August 1, 2026 · 4 min read

Is Your ISP Selling Your Browsing Data? The Consent Reality

Your internet provider sits in an awkward place. It is not just another website you visit. It is the pipe you use to reach every website, app, update server, streaming service, and random background request your devices make all day.

That does not mean your ISP can read everything you do. HTTPS changed a lot. When you visit a secure site, your provider usually cannot see the exact page content, passwords, messages, or checkout details.

But “they cannot read the page” is not the same as “they know nothing.” They can still see useful metadata: the IP addresses you connect to, the domains your devices look up, when you connect, how long sessions last, how much data moves, and sometimes which apps are active.

The legal answer is messier than people expect

In the United States, broadband privacy rules have bounced between agencies and politics for years. The short version: there is not one clean national rule that says your ISP can never use browsing or app data for advertising.

The FTC’s 2021 staff report on internet providers was blunt. It found that many ISPs collect and share far more data than customers expect, including web browsing data, app usage, and location information. The report also said users often have few meaningful choices to restrict that use.

Some states add extra privacy rules. Some providers promise opt-outs. Some say they do not use web browsing data for advertising. That is good, but it still puts the burden on you to find the setting, trust the wording, and hope “business purposes” does not mean more than you think.

What your ISP can usually learn

Think of your ISP view like seeing envelopes instead of letters. They may not read the message inside, but the outside still says a lot.

None of this requires spy-movie hacking. It is normal network operation mixed with advertising incentives. That is why ISP browsing data feels different from website tracking. You can stop using one website. You cannot browse the internet without an access provider.

Where a VPN helps

A VPN changes the first hop. Instead of your ISP seeing a long list of sites and services, it sees an encrypted connection from you to one VPN server. The websites you visit see the VPN server’s IP address instead of your home IP.

That is useful, especially on home internet, mobile data, hotel WiFi, airport WiFi, and anywhere you do not want the network provider building a detailed map of your day.

A VPN does not make you invisible. The VPN provider becomes the party you are trusting with that first-hop view. Websites can still track accounts, cookies, browser fingerprints, and logins. If you sign into Google, Google still knows it is you.

So the practical question is not “does a VPN solve all privacy?” It does not. The better question is: would you rather your ISP see your browsing destinations by default, or would you rather reduce that view to one encrypted VPN connection?

If you want the simple version, 99¢ VPN gives you WireGuard for one device at $11.88/year. No bundle. No giant renewal price. Just a cheap way to keep your ISP from getting the easiest look at your browsing.

The bottom line: your ISP probably cannot read every secure page. But it can still learn more from metadata than most people realize. A VPN is not magic. It is just a clean, boring way to stop your access provider from being your default browsing-history observer.


Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English privacy version.