June 27, 2026 · 4 min read

Can Your ISP Sell Your Browsing History?

The short answer is: your internet provider can collect more about you than most people expect, and in the US the rules are not as simple as “they need permission first.”

That does not mean a person at your ISP is sitting there reading your browser history over coffee. It means the company that connects your house, phone, or apartment to the internet is in a very privileged spot. Every request starts by passing through them.

The FTC said this plainly in its report on major internet service providers. ISPs can have access to all of a customer’s internet traffic, and some combine web browsing data, app usage, location data, and information from other product lines for advertising and analytics.

What your ISP can actually see

HTTPS changed the internet for the better. When you visit your bank, email, or most normal websites, your ISP usually cannot read the exact page contents, passwords, messages, or checkout details.

But that does not make your browsing private from the network. Your ISP may still be able to see useful metadata, like:

That metadata is not harmless. A list of domains can say a lot. Health sites, financial services, political sites, job boards, dating apps, religious communities, and late-night searches all create patterns.

What the law allows

In 2017, Congress reversed FCC broadband privacy rules that would have required stricter consent before ISPs used or shared sensitive customer data. Since then, protection has been a patchwork.

The FTC can still act against unfair or deceptive practices. Some states have privacy laws that give residents more rights. California’s privacy law, for example, can cover broadband providers and gives people rights around access, deletion, and sale of personal information.

But for most people, the practical takeaway is simple: do not assume your ISP is legally blocked from using browsing-related data for advertising, analytics, or sharing with affiliates. Read the privacy policy if you want the legal version. Then remember that “we do not sell personal information” does not always mean “we do not monetize data.”

Plain-English rule: if a company controls the pipe, it can learn from the traffic unless you reduce what the pipe can see.

How a VPN changes the picture

A VPN does not make you invisible. Websites can still see what you do when you log in. Apps can still collect their own data. Cookies and accounts still matter.

What a VPN does is change what your internet provider sees on the first hop. Instead of seeing separate connections to every site and app, your ISP sees an encrypted connection to the VPN server. Your browsing, DNS requests, and app traffic go through that tunnel.

That is useful at home, and it is even more useful on apartment WiFi, hotel WiFi, airport WiFi, and mobile networks you do not control.

The trust does not disappear. It moves. Instead of trusting your ISP with your browsing metadata, you trust your VPN provider. That is why the provider’s business model matters. If the VPN is free, ask how it pays for servers. If it is $12 a month, ask how much of that is ads and sponsorships.

At 99¢ VPN, the idea is boring on purpose: WireGuard, one device, simple setup, and a price that does not need a marketing circus behind it. If you want a basic tunnel between you and your ISP, you can get 99¢ VPN for $11.88/year here.

The bottom line

Your ISP probably cannot see every word you read or every password you type. Modern encryption helps a lot.

But your ISP can still sit in a powerful spot. It can see enough metadata to build a useful profile, and US privacy rules still leave plenty of gaps. A VPN is not magic privacy dust. It is a practical way to keep your internet provider from being the easiest company in the chain to learn where you go online.


Written by the person who runs 99¢ VPN. Not legal advice. Just a plain-English explanation of what your internet provider can see and how a VPN changes the first hop.