“My internet provider” isn’t one company. At home your traffic goes through your broadband provider (your ISP). The moment you leave the house, or your Wi-Fi drops for thirty seconds, the same traffic goes through your mobile network instead, and a mobile network is just an ISP with phone masts. Everything below applies to both. The mobile one sees more, because your phone tells it where you are just by staying connected.
You also can’t opt out of this. You can refuse a loyalty card and delete an app. You can’t use the internet without someone carrying your traffic.
What they can actually see
The news here is better than it was ten years ago. Nearly all web traffic is now encrypted, and the padlock is real. Your provider cannot read your messages, your searches, your passwords, or which page of a site you’re on.
What stays visible is the wrapping. Think of envelopes: the letters are sealed, but every envelope shows an address, a time and a weight.
Every destination. Before your device talks to any service, it asks a directory where that name lives. This is the DNS lookup, and by default your device asks a directory run by your provider. Even when it doesn’t, the secure connection says the site’s name out loud as it’s set up. Either way, the provider learns the site: not which article you read, but that you visited, at 23:40, and again at 23:55.
Timing and amount. When you’re online, for how long, how much data moved and where to. Enough to tell a video call from a backup from a sleepless night.
On mobile, where you are. The network has to know which mast is serving your phone, because that’s how calls reach you. So your mobile network holds a constant, rough trail of where the phone has been, linked to an account checked against your name and bank details. No app permission is involved, and no setting turns it off.
On their own, these are crumbs. Kept for months and read together, they’re a diary written on envelopes: where you sleep, where you work, what worries you at 3am, which clinic you went to, and whose house your phone spends the night at.
- 01you open an app or a sitethe content is sealed. The padlock is real
- 02the connection names itselfthe lookup and the connection setup both say where you are going
- 03the log fillsevery destination, with times and amounts. On mobile, where you were standing too
- 04the log outlives the visitkept, studied, and in the UK can be held for up to twelve months
They cannot read the letters. They keep every envelope.Metadata is the record of who you talked to, when, and how much. It is most of what a life looks like from the outside.
What gets done with it
We don’t have to guess, because regulators have already looked.
In 2021 the US Federal Trade Commission examined six major providers covering most of the American market. It found providers combining browsing data with app use and personal details to target adverts, sorting customers into sensitive groups including race and sexual orientation, and sharing live location with other companies. Several ran their own advertising businesses on the side, with the details hidden in the small print.
The mobile networks’ record is worse. In 2024 the US regulator fined the four big American networks nearly $200 million for selling access to customers’ live location to data brokers, who sold it on again. It came to light when a sheriff was found using one of these services to track phones without warrants.
Those are American cases, so to be precise: UK law doesn’t allow that kind of open market in browsing histories, and no such scandal has hit UK ISPs. What Britain has instead is stranger.
The British version: a log kept by law
Under the Investigatory Powers Act 2016 (the law campaigners nicknamed the Snoopers’ Charter), the Home Secretary can order a provider to keep up to twelve months of every customer’s “internet connection records”: which services each connection reached, and when. Not page content, not full web addresses, but the envelope log, kept for a year, and open to requests from a long list of public bodies. Which providers have these orders isn’t public, though trials of the collection system with major ISPs have been reported since 2021.
So, in the UK: your provider is probably not selling your history, and may be required to keep it in case somebody with the right paperwork asks. Whether that reassures you is up to you.
What a VPN changes here, and what it doesn’t
A VPN is the one tool aimed directly at this watcher, and against it, it works. With the tunnel on, your provider’s log of you shrinks to one entry: one scrambled stream, to one address, of some size. No sites, no timeline. The envelope log goes blank.
There are three catches, each covered elsewhere on this site.
It only works if it’s set up properly. If your device’s name lookups slip outside the tunnel, your provider gets the full list of sites back: a sealed box with a postcard of destinations alongside it. This is common and silent. What a VPN does not hide covers it, and the DNS leak suite tests your own setup in half a minute.
Mobile keeps one thing whatever you do. The mobile network still knows where the phone is. That’s radio, not internet, and no tunnel touches it. A VPN blanks the browsing log. The location trail stays.
You’ve swapped watchers, not removed them. Whoever runs the far end of the tunnel now stands where your ISP stood. With a paid VPN service, that’s a company you have to trust. This is the case for ending the tunnel on equipment you control: run your own exit, and the answer to “who sees my traffic now?” is you.
Once the far end is yours, you can do more than hide. The directory inside the tunnel can be your own, with tracking and advertising sites simply taken out of the phone book. That’s the network-level filtering covered in why an ad blocker is not enough. It’s how this network works: every device uses the tunnel, every lookup is answered by a filtering directory we run, and the provider sees one sealed stream. How it fits together is explained on how it works.
In fairness to the provider
Your provider isn’t an enemy. It needs some of this data to work: routing traffic, planning capacity, finding faults, stopping abuse. Almost everything it carries is never looked at by anyone. UK providers in particular follow data protection law that their American counterparts spent years lobbying to avoid.
The complaint is narrower and sharper: keeping data longer than needed, making money from it in ways you never really agreed to, and a law that treats a year of everyone’s envelope log as normal. None of that needs your provider to mean harm. It only needs the log to exist, and logs that exist get used.
You can’t choose whether your traffic passes through someone else’s hands. You can choose what those hands can see. One well set-up tunnel, ending somewhere you trust, cuts it down to almost nothing.