Privacy basics · 7 min

What a VPN changes

A VPN can be useful, but it is not an invisibility switch. Here is what happens to your connection and where the trust moves.

The short version

A virtual private network creates an encrypted tunnel between your device and a VPN server. Websites see the server's public IP instead of the address assigned by your home, office or mobile provider. Your provider can see that you connect to a VPN, but normally cannot see the individual destinations carried inside the tunnel.

What a VPN can hide

  • Your usual public IP from the websites and apps reached through the tunnel.
  • DNS requests from the local network when the VPN supplies and correctly routes DNS.
  • Unencrypted traffic from people observing the same local Wi‑Fi.
  • Your direct destination list from your internet provider, although traffic timing and volume remain visible.

What it cannot hide

Signing into an account still identifies you to that service. Cookies, browser fingerprinting, payment details and location permissions can also connect activity to you. A VPN does not remove malware, fix weak passwords or make phishing pages trustworthy.

Trust is transferred, not deleted

Without a VPN, your internet provider operates the first hop. With one, the VPN provider can potentially observe connection metadata and, for non-HTTPS traffic, content. Look for clear ownership, a readable privacy policy, modern protocols, independent security assessments and a believable business model.

“No logs” is not a complete specification. Ask which logs are excluded, which operational records remain, how long they are kept and under which legal jurisdiction the company operates.

When a VPN is useful

A VPN makes sense on networks you do not control, for remote access to a workplace, to reduce routine IP-based profiling, or to route traffic through a chosen region where lawful. It may add latency or trigger extra verification checks because many users share an exit address.

Verify the connection

  1. Check your public IP before connecting.
  2. Connect to the VPN and refresh KiwiVPN.
  3. Confirm that the public IP and provider have changed.
  4. Use a reputable DNS leak test if DNS privacy is part of your goal.
  5. Disconnect and verify that normal routing returns.

A changed IP proves that web traffic reached the lookup service through a different network. It does not prove every application on the device is using the tunnel.