FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

Incognito Mode Plus a VPN Didn’t Make Me Anonymous—But One Setup Left Less to Link Back

The page did not fail to load. It stopped me with an age-check screen asking for a face scan or identity document before I could read an adult forum thread about a medication side effect—something I did not want connected to my ordinary accounts. I opened an Incognito window, switched on the large VPN I already paid for, chose a New Zealand server and refreshed. The gate disappeared. That should have felt like success. Instead, I noticed the email address displayed inside the VPN app, the forum’s login button and the advertising scripts waking up around the page. I had changed my location, but had I actually separated the visit from my identity?

The timing of that question was not accidental. Australia’s latest Age-Restricted Material Codes took effect on March 9, 2026, expanding age-assurance obligations across social media, designated internet services, electronic services and other parts of the online ecosystem. The day before, downloads of major VPN apps were nearly three times the previous daily average.

It was tempting to describe the surge as people simply trying to bypass restrictions. But that missed the more personal concern. Many adults were not objecting to being over 18. They were objecting to proving it by handing a face image, identity document or biometric estimate to a site—or to a verification vendor they had never encountered before.

Australia’s privacy regulator has acknowledged that age-assurance systems may involve personal or sensitive information moving through several organisations. Its guidance tells services to minimise collection, explain who handles the information and destroy identity documents or biometric inputs when they are no longer required.

That context clarified the task in front of me. I was not trying to become invisible to every possible observer. I wanted to read one sensitive page without saving it in my laptop history, revealing my home IP address to the site, uploading identification or creating another account tied to my usual email address.

The short answer

Incognito protected the local browsing record. Both VPNs replaced the home IP address. The difference was what happened before and after the connection: one route began inside an account already linked to my ordinary identity; the other let me reach the page without requiring another conventional registration and then reduced some of the page’s background tracking requests.

Incognito Solved Only the Problem Beside Me

Incognito mode was useful, but in a much smaller way than its name suggests.

It created a separate browser session. When I closed all the Incognito windows, Chrome would remove the session’s local history, cookies and site data from the device. That protected me from someone later opening the laptop and seeing what I had read.

It did not hide the session from the website, the services embedded in the page, the organisation managing the network or the internet provider. Google says this directly in its own Incognito documentation.

The VPN handled another part of the problem. It sent my connection through an encrypted tunnel to a remote server. My internet provider saw the connection to the VPN, while the forum saw the VPN server’s IP address rather than my home address.

Together, the two tools had done something worthwhile: one reduced traces on the laptop, and the other replaced the IP address visible to the destination.

The mistake was assuming those two changes added up to anonymity.

I was still using the same browser configuration, screen size, time zone, language settings and operating system. Those details can be combined into a browser fingerprint. Cookies are an easy way to recognise a returning visitor, but they are not the only way.

EFF’s Cover Your Tracks project explains the distinction neatly: private browsing was designed primarily to stop visited pages from being stored on the machine. It was not designed to stop websites and remote trackers from recognising the browser.

So Incognito had removed one obvious label. It had not made the browser itself unrecognisable.

Changing Countries Did Not Erase the Rest of the Device

The Australian age-restriction guidance made that gap harder to ignore.

Platforms trying to determine whether someone normally lives in Australia may consider more than an IP address. They can also look at GPS information, device language, time settings, phone numbers, account history and other persistent signals. A VPN can change the apparent network location without rewriting the rest of the device.

This did not mean my VPN had failed. It had opened the page quickly, and its large support operation and broad server selection were real advantages.

But the account panel still showed my normal email address. I had paid for the subscription using an ordinary payment method. If I signed into the forum, reused a familiar username or disclosed personal details in a post, the overseas IP would not cancel those decisions.

That was the moment the comparison changed for me. I no longer cared only about whether a service could replace my IP address. I cared about how many new connections to my identity I had to create before it would do so.

A public VPN discussion captured the same confusion in a few lines: the original poster assumed that Incognito plus a VPN sounded close to anonymous, while the replies pointed out that the two tools address different observers and still leave accounts…


Fewer Identity Links Mattered More Than More Locations

Once I started counting identity links instead of server locations, the next option made more sense.

I opened OnlydogVPN and selected a situation-based option for restricted access rather than choosing from a long map of countries. More importantly for this task, basic use did not begin with an email-and-password registration screen.

I returned to the forum and refreshed.

