June 28, 2026 · 4 min read

What Your ISP Can Still See When You Browse

A lot of people hear “HTTPS” and assume their internet provider is basically blind now. I wish it were that simple.

HTTPS does protect the contents of most modern websites. Your ISP usually cannot read the exact article you opened, the password you typed, or the private message you sent. That is good.

But your ISP still sits at the front door of your internet connection. Even when the room is locked, it can often see which building you walked into, when you arrived, how long you stayed, and how much stuff you carried out.

HTTPS hides content, not every pattern

Think of HTTPS like a sealed envelope. The mail carrier cannot read the letter, but the carrier can still see the address on the outside.

Online, that outside information is metadata. It can include:

That may sound harmless until you imagine a month of it. A domain list can sketch out your habits pretty quickly: where you shop, what news you read, which medical topics you look up, when you are awake, and which apps are always running in the background.

The privacy rules are still patchy

The FTC has warned that large internet service providers can collect huge amounts of personal data, including browsing information, app usage, location data, and information from other services they own. Some ISPs also operate ad businesses, which makes the data more valuable.

The FCC now requires broadband “nutrition labels” that show prices, speeds, data caps, and links to privacy policies. That is useful, but it does not mean every privacy issue is solved. A link to a privacy policy is not the same thing as private browsing.

In the US, broadband privacy is still a mix of federal rules, FTC enforcement, state privacy laws, and whatever your provider says in its own policy. Some states give you more rights. Some companies make stronger promises. But the average person should not assume their ISP is legally blocked from learning from traffic metadata.

Plain-English rule: modern encryption hides more than it used to, but the company carrying your connection can still learn from the shape of your traffic.

Where a VPN helps

A VPN changes what your ISP sees. Instead of many separate connections to many different sites, your provider sees one encrypted connection to the VPN server.

That does not make you anonymous. If you log into Gmail, Google still knows it is you. If you open Instagram, Meta still sees your account activity. A VPN does not erase cookies, stop tracking pixels, or fix bad privacy settings.

What it does is reduce what the network operator can observe on the first hop. Your ISP no longer gets the same easy map of every domain your device contacts. On public WiFi, hotel WiFi, apartment WiFi, or mobile networks, that is a practical privacy improvement.

The trust moves from your ISP to your VPN provider, so the provider matters. I would avoid free VPNs for that reason. Servers cost money. Bandwidth costs money. If the product is free, the business model is hiding somewhere.

That is also why expensive VPN bundles annoy me. Most people do not need a giant security suite. They need a basic encrypted tunnel that is easy to turn on and cheap enough to leave running.

If that is what you want, 99¢ VPN is $11.88/year for a simple WireGuard VPN. One device, plain setup, no big sponsorship machine baked into the price.

The bottom line: HTTPS helped a lot, but it did not make your ISP irrelevant. If you want your provider to see less of your browsing life, a VPN is one of the simplest ways to close that gap.


Written by the person who runs 99¢ VPN. Not legal advice. Just a plain-English guide to what your internet provider can still learn from your connection.