What your internet provider sees when you connect to the internet and how to protect yourself

Last update: January 2, 2026
  • Your operator and the WiFi owner can log visited domains, times, and data volume, even if you browse using HTTPS.
  • ISPs are required to keep certain records and may share them with authorities or third parties according to legislation and their policies.
  • A VPN encrypts your traffic and hides your activity from the ISP and the WiFi owner, although it transfers trust to the VPN provider.
  • Combining VPN, HTTPS, encrypted DNS, Tor, private browsers, and tracker blocking significantly reduces your digital footprint.

Privacy and data seen by the Internet provider

Most people connect to Wi-Fi at home, work, university, or a bar without stopping to think about what's happening "behind the scenes." Your internet provider, the router owner, and even some online services can know much more about you than you imagine, simply from your internet traffic.

Understanding what's being recorded, who can see it, and the extent of that surveillance is key to making informed decisions: from using a VPN or not, to choosing a specific browser or avoiding certain Wi-Fi networks. Let's take a step-by-step look at what your internet provider sees when you connect to the internet, what the Wi-Fi owner sees, and what you can do to reduce your digital footprint without driving yourself crazy in the process.

digital privacy
Related articles:
Digital privacy on the Internet

What your operator can actually see when you browse

Data your ISP sees when you browse

Every time you connect to the internet, you do so through a connection provided by your internet service provider (ISP). This provider assigns a public IP address to your router, and from then on, all your traffic passes through their equipment . This allows them to keep a fairly detailed record of your online activity.

The first thing your ISP records is your public IP address and the dates and times you use it . They know when you connect, how long you're online, and how much data you use. This alone allows them to profile your routines quite well : times of day, peak usage, whether you do a lot of streaming, online gaming, etc.

Furthermore, you almost always use your ISP's own DNS servers , because most users don't change those settings. Every time you type a website address (for example, "socialnetwork.com"), your device queries the DNS server to find the IP address that corresponds to that domain. These queries are usually unencrypted unless you use DNS over HTTPS (DoH) or DNS over TLS, so your ISP can see and keep a complete history of the domains you visit.

Through these DNS queries and other logs, the operator can determine if you use specific social networks, download via Torrent or Emule, use P2P, access streaming websites, forums, dating sites, or adult content . They don't need to spy on the content itself; knowing which domains you connect to is enough for them to create a profile of your interests.

Most modern web browsing uses HTTPS, which encrypts the content of what you send and receive. This means that if you visit a website with a padlock icon in your browser, your ISP can't see what message you type, what video you watch, or what form you fill out . However, they can see the domain (via DNS or the TLS connection itself) and the volume of data, allowing them to deduce quite a bit about your behavior on that website.

With all this, over time, a very detailed profile can be built of your tastes, your routines, your concerns and even your state of health or employment situation : searches about serious illnesses, job portals, forums on certain topics or very specific consumption patterns.

Legal obligations and use of that data by ISPs

Data retention by Internet providers

Not all activity logging is done because the operator wants to make money from your data. In many countries, laws require ISPs to retain certain traffic information for a specific period, usually ranging from several months to over a year, and even longer in some cases.

These records include, at a minimum, your assigned IP address at any given time, when you connected, for how long, and metadata related to those connections . This information may be requested by a judge, law enforcement agencies, or other public bodies as part of a criminal investigation, ranging from cybercrime to terrorism.

Cases like Edward Snowden's exposed mass surveillance programs where agencies like the NSA collected enormous amounts of traffic data with the collaboration of major providers. Legally, your traffic should only be thoroughly examined under a court order, but the technical reality is that the infrastructure to record and analyze large volumes of data already exists.

On the other hand, private companies aren't always required to specify how long they retain each type of data. The operator's privacy policy might indicate something, but once your data is sold, anonymized, or shared with third parties , it's very difficult to track what actually happens to it.

Furthermore, in terms of storage, DNS connection and request logs take up very little space , as they are essentially text. Storing years of history is perfectly feasible without incurring significant technical costs, although there would be legal limits.

  End-to-end encryption in Gmail: a complete and practical guide

What can the WiFi owner (university, company, someone else's house…) see?

Browsing history visible to the WiFi owner

In addition to the service provider, the person or entity managing the Wi-Fi router you connect to can see a lot of information about your activity. This applies to the network at your university or office, as well as to the Wi-Fi at a friend's house or in a public place.

Most routers keep a log of connected devices, connection times, bandwidth usage, and, depending on the model and configuration, even URLs visited or destination IP addresses . The administrator, by accessing the router's control panel, can view these logs and see your online activity.

If the corporate or university network also uses more advanced monitoring tools (proxies, OpenDNS-type systems, WireShark, deep inspection firewalls), part of computer security , they can have even more detail: search terms, exact websites, specific pages, time spent on each one and even block or filter content.

