A VPN replaces your IP address and encrypts the path between you and the server. That is what it does, and it does it well. Nearly everything else people expect from it is expectation, not function.
Here is what survives the tunnel.
1. Your login
The moment you sign in, the site knows who you are. Location becomes irrelevant. The tunnel changes the return address on the envelope, not the name written inside.
This is the biggest one, and it sits at the top because it silently cancels most of the others. If you are logged into an account while doing something you wanted kept separate, nothing further down this list matters much.
2. Cookies and stored identifiers
Cookies live in your browser. Switching to a server in another country does not clear them, does not change them, and does not stop them being read. If a tracker recognised you an hour ago, it recognises you now.
3. Your browser fingerprint
Screen resolution. Timezone. Installed fonts. How your graphics card draws a curve. Language preferences. Extensions that alter the page.
None of this travels at the IP layer, so the VPN has no contact with it. And there is a twist worth knowing: an unusual combination is easier to single out, not harder. A browser reporting a Paris timezone over an IP that says Dallas is a rarer profile than either would be alone.

Everyone in this photo is anonymous in the sense that no name is written on them. Several are instantly findable anyway, because a combination of ordinary details is not an ordinary detail. That is fingerprinting, and no change of address affects it.
4. DNS, if it leaks
The VPN is supposed to carry your DNS lookups too. Sometimes it does not, because of an operating system setting, a split-tunnelling rule, or a client that fails open when the connection drops. When that happens your provider sees every domain you visit while the tunnel is up and apparently working.
This one is worth testing rather than assuming, because it fails silently and the interface will show you a reassuring green.
5. What you type, and when
Timing, rhythm, the order in which you do things, the vocabulary you use, the phone number you enter in a form. Behaviour is not routed through anything. A tunnel moves packets, not habits.
6. Your device clock and locale
Small, and often decisive when combined with the rest. A device announcing a timezone that contradicts its apparent country is a signal, not a disguise.
7. Whatever the provider itself can see
Your traffic now goes through them instead of your internet provider. That is a transfer of trust, not an elimination of it. Which is why jurisdiction, audits and logging policy are the things worth reading about a provider, far more than server counts.
We are not going to tell you which provider to trust on the strength of a marketing page. What can be checked is published policy, published audits, and what happened the last time the company received a legal request. What cannot be checked from outside is whether logs are kept, and anyone who tells you they have verified that from their laptop is overstating what they did.
What actually changes the outcome
Ranked by effect, not by how often it gets sold:
- Do not be logged in to the thing you want kept separate. Use a distinct browser profile or container. This beats every other item on this page.
- Test for DNS leaks rather than trusting the green icon.
- Reduce fingerprint surface if that is your threat model, accepting that a hardened browser is itself distinctive, and that this trade-off has no clean answer.
- Then think about which server you connect to.
A VPN is a good tool with a narrow job. The problem is never the tool. It is that a false sense of safety changes what people are willing to risk, and that is worse than carrying no tool at all.
Frequently asked questions
- What does a VPN actually hide?
- Two things, and they are worth having. It hides your IP address from the sites you visit, replacing it with the server's. And it hides the content and destination of your traffic from whoever runs the network you are on: the cafe wifi, the hotel, your internet provider. That is a real and specific benefit. Everything outside those two things is untouched by the tunnel, which is why the list of what it does not hide is longer than the list of what it does.
- Does a VPN stop browser fingerprinting?
- No, and it can make you slightly easier to spot. Fingerprinting reads what your browser reveals in normal operation: screen size, timezone, installed fonts, graphics rendering quirks, language settings. None of that travels through the IP layer, so the tunnel does not touch it. Worse, an unusual combination stands out more, not less: a browser reporting a Paris timezone while its IP says Dallas is a rarer profile than either on its own.
- If I log into my account, does the VPN still help?
- Against the network operator, yes. Against the site, largely no. The moment you sign in, the service knows exactly who you are regardless of where the connection appears to come from. The tunnel changes the return address on the envelope, not the name written inside the letter. This is the single most common misunderstanding, and it is why 'browse anonymously' is a claim worth reading very literally.
- Do cookies still work through a VPN?
- Yes. Cookies live in your browser, not on the network, so switching servers does nothing to them. If you were tracked before connecting, the same identifiers are still there afterwards. Clearing them, or using a separate browser profile or container for the activity you want kept apart, does more for that specific goal than any server choice.
- So is a VPN pointless?
- No, it is narrow. It solves the untrusted-network problem well and the who-is-this-IP problem well. It does not solve identity, tracking, or behaviour. A tool that does two things properly is useful; a tool sold as doing everything creates a false sense of safety, which is worse than no tool at all because it changes what people are willing to risk.
Store your files privately → pCloud
Swiss privacy · 10 GB free · optional zero-knowledge Crypto



