itzgee.com

What your internet provider sees — broadband and mobile

What your broadband and mobile providers can actually see now the web is encrypted, what happens to the logs, and what a VPN genuinely changes.

privacyispvpndnsmetadatatracking

Start by correcting the picture in most people’s heads. “My internet provider” is not one company. At home your traffic rides your broadband ISP. The moment you leave the house — or your Wi-Fi drops for thirty seconds — the same traffic rides your mobile carrier instead, and a carrier is just an ISP with masts. Everything below applies to both, and the mobile one sees more, because your phone tells it where you are simply by staying connected.

There is also no opting out of the category. You can refuse a loyalty card and delete an app. You cannot use the internet without someone carrying it.

What they can actually see

Here the news is genuinely better than a decade ago. Nearly all web traffic is now encrypted — the padlock is real. Your provider cannot read your messages, your searches, your passwords, or which page of a site you are on.

What remains visible is the wrapping. Think of it as envelopes: the letters are sealed, but every envelope shows an address, a time, and a weight.

Every destination. Before your device talks to any service it asks a directory where that name lives — the DNS lookup — and by default it asks a resolver your provider runs. Even when it does not, the secure connection itself announces the name of the site it is for during the handshake. Either way, the provider learns the domain: not which article you read, but that you visited the site, at 23:40, again at 23:55.

Rhythm and volume. When you are online, for how long, how much data moved, and to whom. Enough to tell a video call from a backup from insomnia.

On mobile, your position. The network must know which mast serves your phone — that is how calls reach you — so your carrier holds a continuous, approximate trail of where the phone has been, attached to an account verified with your name and bank details. No app permission is involved, and no setting turns it off.

Individually these are crumbs. Kept for months and read together, they are a diary written in envelopes: where you sleep, where you work, what you are worried about at 3am, which clinic you visited, and who else’s house your phone spends the night at.

one connection, from the provider's side
  1. 01 you open an app or a site the content is sealed — the padlock is real
  2. 02 the connection names itself the lookup and the handshake both say where you are going
  3. 03 the log fills every destination, with times and volumes — plus, on mobile, where you were standing
  4. 04 the log outlives the visit kept, analysed, and in the UK retainable for up to twelve months

They cannot read the letters. They keep every envelope. Metadata is the record of who you talked to, when, and how much — and it is most of what a life looks like from the outside.

The content is sealed and stays sealed. Everything on the outside of the envelope goes in the log — and the log is the product.

What gets done with it

This is not hypothetical, because regulators have already been through the filing cabinets.

In 2021 the US Federal Trade Commission examined six major providers covering most of the American market. Its findings: providers combining web-browsing data with app usage and personal details to target advertising, sorting customers into sensitive categories including race and sexual orientation, sharing real-time location with third parties — several of them running their own advertising businesses on the side, with the disclosures buried in the fine print.

The carriers’ record is worse. In 2024 the US regulator fined the four big American networks nearly $200 million for selling access to customers’ real-time location to data aggregators, who resold it onward — a chain uncovered when a sheriff was found using one such service to track phones without warrants.

Those are American cases, and worth being precise about: UK law does not permit that kind of open market in browsing histories, and no such scandal attaches to UK ISPs. What Britain has instead is stranger.

The British version: a log kept by law

Under the Investigatory Powers Act 2016 — the law campaigners nicknamed the Snoopers’ Charter — the Home Secretary can serve a provider with a retention notice requiring it to keep up to twelve months of every customer’s “internet connection records”: which services each connection touched, and when. Not page content, not full addresses — the envelope log, held for a year, queryable by a long list of public bodies. Which providers hold live notices is itself not public, though trials of the collection system with major ISPs have been reported since 2021.

So the honest UK summary is: your provider is probably not selling your history — and is potentially required to keep it, in case somebody with the right paperwork asks. Whether that reassures you or not is a personal question. It should at least be a question you know exists.

What a VPN changes here — and what it does not

A VPN is the one tool aimed squarely at this watcher, and against this watcher it genuinely works. With the tunnel up, your provider’s log of you collapses to a single entry: one encrypted stream, to one address, of some volume. No domains. No per-site timeline. The envelope log goes blank.

Three honest caveats, each with its own longer treatment on this site.

“Properly configured” is doing real work in that sentence. If your device’s name lookups slip outside the tunnel, your provider gets the full list of sites back — a sealed box with a postcard of destinations alongside it. That failure is common and silent; what a VPN does not hide covers it, and the DNS leak suite tests your own setup in half a minute.

Mobile keeps one thing regardless. The carrier still knows where the phone is — that is radio, not internet, and no tunnel touches it. A VPN blanks the browsing log; the location trail stays.

You have swapped watchers, not removed watching. Whoever runs the far end of the tunnel now stands where your ISP stood. With a commercial VPN that is a company you take on faith. This is the argument for the tunnel ending on hardware you control: run your own exit and the answer to “who sees my traffic now” is you.

And once the far end is yours, something better than hiding becomes possible: the resolver inside the tunnel can be your own, with the tracking and advertising domains simply removed from the phone book — the network-level filtering covered in why an ad blocker is not enough. That is how this network runs: every device carries the tunnel, every lookup is answered by our own filtering resolver, and the provider’s view is one opaque stream. The architecture is documented on /mesh.

Being fair about it

Your provider is not an enemy. It needs some of this data to function — routing, capacity planning, fault-finding, stopping abuse — and the overwhelming majority of what it carries is never looked at by anyone. UK providers in particular operate under data protection law that their American counterparts spent years lobbying to avoid.

The objection is narrower and sharper: retention beyond need, monetisation you never meaningfully agreed to, and a legal regime that treats a year of everyone’s envelope log as a reasonable default. None of that requires your provider to be malicious. It only requires the log to exist — and logs that exist get used.

You cannot choose whether your traffic passes through someone else’s hands. You can choose what those hands can see — and one well-configured tunnel, ending somewhere you trust, reduces it to almost nothing.

more in privacy

← back to blog more in privacy →