The clinic email arrived six minutes before my next call: Your results are ready. I clicked without thinking. The portal opened on my work laptop, and the company VPN icon was still lit beside the clock.
I closed the page, disconnected the VPN and reopened the link in a private window. Then I noticed the browser menu: Managed by your organization.
The VPN had disappeared. The feeling of being observed had not.
I did not need a general debate about workplace privacy. I needed to know whether my employer could see that I had opened a medical portal—and whether clicking Disconnect had made the second visit private.
The short answer
It belonged to me. It had no company profile, managed browser, endpoint agent or work VPN. Moving the clinic visit there removed the employer’s systems from the device, but I still did not want a public network handling the session more directly than necessary.
A Work VPN Serves the Company First
That question has become harder to ignore as employers introduce more detailed workplace analytics. In June 2026, Reuters reported that a major Canadian bank planned to measure time spent in browsers and internal communication applications, adding to wider disputes over tools that can record application use, mouse activity and keystrokes.
Employees rarely receive a clear diagram showing what is recorded by the VPN, the browser, the company account or security software installed on the device. They see one green shield and assume it is either protecting them or watching them.
A public r/VPN discussion captured the practical problem in a few lines: once personal browsing and employer-controlled software share the same computer, workers no longer know where the company’s visibility ends.
That was the mistake I had made. I was treating the work VPN like the personal VPN I used while travelling.
They serve different customers.
A personal VPN protects the user’s connection from an internet provider, hotel network or public hotspot. A work VPN brings the employee’s device into an environment the company can secure, manage and audit.
That does not mean someone in IT is sitting behind a dashboard watching every tab open. It means the company’s systems can record more than the VPN icon suggests.
What Travels Through the Tunnel
The first distinction is simple: full tunnel or split tunnel.
A full-tunnel work VPN sends all traffic from the computer through the company gateway, including ordinary web browsing. Cisco’s configuration documentation describes the same arrangement: without split tunnelling, web traffic travels through the VPN.
In that setup, company security systems can record when the laptop connected, which domains it contacted, how long the connections lasted and how much data moved.
HTTPS still protects the contents of most pages during ordinary transit. The company might see that the laptop contacted a medical portal without automatically receiving a readable copy of the diagnosis or password.
Corporate systems can also use TLS inspection. Microsoft’s enterprise security tools support decrypting HTTPS traffic, applying URL and file policies, and then re-encrypting it before sending it onward. On a managed device that trusts the company’s security certificates, the padlock in the browser is not a guarantee that the organization operating the device cannot inspect the request.
A split tunnel sends only company-related traffic through the corporate gateway. Other browsing leaves through the user’s normal connection.
At first, that sounded like the distinction that would settle my question.
Then I looked again at the words Managed by your organization.
Disconnecting Was Only Half the Answer
While the VPN was connected, my public IP address belonged to the company network. The first clinic visit had clearly travelled through the full tunnel.
Disconnecting removed that route.
It did not remove the managed browser, the security agent running in the background or the company configuration installed on the laptop.
Endpoint security software can record network activity directly on the device. Microsoft Defender’s endpoint records can include the remote domain or URL, the process that opened the connection, the protocol used and the identity of the device. That reporting does not require every request to pass through a traditional VPN gateway.
The same basic problem applies to managed browsers, security extensions, company applications and data-loss-prevention tools. A private window can stop the browser from leaving ordinary local history behind. It does not make the activity invisible to software operating elsewhere on the computer.
I could not see my employer’s internal retention and review rules, so I could not know whether anyone would ever examine my clinic visit.
But I had learned enough to stop experimenting. Disconnecting the VPN removed one observation point. It did not turn the work laptop into a private device.
The useful question was no longer, “Is the VPN using a full tunnel or a split tunnel?”
It was, “Why am I opening something this personal on a managed computer?”
Moving the Task Instead of Hiding It
My phone was beside the laptop, connected to the same coworking-space Wi-Fi.
