What Your ISP Still Knows Before You Open a Browser
Most people think about internet privacy after they open a website. That is a little late.
Your internet service provider sits at the first hop. Before your browser loads the page, before the app finishes opening, before you remember to delete your history, your connection has already passed through the company that sells you internet access.
That does not mean your ISP can read everything. Modern HTTPS is doing a lot of work. If you visit your bank, your ISP should not see your password, your balance, or the exact transfer page you opened.
But it can still learn more than most people expect.
What your ISP can usually see
Think of HTTPS like mailing a sealed envelope. The letter inside is private, but the outside of the envelope still says where it is going.
That outside information matters. Your ISP may be able to see domain names, DNS lookups, connection times, how much data moved, which device connected, and rough app patterns. It may not know the exact YouTube video you watched, but it can often see that you connected to YouTube, when you did it, and how much data moved.
DNS is the easy one to understand. When you type a domain name, your device has to ask where that site lives. Unless that lookup is encrypted, the network can log the request. Even when the page itself is encrypted, the lookup can still say, "this person opened this service at this time."
Incognito mode does not fix this. It keeps local browser history off your own device. It does not hide your network traffic from the company carrying that traffic.
Can ISPs sell browsing data?
In the US, the simple answer is: the strict broadband privacy rules people often remember did not survive. The FCC adopted rules in 2016 that would have required stronger consent for using and sharing sensitive broadband data. Congress repealed them in 2017 before they took effect.
That left a messier privacy picture. The FTC has said large ISPs can collect broad sets of personal data, combine it across services, and give customers limited ways to avoid some uses. State privacy laws may give you opt-out rights in some places. Company privacy policies may promise more than the law requires. But there is no universal magic switch that makes your ISP blind to your connection.
What a VPN changes
A VPN changes the first hop of trust. Instead of your ISP seeing connections to every site and app, it sees an encrypted tunnel to one VPN server. Your DNS requests and browsing traffic travel inside that tunnel.
That means your ISP can still see that you are online. It can still see that you are using a VPN. It can still see how much data is moving. But it no longer gets the same easy list of domains, apps, and timing patterns from your normal browsing.
A VPN does not make you anonymous. Websites can still track accounts you log into. Apps can still collect their own data. Cookies still exist. If you sign into Instagram, Instagram knows it is you.
But for the ISP question, a VPN is practical. It moves your everyday browsing away from the company that already knows your name, address, billing details, and home connection.
That is why a basic VPN is enough for a lot of people. You do not need a giant security bundle or a long feature list. You need a clean WireGuard connection that turns your ISP's view from "here are the sites this customer visits" into "this customer is connected to a VPN."
If you want that without paying big VPN prices, 99¢ VPN is $11.88/year for one WireGuard device. Simple setup, no bundle, no renewal-price games.
The bottom line: your ISP does not need to read every page to learn a lot. Metadata is still data. If you would rather not hand that first-hop history to your internet provider by default, keep a VPN on.
Written by the person who runs 99¢ VPN. Not a lawyer. Just someone who thinks basic network privacy should be cheap and easy.