Ask what an internet provider can see and you will get two bad answers. One says they read everything you do. The other says HTTPS means they see nothing.
Both are wrong, and the accurate answer is more useful than either.
Start with what encryption already covers
Almost all web traffic is now encrypted with TLS — the padlock in the address bar. Where it is in use, your provider cannot see:
- The specific pages you view on a site
- What you type: searches, messages, form contents, passwords
- Images, video and files you send or receive
- The contents of messages in properly encrypted messaging apps
This is real protection and it covers the majority of what people worry about. Your provider is not reading your emails as you write them.
Now what remains visible
Encryption protects the contents of the envelope. It does not hide the envelope.
Which sites you connect to. This is the big one, and it leaks through two separate channels.
The first is DNS. Before your device can connect to a site, it converts the name into an address, and by default that lookup goes to your provider's DNS server in plain text. They receive a direct, timestamped request: this customer wants the address for this hostname. That is a browsing history, delivered voluntarily, in a convenient list.
The second is the connection itself. Even with encrypted DNS, your traffic goes to an IP address your provider can see. For sites on dedicated infrastructure, the address identifies the site. Historically the server name was also sent in the clear during the TLS handshake; encrypted variants exist but are not universally deployed, so this often remains visible.
When and how much. Every connection is timestamped and measured. Your provider knows when your devices are active, when you sleep, when the house is empty, when you started streaming and for how long.
Traffic shape, which implies content type. Video streaming, voice calls, large downloads and ordinary browsing all have distinct patterns. Nobody needs to decrypt a video call to know it was a video call.
Everything your devices do without you. Background sync, app updates, telemetry, smart-home devices phoning home. This is a continuous, passive inventory of the software and hardware in your home.
Anything not encrypted. Increasingly rare on the web, but older devices, some apps and various embedded systems still transmit in the clear.
Why this is not a trivial residue
It is tempting to conclude that hostnames and timings are harmless metadata. They are not.
A list of which sites you visited and when is, for most practical purposes, the interesting part. It reveals which bank you use, which health conditions you research, which political sites you read, which dating services you have accounts with, and who you might be talking to. Content is often predictable once the destination is known.
What happens to that record varies by jurisdiction. Some countries mandate retention for a fixed period. In some, providers may sell aggregated browsing data commercially. In most, it is obtainable by legal process. The consistent fact is that the record exists and you are not the one holding it.
What a VPN changes, precisely
A VPN encrypts everything leaving your device and sends it through one tunnel to a server you have chosen. From your provider's position, that changes the picture:
- They see one encrypted connection to one address. Not a list of destinations.
- DNS goes through the tunnel, so the lookup no longer reaches them.
- Traffic shape is largely obscured, because everything is multiplexed into a single stream.
- Timing and volume remain visible. They still know you are online and roughly how much data is moving.
The honest framing is that a VPN does not delete the observation point. It relocates it. Your provider stops being able to build the list; the VPN operator now occupies that position instead.
Which makes the operator's policy the entire question, and the reason to be specific rather than trusting a logo:
- Does it keep no connection or session logs? Infrastructure that runs in RAM only cannot retain what was never written to disk.
- Does it run its own DNS resolvers inside the tunnel, rather than leaking queries to a third party?
- Is there a kill switch, so traffic stops rather than falling back to the open network if the tunnel drops?
- What is the business model? A free VPN has costs and no revenue from you. Several have been documented monetising user traffic. You are not removing a watcher; you are choosing a worse one.
What a VPN does not do
Worth stating plainly, because the industry is bad at this:
- It does not make you anonymous. Logging into an account identifies you regardless of the tunnel.
- It does not stop tracking by sites you visit. Cookies and browser fingerprinting are unaffected.
- It does not protect you from phishing, malware or a compromised device.
- It does not hide activity from the sites themselves, or from anyone you send data to.
The practical summary
Use encrypted DNS and keep everything on HTTPS — that is free and closes the largest leak on any network.
Use a VPN when the observer you want to remove is the network operator: your ISP, a public Wi-Fi provider, a hotel, a landlord's shared connection, or a national filtering system. That is the specific problem it solves, and it solves it well.
Do not use it expecting anonymity, and do choose the operator as carefully as you would choose an ISP — because for the duration of the connection, that is exactly what they are.