July 16, 2026 · 4 min read

What Your ISP Knows Even When HTTPS Is On

Most websites use HTTPS now, which is good. It means your internet provider usually cannot read the exact page contents, your passwords, or the message you typed into a form.

But that does not mean your internet service provider is blind. It still sits at the first hop between your device and the rest of the internet. That position is powerful.

The plain-English version: HTTPS hides the conversation, but your ISP can still often see who you are talking to, when you talked, how much data moved, and which devices were involved.

HTTPS is not the same as private browsing

Think of HTTPS like a sealed envelope. Your ISP cannot easily read the letter inside. But it can still see the outside of the envelope: where it is going, when you sent it, and roughly how heavy it is.

That outside information is called metadata. It sounds harmless until you add it up. If someone sees that your phone connects to a bank every Friday morning, a medical portal twice this week, a job site late at night, and a streaming service for four hours, they do not need the page contents to learn something about your life.

The FTC has said large ISPs can collect broad categories of personal data, including browsing data, app usage, location information, and connected-device data. The exact rules depend on where you live, what the ISP says in its privacy policy, and which state or federal laws apply. But the important part is simple: your provider may know more than you think.

What your ISP can usually still see

The details vary by network, device, and settings, but here are the common pieces:

This does not mean someone at the ISP is personally reading your life like a diary. Most of this is automated. It can be used for network management, advertising, analytics, fraud detection, or legal compliance. The point is that the data exists, and privacy policies often leave a lot of room for collection and sharing.

Quick rule: HTTPS protects the content of most modern websites. A VPN protects more of the connection path between your device and the network you are using.

What a VPN changes

When you turn on a VPN, your ISP sees an encrypted connection to the VPN server. It no longer gets the same easy view of every site and app your device is contacting directly.

That does not make you anonymous. The VPN provider becomes the next hop of trust, and websites can still track you with logins, cookies, browser fingerprints, and account behavior. A VPN is not a magic privacy cloak.

But it does solve a very specific problem: it stops your ISP, hotel WiFi, airport network, or coffee shop router from being able to build a simple map of your browsing from the local connection.

For most people, that is the practical reason to use one. Not because you are doing anything strange. Because your browsing patterns should not be easy background data for every network you pass through.

If you want the simple version, 99¢ VPN gives you WireGuard for one device at $11.88/year. It is built for exactly this kind of everyday privacy: turn it on, route your traffic through an encrypted tunnel, and stop handing your ISP the first draft of your browsing habits.

The bottom line is not complicated. HTTPS is necessary. Incognito can keep local history off your browser. A VPN handles the network layer. They are different tools, and if you care what your ISP can learn, the network layer is the one you should not ignore.


Written by the person who runs 99¢ VPN. Not legal advice. Just a plain-English guide to what your internet provider can still learn.