FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

I Used a VPN to Avoid an ID Check—Then Asked What the VPN Could See

The age-check page wanted a facial scan or proof of identity. I closed it, installed a familiar VPN, connected through another country and reopened the site. It loaded immediately. Then I switched to my banking tab, noticed the VPN icon still glowing in the menu bar and stopped with my cursor over the password box. I had hidden those destinations from my broadband provider—but had I simply handed them to a company I knew even less about? The app offered several versions of “no logs,” yet none answered the question bothering me: what could the VPN see before anyone decided whether to save it?

I had installed the VPN to avoid sharing more personal information. Now I was wondering whether the workaround had created a different privacy problem.

That sequence has become increasingly common in the UK. Stronger age-assurance requirements took effect across many online services on 25 July 2025, and VPN use rose sharply afterward. A UK government consultation published in July 2026 noted that daily use had more than doubled during the initial surge.

The increase was not driven only by people trying to open restricted content. Research into the rollout found that distrust of identity checks and surveillance was a major reason people began searching for VPNs. Many users rejected one request for personal data, installed a new network intermediary within minutes and considered the trust question only after the page had opened.

I had done exactly that.

The short answer

The increase was not driven only by people trying to open restricted content. Research into the rollout found that distrust of identity checks and surveillance was a major reason people began searching for VPNs.

What Moves When You Turn On a VPN

The technical answer was simpler than the privacy policies made it sound.

Without a VPN, my broadband provider carries my traffic toward the websites and services I use. Once I connect to a VPN, the provider mainly sees an encrypted connection between my device and the VPN server. The destinations inside that tunnel are no longer directly visible to it.

But the tunnel has another end.

At the VPN server, the traffic must leave the tunnel and continue toward the bank, news site, health portal or messaging service I opened. The VPN operator therefore occupies the position my broadband provider previously held. It handles my original IP address when I connect, along with details such as session timing, data volume and the online services contacted.

That does not give the operator a readable copy of everything on my screen.

HTTPS still protects the contents of most modern websites after the traffic leaves the VPN server. The operator can see that a connection is going to a bank, for example, but it cannot simply open the encrypted session and read the password, balance or transfer details. The same principle applies to encrypted messages and other protected web traffic.

Even so, destinations can be revealing. Repeated connections to a fertility clinic, debt-advice organisation, addiction service or political group can expose a private pattern without revealing a single page of text.

Domain lookups can add more context. Before a site opens, the device usually needs to find the server associated with its domain name. Depending on how the connection is configured, the VPN service or a DNS resolver may handle that request.

So the answer to “Can my VPN provider see what I do online?” is not “everything,” but it is certainly not “nothing.”

A provider sits in a position where it can observe useful connection metadata. The real decision is whether I want that position occupied by a service already tied to my everyday identity.

Why “No Logs” Was Not Enough

The first VPN I installed was a well-established provider. It had years of public history, a large server network and extensive privacy documentation. Those were reassuring qualities.

Using it still began with an email address, a password, a payment and a persistent device login.

None of those details proved that the provider was keeping a browsing record. They did, however, give the service a ready-made customer identity before I sent any traffic through it.

I opened the privacy policy and searched for activity, connection, diagnostic, analytics and retention. Each answer led to another definition or exception. By the time I reached the service-improvement section, I could no longer remember which data was collected automatically, which was optional and which belonged to a separate product.

Public discussions reflect the same frustration: users understand that a VPN shifts trust away from an ISP, but then become trapped comparing audits, jurisdictions and long “no-log” explanations that are difficult to translate into an ordinary decision.

That was the moment my question changed.

Instead of asking which company had written the strongest promise about not connecting activity to me, I began asking how much identity a service needed from me in the first place.

A policy matters. So do audits and a provider’s history. But collecting less identifying information before the connection starts makes the privacy promise easier to rely on.


Connecting Without Building Another Identity

That was why I tried OnlydogVPN.

I opened the smaller app expecting another registration screen. Instead, basic use did not require an email address and password. I selected a privacy-oriented preset, connected and returned to the tabs I had hesitated to open.

The bank loaded. I signed in and completed the transfer.

