Privacy From Whom? The Five Observers a VPN Treats Differently

There is no such thing as a more private VPN in general, because privacy here is not a single quantity that a service can have more of. It is at least five separate relationships, and a tunnel changes each one in a different direction — improving two, relocating two, and leaving the fifth entirely to whoever you hired. Asking “which is best for privacy” collapses five questions into one, which is why the answers you find are so uniformly unfalsifiable.

This page does not rank providers and names none. What it does is take the five apart, so you can see which of them your situation actually turns on.

Observer one: who can read what you send

Contents are the observer people worry about first and the one a tunnel has least to do with. Most traffic today is already encrypted between your device and the service you are talking to, so the network in front of you cannot read it either way. What a tunnel adds is a second wrapper over the part of the journey between your device and the exit.

The consequence is that the exit operator does not get to read your traffic contents any more than your access provider could. Where a tunnel genuinely helps is with anything still unencrypted, and with the plaintext scraps that survive on the outside of encrypted connections — most notably the hostname that is visible while a connection is being set up.

So: improved slightly, moved not at all, and rarely the reason anyone should be choosing.

Observer two: who can connect an address to a person

This is the observer a tunnel is actually built for, and it is the one where the improvement is real. A service you connect to records an address. Without a tunnel that address belongs to your household or your mobile carrier and is linkable to you by anybody who can ask the party that assigned it. With a tunnel it belongs to the operator and is shared, often widely.

Two things limit the improvement. The first is that the operator holds the mapping between the borrowed address and your account, so linkability has not vanished — it has been consolidated into one place that you selected. The second is that an address is only one of the ways you are recognised, and usually the weakest: an account you sign into identifies you immediately regardless of where the packets came from.

Observer three: who keeps a record of what you did

Visibility and retention are different questions, and conflating them is the most common mistake in this subject. Your access provider can see connection destinations whether or not it stores them. So can an exit operator. The privacy consequence depends almost entirely on what is written down and for how long.

A tunnel changes who is in a position to keep that record. It does not, by itself, change whether anyone does. What a retention promise can and cannot mean is set out in what a no-logs VPN is, and the difference between a policy that says nothing is stored and an architecture in which the record is never produced is the substance of VPN logging policies explained.

Observer four: who can require those records to be handed over

Records that exist can be demanded, and the demand goes to whoever holds them. Before a tunnel, that is your access provider, under the rules of the place it operates in. After, it is the exit operator, under the rules of the place it operates in. You have not removed the possibility of compulsion; you have changed which legal system is involved and which company receives the request.

Whether that is an improvement depends on facts about the operator, not on anything a tunnel does. There are categories of question worth understanding here — where the entity is established, what kinds of process it can be served with, whether it publishes anything about requests it has received — and the shape of them is described in VPN jurisdiction and the Five Eyes, explained. No page on this site states what the law is anywhere; that is a question for official sources in your own country.

Observer five: who owns the company

The fifth observer is the one nobody searches for and the one that determines the other four over time. A provider is a business with owners, and owners set the incentives that decide what gets logged, how a demand is answered, and what happens to accumulated data if the business is sold.

This is where a funding model matters more than any feature. A service whose revenue comes from subscriptions has an interest in the promises it made. A service whose revenue comes from somewhere you cannot see has an interest you cannot inspect. And ownership changes: the company you evaluated may not be the company holding your records in three years, which is the single most under-weighted fact in the category.

Which of the five you can actually check

Sorting the observers is more than half the work, but it is worth knowing how far your own verification can reach, because it varies enormously between them.

Observers one and two are largely checkable by you, on your own device, this evening. You can see whether name resolution goes through the tunnel, whether the other address family is carried or silently escapes, and what address a service reports back. That is ordinary diagnostic work and no permission is required for it.

Observer three is not checkable by you at all. Absence of a record cannot be observed from outside; the strongest available evidence is a narrow, dated examination by a third party, and what such an examination does and does not establish is described in what a VPN audit is.

Observers four and five are checkable but not testable. They live in documents: registrations, terms, corporate filings, and whatever the operator has published about demands. Reading those is unglamorous and is where most of the real signal sits.

Why no provider is graded here

Grading anybody on this would mean asserting things about observers three, four and five that we are in no position to assert. We have not used these services, have not inspected anyone’s systems, and cannot verify a retention claim from outside — nobody can. A ranking would therefore be an ordering of unverifiable promises, and dressing promises as findings is precisely the move that makes privacy roundups worthless to the people who most need them.

Worse, a single score would have to average the five observers together, hiding the only useful information: that most readers care intensely about one of them and not at all about the rest.

Putting it to work

Decide which observer your situation is about, then act accordingly. If it is one or two, this is a technical question you can settle yourself. If it is three, four or five, no test you run will help and the work is documentary. Doing both because a page told you to is how people end up paying for reassurance instead of privacy.