A VPN Hides One Part of Your Trail. The Rest Is Still There.

A VPN changes the IP address websites see and hides destinations from the local network, but cookies, logins, browser fingerprints and the VPN itself remain.
The appealing version of a VPN is simple: switch it on and become private online. The real version is narrower. A VPN creates an encrypted tunnel between your device and a VPN server. That can solve important problems, but it does not turn the browser into a clean identity.
The easiest way to evaluate the claim is to list each observer and ask what changes.
Your local network sees less
Without a VPN, the Wi-Fi operator and internet provider can observe connection metadata such as destination IP addresses and DNS requests, unless encrypted DNS is used. HTTPS protects page contents but does not conceal every destination clue.
With a properly configured VPN, that local observer mainly sees an encrypted connection to the VPN server, plus timing and volume. This is a real benefit on a network you do not trust. It also prevents the access provider from building the same destination-level view from your ordinary traffic.
The VPN provider now sits at the tunnel exit. It can see source-account information and connection metadata, and it may see destinations. HTTPS still protects page contents from the VPN. The tool moves visibility; it does not make visibility disappear.
Websites still recognise the browser
A website sees the VPN server’s IP address instead of your home address. That can change approximate location and separate the visit from other traffic on the home IP.
But the site also has stronger identifiers:
- If you sign in, the account identifies the session.
- Existing cookies survive when the VPN connects.
- Advertising and analytics identifiers remain in browser storage.
- A browser fingerprint can combine screen size, fonts, language, time zone, graphics behaviour and other signals.
- Links can carry tracking parameters tied to an email or campaign.
Changing one network field while leaving the same account and cookies is not a fresh identity. It is the same browser arriving by a different exit.
Incognito mode solves a different problem
Private or incognito windows mainly limit what the browser stores after the window closes. They start with a separate temporary cookie jar and avoid adding pages to local history. They do not hide the public IP address from websites or the destination from the network.
A VPN and a private window can therefore complement each other, but neither covers the entire path. One changes the network route; the other limits persistent browser state on the device.
The leak checks have limits too
VPN sites often point to an IP, DNS or WebRTC leak test. These tests are useful for confirming that a browser request reaches the tester through the expected exit. They cannot prove that every application uses the tunnel, that the provider keeps no logs, or that a website cannot recognise the browser another way.
A meaningful check includes the failure case. Start a transfer, interrupt the VPN and see whether traffic stops or falls back to the ordinary connection. Verify IPv4, IPv6 and DNS. If a product has a kill switch, test it instead of trusting the label.
What a VPN is actually good at
A VPN is useful when the threat is specific:
- preventing a local network or access provider from seeing ordinary destinations;
- making a remote service see the VPN exit address;
- reaching a private workplace or home network securely; or
- keeping applications on one protected route when the controls are configured correctly.
It is a weak answer to account tracking, cookies, browser fingerprinting, malware, phishing or a device already controlled by somebody else.
That narrower description is less cinematic than “be anonymous online.” It is also more useful. Privacy tools work best when the observer, data and mechanism are named. If a claim cannot say which of those changes, it is probably selling a mood.