What Your ISP Can Learn Before a VPN Gets Involved
Your internet provider sits in an awkwardly powerful spot. It is the first company your traffic touches when you open your laptop, unlock your phone, or let your apps sync in the background.
That does not mean your ISP can read every message or every page. HTTPS changed a lot. Your bank login, email contents, and most page text are encrypted before they leave your device.
But “they cannot read the page” is not the same as “they know nothing.” The outside of your traffic still tells a story.
What your ISP can still see
Think of HTTPS like putting a letter inside an envelope. The message is hidden, but the mail carrier still sees where the envelope is going.
For internet providers, that can include:
- Domains and IP addresses. They may not see the exact article, but they can often see that you connected to a news site, streaming service, bank, health portal, or shopping app.
- DNS requests. If your device asks for a site through regular DNS, that lookup can reveal the services you use.
- Timing and volume. Late-night browsing, work hours, video streaming, gaming sessions, and large downloads all have patterns.
- Location clues. Mobile providers and home broadband providers both connect your activity to an account and a service location.
The FTC has said many internet providers collect large amounts of personal data and that some combine browsing, app usage, location, and other product data for advertising or analytics. The uncomfortable part is not one single website visit. It is the profile that can be built from months of routine traffic.
Can they sell it?
In the United States, the simple answer is: privacy rules are patchy. The FCC broadband privacy rules that would have required stronger permission before sharing browsing history were repealed in 2017 before they took effect.
That does not mean every ISP is dumping a list of your websites onto an auction table. Many providers use careful language like “share,” “use,” “monetize,” “personalize,” or “partners” instead of “sell.” Some states also give consumers privacy rights, and the FTC can go after unfair or deceptive practices.
Still, the practical takeaway is the same: do not assume your ISP is a neutral pipe that forgets everything. Read the privacy settings in your ISP account. Opt out of targeted advertising where you can. Use encrypted DNS if you understand the tradeoffs. And be realistic about what your provider can infer from being your first hop to the internet.
Where a VPN actually helps
A VPN does not make you invisible. The VPN provider becomes the company handling the first hop, so you still need to trust it. Websites can still track accounts, cookies, browser fingerprints, and logins.
What a VPN does well is simpler: it encrypts the traffic leaving your device and sends it through a VPN server first. Your ISP sees an encrypted connection to the VPN. It does not get the same easy view of every domain, DNS request, and traffic pattern on your normal connection.
That matters most when you do not want your home ISP, mobile carrier, hotel network, airport WiFi, or landlord-provided internet to build a casual map of your browsing habits.
If you want a basic VPN without the usual $10-a-month routine, 99¢ VPN is $11.88 for a year. It uses WireGuard, works on one device, and keeps the setup boring on purpose.
The bottom line: your ISP may not know every word you read, but it can still learn more than most people would casually hand over. A VPN is not magic. It is just a cleaner place to put the first hop.
Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of why your ISP can see more than page contents.