The VPN Myths I Keep Having to Correct

Sep 01, 2026By Jay Kells
Jay Kells

The VPN Myths I Keep Having to Correct

VPNs get talked about more than almost any other privacy tool, and a lot of what gets repeated about them is either outdated or was never quite true in the first place. I hear the same handful of misconceptions from people who are otherwise pretty switched on about their online safety, usually because a VPN's marketing leans on whichever claim sounds most impressive rather than what's actually accurate. These are the five myths I correct most often, and what I'd tell you instead.

A VPN Makes You Completely Anonymous Online

This is the biggest one, and it's not really true. A VPN hides your IP address and encrypts your traffic between your device and the VPN server, which is genuinely useful, but it doesn't make you anonymous in any complete sense. Websites can still track you through cookies, browser fingerprinting, and account logins regardless of what a VPN is doing underneath. If you log into your usual email or social media account through a VPN, that service still knows exactly who you are, VPN or not, and any tracking scripts running on that page will still build up their usual picture of your visit. I think of a VPN as hiding where your traffic is coming from on the network level, not as an invisibility cloak for everything you do once you're connected to a site. Pairing it with basic browser privacy habits, blocking third-party cookies, being selective about what you stay logged into, gets you a lot closer to genuine privacy than the VPN alone ever will.

Free VPNs Are Just as Good as Paid Ones

I understand the appeal of not paying for something a paid alternative also offers, but the free VPN market has a genuine problem, and it's how these services make money if you're not the one paying. Some free providers log and sell browsing data to advertisers, which is close to the exact opposite of what someone downloads a VPN to avoid in the first place. Others limit bandwidth so heavily the service is barely usable, or inject their own ads into the pages you visit. I'm not saying every free VPN is doing something shady, but the incentive structure is worth being honest about before trusting one with your traffic, and a reputable paid provider with a clear, audited privacy policy is the safer default if you're using a VPN for anything that actually matters to you.

A VPN Always Slows Your Connection Down Noticeably

This used to be a much fairer criticism than it is now. Early VPN services genuinely did introduce a noticeable lag, largely because server networks were smaller and encryption overhead was heavier on older hardware. Modern VPN providers with large, well distributed server networks and current encryption protocols typically cost you a small, often unnoticeable percentage of your speed, especially if you're connecting to a nearby server rather than one on the other side of the world. I've had people avoid using a VPN entirely because of a slowdown they experienced years ago with a different provider, when the actual answer is usually to pick a closer server or switch providers rather than giving up on the idea altogether.

Bright coffee shop interior with customers at tables, counter, espresso machine, and displayed products in natural daylight

You Only Need a VPN for Something You Want to Hide

This framing bothers me more than the others because it treats privacy as inherently suspicious, when actually the opposite is true. Using a VPN on public wifi at a cafe or airport isn't about hiding wrongdoing, it's about not broadcasting your banking session or email password to anyone else sharing that same unsecured network. I use one on public networks specifically because I don't know who else is on them or what they're capable of intercepting, and that's true whether I'm doing something mundane or something sensitive. Privacy and secrecy aren't the same thing, and treating every privacy tool as evidence of something to hide is exactly the framing that makes people skip basic protections they'd otherwise use without a second thought.

Every VPN Provider's No-Logs Claim Means the Same Thing

"No-logs" gets printed on nearly every VPN provider's homepage, but the term isn't standardised, and what one company means by it can be very different from what another does. Some providers genuinely keep no identifying records at all, and back that claim up with independent third-party audits you can actually read. Others technically don't log your browsing activity but still keep connection timestamps or bandwidth data that could be used to identify you under the right circumstances. I look specifically for a provider that's had its no-logs policy independently audited, rather than taking the claim on the strength of the marketing copy alone, because a policy nobody's verified is really just a promise. An audit doesn't guarantee a company will never change its practices later, but it's a meaningfully stronger signal than a claim with nothing behind it, and it's the first thing I check before recommending any provider.

None of these myths make VPNs less worth using, they just mean the reasoning behind using one is often slightly off. A VPN is a genuinely useful layer of protection, particularly on networks you don't control, but it's not invisibility, free options carry real trade-offs, modern speed costs are usually minor, using one isn't inherently suspicious, and not every no-logs claim has been checked by anyone but the company making it. I use NordVPN because it's had its no-logs policy independently audited and I've never noticed a meaningful speed difference on the servers I connect to, and my free Safety Toolkit covers the rest of what I'd actually recommend if you want to work through your setup properly, while the NCSC has its own guidance on VPNs if you want a second source alongside mine.