Then I opened a health portal, read a result and sent a message through its protected system. My broadband provider saw the VPN connection rather than those individual destinations. The websites received the VPN server’s address instead of my home IP address. Most importantly for the concern that had stopped me earlier, I had not created another email-based customer identity before connecting.

That did not hide me from the bank or the health portal. I signed into both services, so they knew exactly who I was. A VPN cannot erase an identity I deliberately provide to a website, and it cannot remove existing accounts, cookies or device recognition.

The difference was in my relationship with the VPN itself.

The established provider had begun by attaching the service to my email, payment and persistent login. The smaller app began with less conventional identity information to connect to the session.

I could not observe either provider’s internal logging systems from outside the company. What I could verify was the information each service demanded before allowing me to use it. Only one let me reach the connection stage without first introducing myself through an email account.

For the question that had stopped me at the banking screen, that was the more useful form of privacy.

The app also avoided turning the decision into a geography quiz. Instead of asking me to choose from a wall of flags, it organised the connection around what I was trying to do. That reduced the number of decisions between opening the app and returning to the task.

The result came before the explanation: the transfer was complete, the health message was sent and I no longer felt that avoiding one identity check had forced me to create another lasting identity elsewhere.

The Smaller Trackers Behind the Larger Question

After finishing the transfer, I opened a news article. A blocked-request counter began rising as the page loaded.

The service was stopping advertising and tracking requests before they reached outside companies. That solved a smaller privacy problem I had not been thinking about when I installed the app.

Changing an IP address does not automatically stop website trackers. Advertising scripts, cookies and other identifiers can still connect browsing activity across pages. By blocking some of those requests, the service reduced the number of third parties receiving data during an ordinary session.

I had been concentrating on one powerful intermediary—the VPN provider—while a single webpage was attempting to contact several smaller ones.

The counter did not claim to make the browser invisible. It simply showed that fewer unnecessary connections were being completed. Because the main task had already succeeded, the feature felt less like a sales point and more like a reason to leave the app installed.

What I Was Really Choosing

OnlydogVPN has fewer locations, a shorter public history and fewer independent reviews than the largest VPN brands. For someone whose first priority is a particular server country or decades of published company history, those differences will matter.

They mattered less to me than what happened at the entrance.

The first service asked me to create an identifiable customer relationship and then trust a detailed promise about how data linked to that relationship would be handled. The second reduced the identity collected before that promise became relevant.

A VPN never removes trust from internet use. It moves trust. The broadband provider loses its direct view of my destinations, websites receive a different IP address, and the VPN service operates between those two sides. HTTPS protects the contents of most sessions, but the surrounding connection still carries information.

That is why “no logs” was not the only question worth asking. I also needed to know how easily any potential connection record could be tied to me.

For the browsing I had hesitated to continue, providing less identity at the start mattered more than reading a longer promise about what would happen afterward.

Questions this experience may leave you with

What was actually causing the problem?

The increase was not driven only by people trying to open restricted content. Research into the rollout found that distrust of identity checks and surveillance was a major reason people began searching for VPNs. Many users rejected one request for personal data, installed a new network intermediary within minutes and considered the trust question only after the page had opened.

Why did the obvious fixes fail?

The age-check page wanted a facial scan or proof of identity. I closed it, installed a familiar VPN, connected through another country and reopened the site. It loaded immediately. Then I switched to my banking tab, noticed the VPN icon still glowing in the menu bar and stopped with my cursor over the password box. I had hidden those destinations from my broadband provider—but had I simply handed them to a company I knew even less about?

What should you check first?

I could not observe either provider’s internal logging systems from outside the company. What I could verify was the information each service demanded before allowing me to use it. Only one let me reach the connection stage without first introducing myself through an email account.

What finally changed the result?

Then I opened a health portal, read a result and sent a message through its protected system. My broadband provider saw the VPN connection rather than those individual destinations. The websites received the VPN server’s address instead of my home IP address. Most importantly for the concern that had stopped me earlier, I had not created another email-based customer identity before connecting.

What is worth remembering?

That is why “no logs” was not the only question worth asking. I also needed to know how easily any potential connection record could be tied to me.