The popular "incognito mode" won't protect you from this. Private browsing only prevents your browser from saving your history and cookies on your device. But your router and network administrator will still see the requests going out to the internet and, therefore, will still be able to track your browsing history.

In corporate or educational environments, it is very common for network administrators to monitor and log which websites are visited for security, regulatory compliance, or productivity reasons . They may also use filters to block download sites, social media, adult content, or potential threats such as malware and phishing.

HTTPS, DNS and end-to-end encryption: what you see and what you don't

A common question is what the HTTPS padlock or end-to-end encryption of WhatsApp, Signal, and similar apps actually protects. End-to-end encryption (E2EE) applies to the message content, not to all connection metadata.

When you use a service with end-to-end encryption (E2EE), your messages are encrypted on your device and only decrypted on the recipient's. This means that even if the ISP or the Wi-Fi owner intercepts the traffic, they will only see a stream of encrypted data that they cannot read without the key . They will not see the message text, photos, or audio.

However, they will still be able to see that you connect to that service. Your device has to resolve the domain (for example, “api.whatsapp.com”) using DNS and then establish an encrypted connection with that server . Therefore, your carrier or Wi-Fi provider can tell that you are using WhatsApp and how much data you are transferring, although not the content.

DNS servers, if not encrypted, are a weak point. When you visit a website, your computer sends a DNS request to find the domain's IP address. If you use your internet service provider's DNS servers, they can log all those requests, even if the rest of your traffic is over HTTPS . And if you're on someone else's Wi-Fi network, the administrator can also see those requests.

This is where protocols like DNS over HTTPS (DoH) or DNS over TLS (DoT) come into play , encrypting DNS queries. If you use them with a provider other than your ISP, this filtering point is significantly reduced: your ISP can no longer easily see which domains you're resolving, only that you're communicating with the encrypted DNS server.

In short, HTTPS protects the content within the website, E2EE protects the content of your messages, and encrypted DNS protects which domains you're accessing . But neither makes you invisible: metadata such as connection time, packet size, and destination IP address still exist, allowing for the inference of a considerable amount of information.

What additional information is obtained through the browser

Beyond the internet service provider and the owner of the Wi-Fi, your own browser and the websites you visit are another massive source of data about you. Sometimes we give them permission almost without realizing it by accepting privacy policies and cookies.

Your browser collects information about your operating system, IP address, language, installed extensions, screen size, device type, CPU, GPU, and even details like battery status . Combining this data creates a unique "browser fingerprint" that can identify you even if you delete cookies.

If you also sync your browser with an account (for example, your Google account in Chrome), your browsing history, bookmarks, and tabs can be directly linked to your identity . This allows companies like Google or Meta to further personalize advertising, but it also means having a very detailed record of everything you do online.

Websites, for their part, use cookies , tracking pixels, and analytics scripts to track your visits, time spent on the site, clicks, form submissions, and conversions . Social networks like Facebook can track you even outside their website thanks to "Like" buttons, social login systems, and other elements embedded in thousands of sites.

  Complete Guide to Fraud and Deepfake Detection

It's relatively easy to deduce things like your political, religious, or sexual orientation, health problems, financial situation, or even personal crises from your browsing history . This isn't science fiction: it's used daily in advertising targeting and profile analysis.

How long can they keep your history and other data?

One of the biggest questions for users is: "How long is all this data stored?" The reality is that there's no single answer , because it depends on each country's legislation and each company's policy.

Internet service providers are usually legally required to keep certain traffic logs for a minimum period . This period can be six months, a year, or longer, and is often renewed if there is an ongoing investigation or specific requirements.

Beyond the strictly legal requirements, companies can retain anonymized or aggregated data for much longer for statistical analysis, market research, or product development . Once this data is shared with third parties, determining its lifespan becomes even more complex.

From a technical standpoint, since records are usually plain text, it's very easy and cheap to store enormous volumes of information for years . We're not talking about large videos, but rather strings with dates, IP addresses, domains, and little else. Therefore, it wouldn't be surprising if much of what you do online today could be searchable many years from now, at least at the metadata level.

And it's not just your computer. Any device connected to your network (mobile phone, tablet, game console, smart TV, smart speaker, IP cameras, etc.) generates traffic that's associated with your line. For the internet service provider, and often for the Wi-Fi owner, all of that is recorded under the same identity: you as the account holder.

Can your ISP stop tracking you if you ask them to?

The logical temptation is to think, "Well, I'll just call them and tell them I don't want them to record anything." In practice, this rarely works , because a large part of the records are in response to legal obligations or technical operational and security needs.

Some providers in certain countries offer "premium" privacy plans where they promise not to use your data for commercial purposes or to reduce the level of ad personalization, but that doesn't mean they stop tracking your activity altogether. They simply change how they use it and how they communicate this in their policies.

