.
Is incognito mode the same thing as a VPN?
No, and they are frequently confused. Incognito browsing only stops your own browser saving history, cookies and form data on that device once you close the window. It hides nothing from your ISP, the network, or the sites you visit. It is a tool for keeping activity off a shared computer, nothing more.