The adult site had not even opened when my email notification appeared.
Welcome—confirm your new VPN account.
I was spending three weeks in a furnished flat in Manchester, using Wi-Fi managed by the landlord. My partner had sent me a private video link, and I did not want the destination mixed into the building network’s ordinary traffic records.
A VPN seemed like the obvious precaution.
I installed a large, familiar provider, created an account with my personal email address, confirmed the login, and selected a nearby server. The app turned green.
Then I opened the link.
Instead of the video, the site asked me to prove that I was over 18. The choices included a facial age estimate and an identity-document check.
I changed the VPN location and refreshed.
The age screen disappeared, but a proxy warning replaced it.
Another server produced a CAPTCHA. The next returned me to the verification screen.
Ten minutes earlier, I had thought private adult browsing meant turning on a VPN before opening the page. Now I had created a named account, joined a heavily shared server, and started rotating through countries while the original link remained unopened.
The connection was encrypted.
The experience did not feel private.
The short answer
Ten minutes earlier, I had thought private adult browsing meant turning on a VPN before opening the page. Now I had created a named account, joined a heavily shared server, and started rotating through countries while the original link remained unopened.
Opening the page now involves another privacy decision
Since July 25, 2025, UK services that allow pornographic content have been required under the Online Safety Act to use highly effective age assurance. Ofcom has continued enforcing those requirements, including investigations and financial penalties against operators that failed to introduce compliant checks. (Ofcom)
That means an adult visitor may encounter facial age estimation, photo-ID matching, credit-card checks, mobile-network confirmation, open-banking checks, or a digital identity service before the content appears. (Ofcom)
These methods do not all collect the same information. A facial estimate may analyse an image only long enough to estimate an age range. An ID process may handle a passport, date of birth, photograph, and document number.
UK data-protection guidance says providers should collect only what is needed, explain who receives it and how long it is retained, and avoid keeping an identity document when a simple over-18 result is enough. (Org)
The problem is that those explanations are rarely the first thing a visitor sees.
The camera and ID buttons occupy the centre of the screen. The retention policy sits behind a smaller link. A person expecting a private few minutes suddenly has to evaluate another company and decide whether its promise to delete a face image or document is clear enough.
Public discussions show that the uncertainty often lasts longer than the check itself, especially when a failed face estimate leads to an ID request. (Reddit)
That was exactly the decision I had not expected to make before opening the link.
My first VPN protected the route, not the whole session
The established provider was doing one important job correctly.
Its encrypted tunnel prevented the shared Wi-Fi from directly seeing the destinations carried through it. (Eff) On a connection managed by someone else, that mattered.
But the VPN had already collected my email address before the private session began. The adult site could still use its own cookies and browser storage. Advertising systems could still send tracking requests through the protected connection. Signing into an existing account would identify me regardless of which public IP address appeared at the exit. (Eff)
That was the gap in my original comparison.
I had judged VPNs by server count and whether an IP-checking page displayed another city. Those details proved that the route had changed. They did not tell me how much identity the VPN required, whether the destination would accept its exits, or how many other services would surround the page afterward.
The first provider had an impressive network, years of public history, many independent reviews, and a large support operation.
Those were meaningful strengths.
They did not answer the question that now mattered most: how little information would I have to expose before this private session could begin?
The server list became part of the problem
I returned to the provider’s location menu.
Ireland produced the proxy warning. Belgium loaded the front page but not the video. The Netherlands triggered a CAPTCHA and then returned me to the age screen.
Each switch changed the public IP address. It also added another abrupt location change to the same browser session.
The site saw a sequence of familiar shared exits. My browser continued carrying the same cookies. The VPN account remained attached to the email address I had just confirmed.
I could clear the browser, read the verifier’s full privacy policy, or continue testing countries. All three were possible.
None resembled the quick, private visit I had intended.
A large network is useful when someone needs a precise country or several alternatives during an outage. Here, the alternatives had become the work. I was no longer browsing; I was managing exits.
That changed the comparison.
For private adult browsing, dozens of available routes mattered less than one accepted route that did not begin by creating another identity record.
