The age-check page appeared while I was trying to open a mature health community from a coworking space in Manchester. I connected a familiar VPN, refreshed and watched the page load. Then three things happened that made me think the VPN had failed: the site greeted me by name, a map still placed me inside the building, and the restricted discussion still asked me to confirm my age. I changed VPN countries twice. My name, location and age prompt followed me.
The short answer
A short public discussion reflected the same mistaken assumption: the VPN showed as connected, yet a location page still knew where the device was. The missing detail was not another server. It was the browser permission sitting beside the changed IP.
I had expected one switch to hide everything
My expectations were understandable.
VPN interest rose sharply after stronger UK age-assurance requirements took effect in July 2025. People who had rarely thought about network privacy were suddenly being asked to use a selfie, identity document or other method before opening mature content.
I was one of them.
The usual VPN promise sounded simple: hide the IP address, change the apparent location and protect the connection. Without noticing, I had expanded that into a much larger promise.
I expected the VPN to hide my identity from websites, erase what my accounts already knew, disable location services and make the age prompt disappear.
When none of that happened, I assumed the tunnel was broken.
The real problem was simpler: I had not decided whom I wanted privacy from.
The coworking network was only one observer
The coworking company controlled the Wi-Fi beneath my laptop.
Without a VPN, the network could identify the domains my device contacted. HTTPS protected the contents of those connections, but the destination could still be visible.
Once the VPN connected, the network’s view changed. It saw an encrypted connection to the VPN service rather than separate visits to the health community, the age provider and the pages linked from them.
That was what the VPN had hidden.
The website was a different observer. It now saw the VPN server’s IP address instead of the coworking network’s address, but I was already signed in. My username and session cookie were enough to recognise me.
The map was using another source again. I had previously allowed the browser to access the laptop’s location. Changing the public IP did not withdraw that permission.
The results were not contradicting one another. Different systems were recognising different signals.
Once I understood that, switching countries again stopped looking useful. But before giving up on the familiar provider, I tried to complete the age check.
The large provider changed my IP and complicated the session
The established VPN was still a reasonable first choice.
It had a long public history, extensive support and servers across many countries. I selected a nearby route and confirmed that my public IP had changed.
The coworking filter disappeared.
Then a CAPTCHA appeared.
I completed it and opened the age-verification page. The camera loaded, but the return link produced an error. I switched servers and tried again.
The CAPTCHA returned. The health community also sent a security email about a login from a new location.
On the third server, the verification page opened, but the handoff dropped me back at the original age prompt.
The VPN had changed my public address every time. That part worked. The problem was that the website, verification provider and account-security system were watching one sensitive session jump between shared IP addresses and countries.
Meanwhile, the site still knew my name because I remained logged in.
A short public discussion reflected the same mistaken assumption: the VPN showed as connected, yet a location page still knew where the device was. The missing detail was not another server. It was the browser permission sitting beside the changed IP.
I stopped searching the map.
I needed one clean route, not a more convincing disguise.
The page opened when I protected the right layer
I opened OnlydogVPN and selected the private-browsing situation.
There was no conventional email-and-password registration before the first connection. I did not have to create another account or attach an everyday email address to the route before seeing whether it worked.
I connected and returned to the health community.
The main page loaded without the coworking filter. I opened the age-assurance option, completed the check and returned to the original tab.
The restricted discussion appeared.
I refreshed it. It remained open.
Then I followed the link I had been trying to reach and read the medication guidance before my scheduled call.
Only after the task succeeded did I check the other signals again.
The IP test showed the service’s address rather than the coworking network.
The health community still greeted me by name.
The map still placed me inside the building.
This time, those results made sense.
The VPN had hidden the destinations from the local network and replaced the public IP visible to the website. It had not erased the account I chose to use or revoke a browser permission I had already granted.
The difference was that the smaller app completed the privacy job I actually needed without adding another conventional account to the session.
What the VPN hid from each side
The easiest way to understand a VPN is to ask what each observer sees.
The coworking network saw an encrypted VPN connection. It could tell that the connection existed, but it could not see the individual destinations inside it.
The health community saw the VPN server’s public IP. It no longer received the coworking network’s address, but it still recognised my account and activity on its own pages.