It belonged to me. It had no company profile, managed browser, endpoint agent or work VPN. Moving the clinic visit there removed the employer’s systems from the device, but I still did not want a public network handling the session more directly than necessary.
I opened OnlydogVPN.
Basic use did not require an email address and password. That mattered in the moment. I was trying to remove identities and employer-controlled systems from the path, not create another account while a medical result waited behind a login screen.
I selected the privacy-oriented preset and connected.
Then I opened the clinic portal.
The results page loaded. I read the note, downloaded the attached report and used the appointment link to book a follow-up for Thursday morning.
The work laptop remained connected to the company VPN on the other side of the desk. Its security tools continued handling the work activity they were installed to protect. My clinic visit never entered that laptop, its browser or the corporate tunnel.
The coworking network saw an encrypted connection from my phone to the VPN service. The clinic saw the service’s exit address rather than the coworking space’s public address. My employer’s infrastructure was no longer part of the route.
That solved the problem more cleanly than trying to make a managed laptop behave like a private one.
The Other Connections on the Page
After booking the appointment, I opened the clinic’s preparation page. The app’s blocked-request counter began to rise as advertising and tracking connections were stopped.
It was a smaller benefit, but it followed naturally from the same concern.
Moving the session away from the employer did not mean the page contained no other observers. Medical, financial and ordinary news sites can load analytics and advertising services alongside their main content. HTTPS protects the connection, but it does not prevent a page from contacting additional companies.
The counter made those background requests visible without turning the moment into another technical investigation.
I had started by worrying about one organization seeing the clinic domain. The page reminded me that privacy is often lost through accumulation: an employer-controlled device, a corporate tunnel, a tracking script and an identifiable account, each adding another link.
The smaller app removed two of those links. It provided a personal route without requiring conventional account registration, then reduced unnecessary third-party requests after the page opened.
I left it installed.
What My Employer Could Actually See
Through a full-tunnel work VPN, an employer can record the domains and online services contacted, connection times and traffic volume. When TLS inspection is deployed on a managed device, the organization can also inspect full URLs, downloads and other HTTPS traffic.
With split tunnelling, ordinary personal browsing can bypass the corporate VPN gateway.
But the tunnel is only part of the answer. Endpoint security, managed browsers and workplace applications can report activity even after the VPN is disconnected. That made the laptop—not the VPN button—the decisive part of my privacy problem.
OnlydogVPN offers fewer exit locations than the largest consumer VPN providers. For someone choosing among many specific countries, that difference matters. I did not need a large server map at lunchtime. I needed a quick personal connection on a device my employer did not control.
I was not trying to disable company security, conceal activity performed on an employer-owned system or install an unauthorized VPN on a work machine. I moved the personal task to my own phone and used my own connection.
The work VPN had not betrayed me. It had done exactly what a corporate VPN is designed to do: bring the laptop inside an environment the employer can protect and audit.
My mistake was expecting that environment to become private when I clicked Disconnect.
For personal browsing, knowing whether a company uses full or split tunnelling explains part of its visibility. Keeping the activity off the managed device removes the larger uncertainty.
Questions this experience may leave you with
What was actually causing the problem?
It belonged to me. It had no company profile, managed browser, endpoint agent or work VPN. Moving the clinic visit there removed the employer’s systems from the device, but I still did not want a public network handling the session more directly than necessary.
Why did the obvious fixes fail?
I could not see my employer’s internal retention and review rules, so I could not know whether anyone would ever examine my clinic visit.
What should you check first?
While the VPN was connected, my public IP address belonged to the company network. The first clinic visit had clearly travelled through the full tunnel.
What finally changed the result?
But the tunnel is only part of the answer. Endpoint security, managed browsers and workplace applications can report activity even after the VPN is disconnected. That made the laptop—not the VPN button—the decisive part of my privacy problem.
What is worth remembering?
OnlydogVPN offers fewer exit locations than the largest consumer VPN providers. For someone choosing among many specific countries, that difference matters. I did not need a large server map at lunchtime. I needed a quick personal connection on a device my employer did not control.