The age gate was gone. The thread loaded. I read the discussion I had come for without uploading a document, creating a forum account or attaching another conventional VPN login to my normal email address.

That was the result I had actually needed.

The service’s HTTP/3-based transport and added traffic obfuscation helped the connection reach the page under the filtering conditions in front of me. The protocol explanation mattered less than the sequence I could see: the first page had demanded more identity information; the new route opened it without adding another registration step.

After I finished reading, I clicked into a related health article. That was when I noticed the blocked-request counter increasing.

The page was attempting to contact advertising and tracking services in the background, and the smaller app was stopping some of those requests. I could not independently inspect its internal filtering rules, so I treated the counter as a practical indication of blocked connections rather than proof that every tracker had been removed.

Even with that limit, the benefit fitted the problem. Replacing an IP address while allowing every advertising and tracking request to run would have left more organisations observing the same sensitive session. Blocking some of those requests reduced the number of outside parties involved after the main page had already opened.

This was not another claim of anonymity. It was a cleaner chain:

The laptop would not retain the Incognito history. The forum did not receive my home IP address. I had not supplied an ID document. I had not created a new email-based VPN account. Fewer third-party requests completed in the background.

None of those protections was absolute on its own. Together, however, they addressed the actual ways this particular visit could become linked back to me.

Why the Larger VPN Was Not the Better Fit

The established provider still had more server locations, a longer public history and far more independent reviews. Those advantages would matter to someone who regularly needs unusual countries, extensive customer support or years of public scrutiny.

The smaller service has fewer locations and a shorter track record. That is a real limitation, not a cosmetic one.

But neither limitation stopped me from completing the task that had brought me to the article. The large provider’s server map had offered many possible routes; what it had not offered was a way to begin without another familiar account relationship.

For general travel, that difference might not decide the purchase. For a sensitive, age-gated search, it did.

The decisive question was no longer, “How many countries can this VPN make me appear to be in?”

It was, “How much new identifying information must I provide before I can reach the page privately?”

Anonymous Is Still a Bigger Claim

Someone protecting sources, reporting wrongdoing or facing targeted surveillance should not treat any commercial VPN and private browser window as a complete anonymity system.

Tor Browser is built for a different threat level. It routes traffic through multiple relays and includes protections intended to make users’ browsers harder to distinguish from one another. Even then, signing into a personal account or revealing identifying information can connect the activity back to the person behind it.

My problem was narrower. I was an adult trying to read a sensitive page without turning that moment into an identity transaction.

Incognito protected the local browsing record. Both VPNs replaced the home IP address. The difference was what happened before and after the connection: one route began inside an account already linked to my ordinary identity; the other let me reach the page without requiring another conventional registration and then reduced some of the page’s background tracking requests.

So, does Incognito mode plus a VPN make you anonymous?

No. It changes what different observers can see, but it does not erase browser signals, account logins, personal disclosures or the relationship with the VPN itself.

The useful comparison was not anonymity versus no anonymity. It was how much unnecessary identity the setup asked me to expose.

For this age-gated search, the better tool was not the one with the most places to hide my IP. It was the one that opened the page while giving me fewer new ways to identify myself.

Questions this experience may leave you with

What was actually causing the problem?

Incognito protected the local browsing record. Both VPNs replaced the home IP address. The difference was what happened before and after the connection: one route began inside an account already linked to my ordinary identity; the other let me reach the page without requiring another conventional registration and then reduced some of the page’s background tracking requests.

Why did the obvious fixes fail?

A public VPN discussion captured the same confusion in a few lines: the original poster assumed that Incognito plus a VPN sounded close to anonymous, while the replies pointed out that the two tools address different observers and still leave accounts…

What should you check first?

Platforms trying to determine whether someone normally lives in Australia may consider more than an IP address. They can also look at GPS information, device language, time settings, phone numbers, account history and other persistent signals. A VPN can change the apparent network location without rewriting the rest of the device.

What finally changed the result?

The laptop would not retain the Incognito history. The forum did not receive my home IP address. I had not supplied an ID document. I had not created a new email-based VPN account. Fewer third-party requests completed in the background.

What is worth remembering?

Tor Browser is built for a different threat level. It routes traffic through multiple relays and includes protections intended to make users’ browsers harder to distinguish from one another. Even then, signing into a personal account or revealing identifying information can connect the activity back to the person behind it.