Start with the plumbing
Every request your household makes — phones, laptops, the TV, the doorbell camera — leaves through one pipe, and your internet provider owns it. They are not eavesdropping in any exotic sense. They are simply the road, and everything you do drives down it.
That position gives them a view nobody else has. Google sees what you do on Google. Your bank sees your banking. Your provider sees the full sequence: the health site at 11pm, the job board at lunch, the streaming service every evening, and which device did each one.
What they can see, precisely
This is where most articles get sloppy, so let's be exact. On a normal HTTPS connection your provider cannot read the contents — not the page, not your password, not what you typed. What they can see is:
- The domain name of every site. Two separate leaks give this away: the DNS lookup that turns a name into an address (traditionally sent in the clear, and usually to your provider's own DNS server), and the server name your browser announces when it opens the connection.
- Every IP address you connect to, which often identifies the service even without a name.
- Timestamps, duration and data volume for each connection — enough to reconstruct your daily routine.
- Which device did it, since your router hands out the addresses.
"They only see the domain, not the page" sounds reassuring until you write out a day of domains. The list of sites a person visits is the thing that's revealing. The page inside is almost a detail.
What US law lets them do with it
In 2016 the FCC adopted broadband privacy rules that would have required providers to get your explicit permission before sharing sensitive data, including web browsing history. In March 2017, before those rules took effect, Congress repealed them under the Congressional Review Act and the repeal was signed into law. The practical result: at the federal level there is no rule requiring your provider to ask first.
The Federal Trade Commission retains general authority over unfair or deceptive practices, and in a 2021 staff study of major internet providers it reported that several collected and used far more data than their customers would expect, including for targeted advertising through affiliated businesses.
A few states went their own way. Maine passed a law in 2019 requiring opt-in consent before an ISP can use or sell customer personal information, and it survived a court challenge. California's privacy law gives residents rights to access and opt out of sale. Where you live changes your position considerably — which is itself a strange thing to be true of your own browsing history.
How long it's kept, and who else asks
Retention varies by provider and is rarely advertised plainly; periods measured in months are typical, and some records live longer. The data does not only serve advertising. Subscriber records and connection logs are routinely requested through subpoenas and court orders in civil and criminal matters, and copyright enforcement notices reach you precisely because your provider can map an address back to your account.
None of that is scandalous on its own. It just means the log exists, it is durable, and it is reachable — three properties worth knowing about a record of everywhere you have been.
Encrypted DNS helps — and only halfway
Modern browsers can send DNS lookups over an encrypted channel to a resolver of your choosing, which stops your provider from reading that half of the leak. It is a real improvement and it is free. But the connection itself still goes out through their network to an address they can see, and the server name in the handshake is still readable on most sites today. Encrypted DNS narrows the view. It does not close it.
What a VPN actually changes
With a VPN running, your provider sees one encrypted connection to one address, running for as long as you are online. The domains vanish. The per-site timing vanishes. What is left is "this household moved 40 GB today," which is roughly what they need for billing and nothing more.
Be clear about what has happened, though: you have not removed the observer, you have changed it. The VPN provider now occupies the seat your ISP was in. That is only an improvement if the new party is better — which is why the boring details matter more than the marketing: does it keep logs, has anyone independent verified that, and what country's laws can compel it to hand things over.
It is also why "free VPN" is usually the wrong answer. Running a global server network costs real money. If you aren't paying for it, the browsing data is the product, and you've swapped a regulated utility for an unregulated one.
Your ISP isn't the only one keeping a file
A VPN hides your traffic from the network. It does nothing about the accounts you are logged into. If you're signed into Google, Google still knows what you searched, whatever your IP address says — and the same goes for every other service you log in to.
Two different problems, two different tools. A VPN is the right tool for the network layer. Account settings, ad-personalisation controls and a tracker blocker are the right tools for the other one.
Take the list of sites off your provider's bill
NordVPN's no-logs policy has been independently audited, and the company sits in Panama, which has no mandatory data-retention law. That combination is the part that actually matters when you're choosing who gets to see your traffic instead.
Get NordVPN →30-day money-back guarantee · Read our full NordVPN review first.
The reasonable takeaway
Your provider can see the domain of everything you visit, they are not federally required to ask before monetising it, and the record persists. Whether that bothers you enough to pay a few dollars a month is a values question, not a technical one — but it should be a decision you made, rather than a default you never knew you'd accepted.