Direct answer: what a VPN can and can’t see

A VPN can track some aspects of your activity, mainly because it becomes a middle point between your device and the internet. Even if your browsing content is encrypted in transit, the VPN provider may still be able to observe things like your connection timing and the destination domain or IP address.

At the same time, a VPN does not automatically “know everything” about your actions on your device. It generally can’t decrypt and read the contents of HTTPS traffic end-to-end the way the destination website can, because encryption is handled between your device and the website.

Because there are different implementations and provider policies, the practical difference comes down to what the VPN chooses to log, how long it retains those logs, and what protections it applies.

A simple model: where “seeing” can happen

Think of your VPN usage as three vantage points:

  1. Your device: your browser, apps, and operating system can record activity locally, and they may also send data to websites or services even while using a VPN.
  2. The VPN connection: the VPN server can usually see that your device connected, when it connected, and where the encrypted traffic is going (often at the destination level).
  3. The destination service (website/app): the destination can see your IP address (the VPN exit address) and can track your session through normal web mechanisms.

So, a VPN can reduce what the network between you and the VPN (and often other intermediaries) can see, but it doesn’t eliminate every form of observation.

Key limitations and exceptions

Two important limits change the outcome:

  • Logging vs. non-logging: Some VPN services advertise limited logging, but you still need to verify the provider’s stated logging approach and how it treats data over time. Without that, “track” can mean different things.
  • Accounts and identifiers: If you log into websites, use ad identifiers, or reuse device/browser profiles, those services can track you regardless of VPN use.

Also, note that “activity” can mean different categories: browsing content, search terms, metadata (timing/destination), and account-level identifiers. A VPN may affect some categories more than others.

What you can check to judge tracking risk

You can’t reliably determine what any VPN does just from the concept, but you can check for these signals:

  • Logging statements: Look for clear descriptions of what is recorded (for example, connection metadata) and whether it is retained.
  • Retention and deletion: If a provider discloses retention periods or deletion practices, that can help you understand the window of observability.
  • Data types: Prefer explanations that distinguish content visibility from metadata visibility.
  • Your own exposure: Review what your browser and apps may store or transmit while using a VPN (cookies, logins, device identifiers).

If you want a safer privacy posture, the focus is on minimizing unnecessary identifiers on your device and understanding what the VPN provider does with connection-level data.