The smaller app did not begin with my email address
I closed the first provider and opened OnlydogVPN.
Basic use did not require a conventional email-and-password account. There was no confirmation message, named profile, or password-reset trail to create before connecting.
That removed an unnecessary link between the session and my everyday identity before the page had even opened.
The interface also began with situations rather than a wall of server locations. I selected the option intended for a service that was restricting or challenging ordinary VPN traffic.
Then I opened a fresh private window and pasted the original link.
The age-verification screen did not appear.
Neither did the proxy warning.
The video page loaded. I started playback, moved forward several minutes, and switched to full screen.
It continued playing.
I opened another page on the same site and returned to the video. The session remained usable.
The result came before the explanation: I had reached the content over the shared flat Wi-Fi without uploading an identity document, submitting a face scan, or creating a conventional VPN account.
The service uses an obfuscated, HTTP/3-based connection. Put simply, its route passed where the familiar shared exits had been challenged.
The first provider had offered more choices. The smaller app required fewer disclosures and completed the task.
The page itself was still trying to invite others
After the video ended, I opened the site’s privacy settings.
The app’s blocked-request counter began increasing.
The page was contacting services beyond the content I had intentionally requested. Some matched advertising and tracking systems and were filtered before they completed.
This was a different layer of privacy.
The VPN tunnel limited what the shared Wi-Fi could learn about the destination. The changed IP separated the visit from the flat’s ordinary public address. Filtering reduced some of the outside services joining the page after it loaded.
I could see the counter changing, but I could not inspect the service’s internal filtering rules or determine the purpose of every blocked request.
That smaller discovery gave me a reason to leave the app installed. The accepted route had solved the immediate access problem; the filtering made later sessions cleaner without requiring another extension or settings page.
Private mode made more sense once the VPN worked
I had previously treated private browsing mode as a weaker substitute for a VPN.
Used together, they handled different parts of the session.
The private window prevented the new visit from automatically reusing ordinary site cookies and removed its local history when I closed it. The VPN protected the traffic crossing the shared network and changed the public address seen by the destination. The filtering reduced some unnecessary advertising and tracking requests.
The useful sequence was simple:
Connect before opening the page. Start with a fresh browser session. Avoid signing into an account unless it is necessary.
That sequence worked because the smaller app did not make account creation or server research the first step.
Instead of asking me to build a privacy setup, it let me begin the private session.
The limitation did not change the comparison
The service has fewer server locations, a shorter public history, and fewer independent ratings than the established provider I tried first.
Someone who regularly needs a particular exit city or values a longer record of third-party assessments may still prefer the larger company.
Those were not the needs that brought me to the app that evening.
I needed the shared Wi-Fi to stop seeing the destination. I wanted the VPN setup to avoid collecting another routine identity. I needed the adult site to accept the route. Once the page opened, I wanted fewer outside trackers surrounding the session.
The established provider encrypted the connection but added an account and left me testing shared exits. The smaller app asked for less at the beginning, reached the page, and reduced some of the background tracking afterward.
For private adult browsing, the most useful VPN was not the one that offered the largest map.
It was the one that let the private visit begin before asking me to reveal more of myself.
Questions this experience may leave you with
What was actually causing the problem?
Ten minutes earlier, I had thought private adult browsing meant turning on a VPN before opening the page. Now I had created a named account, joined a heavily shared server, and started rotating through countries while the original link remained unopened.
Why did the obvious fixes fail?
For private adult browsing, dozens of available routes mattered less than one accepted route that did not begin by creating another identity record.
What should you check first?
But the VPN had already collected my email address before the private session began. The adult site could still use its own cookies and browser storage. Advertising systems could still send tracking requests through the protected connection. Signing into an existing account would identify me regardless of which public IP address appeared at the exit. ( Eff ) (Eff)
What finally changed the result?
That smaller discovery gave me a reason to leave the app installed. The accepted route had solved the immediate access problem; the filtering made later sessions cleaner without requiring another extension or settings page.
What is worth remembering?
For private adult browsing, the most useful VPN was not the one that offered the largest map.