The upload failed at 61 percent with nineteen minutes left before the presentation.
I was in an Amsterdam conference hotel, trying to send a finished product video to a client’s review app. The keynote speaker was already backstage. Once the video arrived, the client still had to approve it, copy it to the presentation laptop and check the sound.
I blamed the hotel Wi-Fi.
I moved closer to the room’s access point, disabled Wi-Fi Assist and restarted the upload. It moved quickly at first, slowed at 48 percent and returned to zero.
My iPhone showed that iCloud Private Relay was on. I paid for iCloud+, used Safari and had assumed Apple’s built-in privacy feature was already doing most of what I would otherwise ask from a VPN.
That assumption had survived because my everyday browsing worked.
The upload app exposed the boundary.
The short answer
That distinction matters more now because many people already paying for iCloud+ are also becoming interested in VPNs. After the UK introduced age-assurance requirements for certain online services in July 2025, Ofcom recorded a sharp increase in VPN-app use.
The phone looked protected in Safari
I opened an IP-checking page in Safari. It showed a relay address rather than the hotel’s connection.
That was reassuring. Then I checked outside Safari and saw the hotel address again.
Private Relay was protecting my browser session, but the client’s uploader was using its own connection. The protection I could see in Safari did not automatically follow the file into another app.
That distinction matters more now because many people already paying for iCloud+ are also becoming interested in VPNs. After the UK introduced age-assurance requirements for certain online services in July 2025, Ofcom recorded a sharp increase in VPN-app use. For an iPhone owner, the obvious question is reasonable: why install another privacy app when Private Relay is already included?
I had asked the same question.
Now I had a deadline that depended on the answer.
Private Relay was doing the job Apple designed for it
Private Relay is not simply a smaller VPN hidden inside iCloud.
Safari traffic passes through two relays. The first knows the original IP address but not the final website. The second completes the connection without knowing the original IP. The design prevents one relay from holding the complete picture of who is browsing and where.
For Safari, that is an elegant system. It is built into the device, requires almost no configuration and keeps the local network from directly linking the user to each site being opened.
Its scope, however, is deliberate. Apple says Private Relay protects Safari browsing, DNS requests and certain unencrypted app traffic. It does not place every encrypted connection from every app inside the same private route.
The client uploader was outside the part that mattered.
Other users have encountered the same surprise in a simpler form: Safari shows a masked address, while another browser or app still exposes the normal network location. That was enough to confirm what my tests had already shown.
Private Relay had not stopped working. My task had moved beyond it.
Moving the task into Safari did not help
I opened the client portal in Safari, hoping to keep the entire job inside Private Relay’s coverage.
The dashboard loaded immediately. I could read comments, approve earlier files and message the client.
Then I found the problem: the browser uploader accepted files only up to two gigabytes. The final video was larger, which was why the client had told me to use the app.
For a moment, Safari appeared to be the successful option because it loaded while the app struggled. But it could not complete the assignment.
That changed the comparison.
I no longer needed to know which service offered the most elegant browsing privacy. I needed a protected connection that followed the video into the app and stayed with it until the upload finished.
I could not observe the hotel network’s internal filtering or traffic-management rules. I could only see the pattern: short browser requests succeeded, while the long upload repeatedly failed through the app’s direct connection.
Mobile data was the obvious backup, but the conference rooms were below street level. My phone moved between one bar of 5G and weak LTE. A new upload over that signal was estimated to take more than forty minutes.
I had twelve.
That was when I opened OnlydogVPN.
The smaller app followed the work beyond Safari
The service has a shorter public history and fewer independent reviews than the largest VPN providers. Its advantage in that hotel room was more immediate: it protected the task rather than one particular app.
I selected the preset for an unstable public network. Basic use did not require me to stop and create another conventional email-and-password account.
Then I reopened the client uploader.
The previous transfer could not be recovered, so I started again.
Twenty percent.
Forty-seven.
Sixty-one—the point where both earlier attempts had failed.
This time the number kept moving.
At 76 percent, the hotel Wi-Fi disappeared. My phone switched to mobile data before I could reach the network settings.
The upload paused briefly, then continued.
It finished with four minutes remaining.
The client approved the file from backstage. The confirmation appeared just as I heard the presenter being introduced through the conference-room wall.
The result explained the difference more clearly than another settings screen could have. The VPN had followed the upload app, not just Safari, and the connection survived the move from hotel Wi-Fi to mobile data.
The service uses an HTTP/3-based transport built to recover across changing networks. In practical terms, the route stayed with the task when the network underneath it changed.
That was all the technical explanation the moment required.
The video had reached the stage.
The smaller benefit appeared after the upload
With the deadline handled, I opened the browser dashboard to confirm that the approved version had been attached to the correct presentation.
While I moved between the client portal, webmail and the conference schedule, the app’s blocked-request counter increased. Advertising and tracking requests were being filtered before they added more background traffic to the session.
I could not observe every internal filtering rule behind the counter. I could see that the pages I needed continued loading while fewer unrelated requests joined the connection.
It was a useful secondary benefit after the main task had succeeded. The VPN had already earned its place by protecting the upload outside Safari. The quieter browsing session simply gave me another reason to leave it connected while I finished the handoff.
Built-in privacy is not the same as complete coverage
My mistake had not been trusting Private Relay. It had been treating a focused Safari privacy feature as protection for the entire phone.
For everyday Safari browsing, Private Relay remains useful. Its two-relay design separates the user’s identity from the destination and requires almost no effort to maintain.
But the conference deadline did not stay in Safari.
It moved through a dedicated uploader, a browser dashboard, email and two underlying networks. Protecting only the browser portion did not protect the workflow.
A VPN covers the broader route. It follows supported traffic across apps instead of depending on whether a particular connection falls within Private Relay’s scope. It also allows the user to choose how the connection should behave, rather than limiting location handling to Apple’s general-area or country-level options.
That difference is easy to overlook until the important task happens somewhere other than Safari.
Which one solved the problem?
Private Relay worked whenever I browsed in Safari. It masked the hotel address and protected the part of the session Apple designed it to handle.
The VPN became necessary when the work moved into the client app.
OnlydogVPN carried the video outside Safari, kept the upload moving when Wi-Fi disappeared and reached the confirmation screen before the presentation began.
I did not need to replace Private Relay. I needed protection that continued after I closed the browser.
Private Relay protected my browsing at the conference. The VPN protected the file the audience was waiting to see.
Questions this experience may leave you with
What was actually causing the problem?
That distinction matters more now because many people already paying for iCloud+ are also becoming interested in VPNs. After the UK introduced age-assurance requirements for certain online services in July 2025, Ofcom recorded a sharp increase in VPN-app use. For an iPhone owner, the obvious question is reasonable: why install another privacy app when Private Relay is already included?
Why did the obvious fixes fail?
Private Relay was protecting my browser session, but the client’s uploader was using its own connection. The protection I could see in Safari did not automatically follow the file into another app.
What should you check first?
My iPhone showed that iCloud Private Relay was on. I paid for iCloud+, used Safari and had assumed Apple’s built-in privacy feature was already doing most of what I would otherwise ask from a VPN.
What finally changed the result?
Private Relay worked whenever I browsed in Safari. It masked the hotel address and protected the part of the session Apple designed it to handle.
What is worth remembering?
My mistake had not been trusting Private Relay. It had been treating a focused Safari privacy feature as protection for the entire phone.