TL;DR: A VPN is not a tool for anonymity, private browsing does not hide you from sites or your ISP, and end-to-end encrypted messengers still expose some metadata. The FTC and EFF say to verify claims rather than trust marketing.
👉 Check my digital footprint — free 30-second check →
Privacy tools are easy to over-trust. This guide sets out what each type does and does not do, using regulators, the EFF and the vendors' own documentation, so you can judge any product against it.
VPNs
The FTC says VPN apps may encrypt traffic between your device and the VPN server and make your activity appear to come from elsewhere, which can shield information on public Wi-Fi. It also warns that a promise of security does not make an app trustworthy: research it cited found VPN apps that did not encrypt, asked for sensitive privileges or shared data with third parties. Before trusting one, research it, read outside reviews, review the permissions it asks for, verify that it encrypts and check whether it shares data. The EFF says a VPN is not a tool for anonymity and cannot stop tracking by cookies or fingerprinting. Providers can receive law enforcement requests, "no logs" is a claim to verify rather than a guarantee, and because most web traffic now uses HTTPS, VPNs are less critical on public networks than once advised. The FTC's public Wi-Fi page says most websites use encryption and to look for the lock symbol. See how to check your VPN is working, how to spot a fake VPN app and public Wi-Fi risks.
Private browsing and browsers
The FTC notes private mode deletes history after the session but does not stop websites from seeing your activity. Mozilla says Firefox Private Browsing does not make you anonymous: your ISP, employer or the sites can still gather information, and downloads and bookmarks are still saved. Google says Chrome Incognito does not hide activity from websites, including Google sites, or from network administrators such as schools, employers and ISPs. On tracking, Firefox's Enhanced Tracking Protection blocks social media trackers, cross-site tracking cookies, fingerprinters and cryptominers in Standard mode, and Strict mode blocks all cross-site cookies. Brave states its Shields block trackers, cross-site cookie tracking and fingerprinting and strip tracking parameters from URLs. Chrome lets you delete cookies and set per-site exceptions. Choose a browser by what you can verify in its documentation, then tighten cookie settings.
Google says Gmail uses TLS automatically, as do almost all major providers. Proton says message bodies and attachments are stored with end-to-end encryption and that messages between two Proton addresses are end-to-end encrypted in transit. Messages to other providers travel over TLS and are not end-to-end encrypted by default, so the recipient's provider may be able to access them. Subject lines and sender and recipient addresses are not end-to-end encrypted. The EFF defines metadata as essentially everything except the content of your communications.
Messaging
The EFF says end-to-end encryption protects content from eavesdroppers including Wi-Fi monitors, ISPs and the app itself, but does not hide that you are communicating or with whom. Signal's privacy policy says it cannot decrypt or access message or call content and stores only the minimum needed to operate; a phone number is required to register. WhatsApp says not even WhatsApp can see personal messages, photos and calls, and its privacy policy says it collects phone number, profile information, usage and log information, IP address and device data, and shares information with other Meta companies. The EFF notes WhatsApp backups are unencrypted by default unless end-to-end encrypted backup is enabled. Disappearing messages help if someone picks up your phone, but Signal itself says a recipient can still photograph the screen. See also the Telegram privacy settings guide.
How to choose
1. Prefer tools whose makers cannot access your data, not tools that promise not to, the EFF advises.
2. Be wary of "military-grade" claims.
3. Treat every tool as one layer, alongside strong passwords and MFA.
Tools protect accounts, but they cannot un-leak data that is already out. A free digital footprint check shows whether your email or number appears in exposed data.
Frequently Asked Questions
Does a VPN make me anonymous?
No. The EFF says a VPN is not a tool for anonymity and cannot stop tracking through cookies or fingerprinting.
Does incognito or private mode hide me from my ISP?
No. Mozilla and Google both say private modes do not hide activity from websites, employers, schools or internet providers.
Is Gmail encrypted?
Google says Gmail uses TLS automatically. Proton says end-to-end encryption applies between Proton addresses and not by default to other providers.
What does end-to-end encryption not hide?
The EFF says it does not hide that you are communicating or with whom, and metadata such as email subject lines is not covered.
What should I check before trusting a VPN app?
The FTC advises researching it, reading outside reviews, checking permissions, verifying encryption and checking for third-party data sharing.
Sources
- FTC – Market for VPN apps
- FTC – Tips for using VPN apps
- EFF – Choosing the VPN that's right for you
- FTC – How to protect your privacy online
- Mozilla – Enhanced Tracking Protection
- Mozilla – Private Browsing
- Google – Chrome Incognito
- Proton – Mail encryption explained
- EFF – Communicating with others
- Signal – Privacy policy
- WhatsApp – Privacy policy