The minimum information about who connects, from where, when, and with what IP address will always exist, even if only to resolve issues, prevent fraud, detect network abuse, or comply with the law. No matter how much you request it, the operator isn't going to turn off all its logging systems just for you.

If you truly want to reduce what your ISP can see, the solution involves adding an extra layer of encryption between your device and the internet . This is where VPNs, Tor, and, to a lesser extent, encrypted DNS and specific privacy settings come into play.

What happens when you use a VPN: what your provider sees and what it stops seeing

A virtual private network (VPN) creates an encrypted "tunnel" between your device and a remote server . From the ISP's perspective, instead of seeing you connect to a thousand different websites, they only see you communicating with a specific VPN server.

When you connect, your internet service provider can see that you're connecting to an IP address belonging to a VPN service , the start and end times of the connection, the port the VPN protocol uses, and the amount of data you send and receive. They will also see that the content of that traffic is unreadable because it's encrypted.

What they no longer see is which websites you visit behind the VPN, which specific pages you open, what you search for, what files you download, or what forms you fill out . They also can't easily associate that traffic with your real location if the VPN gives you an IP address from another country. As far as the ISP is concerned, all that detail disappears behind the encrypted tunnel.

In other words, with a VPN, the operator can only detect: the VPN server's IP address, timestamps, data volume, and encrypted data flow . The final destination (the actual websites and services) becomes visible only to the VPN provider.

That's why it's so important to choose a reliable VPN with a genuine no-logs policy and a good reputation. Otherwise, you're simply changing who you give detailed information about your browsing to: from your ISP to your VPN provider.

Good commercial VPNs usually offer applications for computers, mobile devices, and sometimes even direct router configuration , so that all traffic from your local network is already encrypted and sent to the VPN, without needing to install anything on each device.

  CAPTCHA: What it is, what it is used for and how it works

VPN, HTTPS, Tor, and other tricks to reduce your digital footprint

If you're concerned about your privacy, you can combine several layers to make things more difficult for anyone trying to track you. Perfect total anonymity doesn't exist for everyone, but you can significantly improve the default situation.

The first, very basic step is to always try to use websites with HTTPS . This prevents the owner of the Wi-Fi or the internet service provider from seeing the content you exchange with the website (passwords, bank details, messages, forms), even though they can still see the domain. Extensions like HTTPS Everywhere (or those already integrated into many browsers) force this secure connection whenever possible.

The second layer is choosing privacy-focused search engines, such as DuckDuckGo or Startpage , which promise not to record your search history or create tracking profiles. This way, at least that part of your activity doesn't end up in the hands of online advertising giants.

For email, alternatives like ProtonMail or Tutanota offer end-to-end encryption and much stricter privacy policies than traditional free services. They don't remove all metadata, but they do make it considerably more difficult for third parties to access the content of your messages.

Another powerful tool is the Tor browser, which routes your traffic through multiple layers of nodes , making it very difficult to trace who you are and where you're connecting from. However, Tor is designed more for specific web browsing and can be slower; furthermore, some ISPs or services block it or monitor it closely.

Complement all of the above with browser extensions designed to block trackers and intrusive advertising , such as uBlock Origin or Privacy Badger. These significantly reduce the number of scripts and cookies that track you across websites, limiting advertising profiling and the creation of persistent digital fingerprints.

Additional risks: mobile networks, public WiFi, and high-profile cases

It might seem that using a mobile network instead of Wi-Fi would protect you. However, the reality is that your mobile operator fulfills the same role as a fiber or ADSL provider : it gives you an IP address, manages your traffic, and can see and record your connections just like any other ISP.

Furthermore, if you share your network (for example, with a mobile Wi-Fi hotspot), everything anyone connected to your Wi-Fi does will be associated with your connection . If someone gets into trouble using your connection, for example, to attack websites , it's very likely that yours will be the first one they try to track down.

Public Wi-Fi networks, such as those in airports, cafes, or shopping malls, are another sensitive area. The Wi-Fi provider can monitor traffic, record your connections, and, in some cases, even sell that data to advertisers to monetize the free service.

There have been high-profile cases where messages sent from a public network have led to arrests or serious investigations . A prime example is the young man arrested at an airport for sending a "joke" in a private chat about "blowing up the plane" using the airport's Wi-Fi, which triggered a major alert.

These kinds of situations make it clear that what you do online, however private you think it is, can be analyzed if it's considered a threat or evidence of a crime . And that browsing history and messages are routinely used as evidence in police investigations and trials.

This whole picture makes one thing pretty clear: every time you connect to the internet, you leave a technical trail that your internet provider, the Wi-Fi owner, your browser, the websites you visit, and, if necessary, the authorities can track, at least in some detail. Using a VPN, encryption, and privacy-friendly browsers and search engines doesn't make you invisible, but it does significantly reduce the amount of useful information that third parties can gather about you and allows you to regain some control over what you share (intentionally or unintentionally) every time you open a browser tab.