The age provider received the information required for the verification method I selected. The VPN protected the route to that provider; it did not stop the provider from receiving the selfie or document I deliberately submitted.
The VPN service carried the traffic after it entered the tunnel. That is why the provider itself matters. A VPN moves trust away from the local network and toward the company operating the route.
In this session, anonymous basic use reduced what I had to give that company directly.
That mattered more than pretending nobody could see anything.
The things that remained visible were not VPN failures
The site knowing my username was not a leak.
I was logged in.
The map knowing the building did not mean my original IP was exposed.
The browser had location permission.
The age prompt remaining on an account would not prove the VPN had failed either. Platforms can attach age status to an account, restricted channel or saved session rather than checking only the current IP address.
A VPN also does not hide information typed directly into a website from that website. It does not anonymise a card payment, remove saved cookies or protect a device already running monitoring software.
Those are different privacy problems.
I had been judging a network tool by whether it controlled accounts, sensors and browser storage at the same time.
Once I stopped doing that, the result looked much stronger. The coworking network could no longer identify the sensitive destinations. The website no longer received the coworking space’s public IP. The age flow completed instead of breaking across several shared routes.
The VPN had not hidden my entire life.
It had hidden the part travelling over the network.
The next page revealed a smaller benefit
After reading the discussion, I opened an external health article linked by another member.
The blocked-request counter in the smaller app began increasing while the page loaded.
The service was filtering advertising and tracking requests generated by the site. I could see the counter change, although I could not independently inspect every internal filtering rule.
That filtering had not created the private route or completed the age check. Those problems were already solved.
It reduced a different form of exposure after the page opened.
The coworking network could no longer see the destinations inside the tunnel. The filtering then reduced some of the additional companies the page attempted to contact.
The order mattered:
The VPN concealed the destinations from the local network.
The changed IP hid the original connection address from the website.
Anonymous use avoided another compulsory account.
Filtering reduced unnecessary background requests.
None of those features needed to erase the account I had chosen to use.
More server locations would not have changed the answer
The smaller service has fewer locations, a shorter public history and fewer independent reviews than the established provider I tried first.
But the larger provider’s map had encouraged me to keep changing the wrong variable. Every new country replaced the IP address while leaving my account login and browser permissions untouched. The shared exits also added CAPTCHAs and security warnings.
The smaller app directed me toward the task instead.
One connection protected the coworking route. No new conventional account was required. The age check completed, and the page remained available.
That was the comparison I had missed.
The important question was not how many identities a VPN could somehow erase. It was whether it protected the network path without creating new friction around the sensitive task.
A VPN hides a route, not a person
By the time I closed the laptop, the question “What does a VPN actually hide?” felt much easier to answer.
It hides the destinations and traffic path from the local network and ISP. It replaces the original public IP shown to websites. It can make the connection appear to come from another region.
It does not hide someone from an account they log into. It does not switch off device location, erase cookies or remove information voluntarily submitted to a website.
The established provider changed my apparent country repeatedly but left me chasing signals the VPN was never meant to control. The smaller service protected the route I cared about, completed the sensitive task and did so without first asking me to create another identity relationship.
The useful test was never whether the VPN could make the website forget my name.
It was whether the person controlling the network could still see where I went.
Questions this experience may leave you with
What was actually causing the problem?
A short public discussion reflected the same mistaken assumption: the VPN showed as connected, yet a location page still knew where the device was. The missing detail was not another server. It was the browser permission sitting beside the changed IP.
Why did the obvious fixes fail?
A VPN also does not hide information typed directly into a website from that website. It does not anonymise a card payment, remove saved cookies or protect a device already running monitoring software.
What should you check first?
By the time I closed the laptop, the question “What does a VPN actually hide?” felt much easier to answer.
What finally changed the result?
Once I stopped doing that, the result looked much stronger. The coworking network could no longer identify the sensitive destinations. The website no longer received the coworking space’s public IP. The age flow completed instead of breaking across several shared routes.
What is worth remembering?
It does not hide someone from an account they log into. It does not switch off device location, erase cookies or remove information voluntarily submitted to a website.