Your ISP Can See More Than You Think: A Simple Privacy Checklist
Most of us think of an internet provider as the company that makes the WiFi work. Fair enough. But every connection from your phone or laptop passes through its network first, which means it gets a useful view of your online life.
That does not mean your ISP can read every message or see every page you open. HTTPS protects the contents of most modern websites. Still, the surrounding details can be revealing: which services you connect to, when you connect, how long you stay, and how much data moves.
The FTC's review of major US providers found that many collected and combined data across products, including web browsing and app-use data, for advertising and analytics. The exact rules and choices available depend on your provider and where you live. So instead of assuming "private" or "sold," it is worth doing a quick check.
What your internet provider can usually see
Think of HTTPS as sealing the letter, not hiding the address on the envelope. Your ISP generally cannot read the text of a secure page, but it may still be able to see enough connection information to make educated guesses about what you are doing.
- Sites and services you connect to: often a domain or network destination, even when the page itself is encrypted.
- Timing and duration: when a device connects and roughly how long the session lasts.
- Traffic volume: whether you are casually reading, on a video call, streaming, or downloading something large.
- Account and device details: the service address, billing identity, device identifiers, and sometimes location information on mobile networks.
That is why Incognito mode is not the answer here. It mainly keeps browsing history and cookies off your own device after the session. It does not change the route your traffic takes through your ISP.
"We do not sell data" deserves a second look
Privacy policies can use careful wording. A company might say it does not "sell" personal data while still describing sharing with affiliates, service providers, advertising partners, or analytics companies. Those are not always the same thing, and the labels do not tell you how much information is involved.
State privacy laws can give people useful rights to see, delete, or opt out of certain uses of personal information. California, for example, treats browsing history and online activity as personal information under its privacy law. That is helpful, but it is not the same as making the connection private by default.
Open your provider's privacy notice and search for a few plain terms: browsing, online activity, advertising, share, and opt out. If the answer is a maze of linked policies, that is information too.
The practical privacy move
A VPN changes the first part of the trip. When it is connected, your ISP sees an encrypted connection to the VPN server instead of a direct connection to every site and service you use. The VPN provider becomes a party you need to trust, so its privacy policy still matters. A VPN also does not stop sites from tracking you after you sign in, and it does not make you anonymous.
But it is a clean way to reduce how much browsing detail your local ISP can observe, especially on home internet, mobile data, and public WiFi. Pair it with HTTPS, sensible account security, and a browser privacy setting that opts out where available.
If you want that encrypted first hop without another expensive subscription, try 99¢ VPN Basic. It is a simple WireGuard connection for one device, built for the boring everyday privacy habit of keeping your traffic encrypted.