Escape surveillance-friendly Big Tech.

    Privacy Analysis
    July 24, 2026
    10 min read

    Your ISP Knows More About You Than Google — and Proton's Stack Is the Last-Mile Fix

    Your internet service provider sits underneath Google, Meta and Amazon — watching the pipes your entire digital life flows through. Here's why that matters, what browser tools miss, and how Proton VPN + NetShield + Mail + Drive close the layers no ad blocker can.

    Your ISP knows more about you than Google — Proton VPN, NetShield, Mail and Drive as a last-mile privacy upgrade
    The last-mile privacy upgrade: VPN + NetShield + Mail + Drive.

    Your ISP knows more about you than Google

    We spend a lot of time worrying about Google, Meta and Amazon — but your internet service provider sits underneath all of them, watching the pipes your entire digital life flows through.

    In Proton's article on how ISPs track you, they show that even with HTTPS your provider can still see the domains you visit, when you visit them, how long you stay connected, how much data you transfer, your approximate location, and which devices are on your home network. This visibility spans smart TVs, streaming boxes, phones, consoles and IoT — not just your browser.

    A 2021 FTC staff report on ISP privacy practices found that major US ISPs combine browsing, app usage, TV viewing and real-time location data across product lines to build advertising profiles — even placing customers into sensitive categories like race and sexual orientation. That's a level of tracking no single app or platform can match.

    "Your ISP knows more about you than Google" isn't clickbait — it's the reality of who owns the pipes.

    The policy shift that supercharged ISP surveillance

    In 2016, the US FCC adopted broadband privacy rules that would have required ISPs to get opt-in consent before selling certain categories of customer data. In 2017, Congress used the Congressional Review Act to repeal those rules — and TechCrunch summarised the result: ISPs effectively gained permission to sell customers' browsing histories and other sensitive data without meaningful consent.

    Combined with the rollback of net neutrality, ISP data collection turned into a race to the bottom. The risk this piece describes isn't a distant threat — it's the direct outcome of a decade of policy choices.

    ISP tracking vs browser tracking: different layers, different risks

    Most privacy conversations focus on the application layer: third-party cookies, tracking pixels, fingerprinting. You fight those with privacy-first browsers and extensions like uBlock Origin.

    Your ISP lives at the network layer. Even when the page itself is encrypted with HTTPS, your provider can still see destination domains, timing and duration, data volume, and which local device is talking to which remote service. Traditional DNS leaks destination hostnames in plain text unless you use encrypted DNS (DoH/DoT) — and private browsing modes don't help here.

    Browser-only tools defend the top of the stack. Your ISP is still quietly logging the routes underneath.

    Beyond URLs: Wi-Fi sensing and in-home visibility

    Proton's guide highlights an emerging dimension of ISP visibility: Wi-Fi sensing. Routers can analyse how wireless signals bounce off objects and people to detect presence and movement inside a home. Academic research shows that under controlled conditions Wi-Fi signals can even reveal motion patterns and breathing. Consumer implementations are simpler, but several ISPs already ship Wi-Fi sensing on router hardware to millions of households.

    That's router-level capability — your browser extensions can't see or influence it.

    Why a VPN fixes the layer most tools miss

    A VPN encrypts your traffic before it leaves your device and routes it through a VPN server. Once you connect, your ISP generally sees only that you're talking to the VPN server — not each individual site or app. DNS requests travel inside the encrypted tunnel, and connection metadata like destination domains and routes becomes opaque.

    Proton VPN's apps are open-source and independently audited, using strong end-to-end encryption between your device and Proton's servers, plus Secure Core multi-hop routing for high-risk scenarios. Visibility shifts from a lightly regulated ISP to a provider that technically and legally limits what it can know about you.

    NetShield: closing the network-layer gap your ad blocker leaves open

    Most ad blockers live inside the browser. NetShield, Proton VPN's DNS-level blocker, operates one layer down: it checks every domain request from websites and apps against a database of known malware, ad and tracking domains, and simply refuses to resolve the bad ones.

    • Network-wide coverage: it protects every app on your device — browsers, games, native clients, news apps, smart-TV clients, IoT — not just a single browser profile.
    • Performance gains: blocking ads and tracking scripts before they load reduces data usage and often speeds up page load times, especially on ad-heavy sites.
    • Measurable privacy: the NetShield privacy panel shows real-time counts of blocked ads, trackers and malware domains.

    VPN tunnel → hides traffic from ISP. NetShield → strips surveillance and malware at the DNS level, across every app on your device.

    Proton Mail: fixing the inbox layer Big Tech still exploits

    Even if your ISP can't read the contents of your HTTPS-protected email sessions, the provider that hosts your inbox often can. Traditional email services store message contents unencrypted on their servers and reserve the right to scan or share them for advertising, machine learning or "service improvement".

    Proton Mail inverts that model. As Proton's article on how messages are encrypted explains, every message and attachment in your inbox is stored with zero-access encryption — Proton itself can't read it. Emails between Proton Mail accounts are end-to-end encrypted in transit, and for non-Proton recipients you can send password-protected, end-to-end encrypted messages. It's a direct answer to a threat a VPN alone can't fix.

    Proton Drive: cloud storage your ISP and Big Tech can't see into

    Cloud storage is the other blind spot. Your ISP can see you're syncing, and the provider often has full access to your files. Proton Drive is built differently: files are encrypted on your device before upload and stored with end-to-end and zero-access encryption, so Proton can't read contents, filenames, folder names or thumbnails. Sharing links can be password-protected, and data is hosted in privacy-respecting jurisdictions.

    Pair Drive with a VPN and the sync itself becomes invisible to your ISP — while the contents stay invisible to the provider.

    Turn ISP anxiety into a layered privacy upgrade

    The pattern is simple: start with the data that hurts most if exposed, then fix the network layer your ISP controls.

    "Your ISP knows more about you than Google" isn't a slogan — it's an invitation to take back control, one layer at a time.

    Frequently Asked Questions

    In many ways, yes. Google sees the searches, sites and apps that use its services; your ISP sits under all of them and can see every domain your household connects to, when, for how long and from which device. A 2021 FTC staff report found that major ISPs combine broadband, mobile, TV and location data across product lines to build advertising profiles no single app can match — including sensitive categories like race and sexual orientation.

    HTTPS hides the content of each page, but not the metadata around it. Your ISP can still see the domains you connect to, timing and duration of each connection, how much data you transfer, and which device is talking to which service. Traditional DNS lookups also leak destination hostnames in plain text unless you use encrypted DNS (DoH/DoT) or a VPN.

    A VPN encrypts your traffic before it leaves your device and routes it through a VPN server. Once connected, your ISP generally sees only that you're talking to the VPN server — not each site or app. DNS queries travel inside the encrypted tunnel, so destination hostnames are no longer visible to your provider. Proton VPN's apps are open-source and independently audited, and NetShield can additionally block ads, trackers and malware at the DNS layer.

    Browser ad blockers only cover the browser they're installed in. NetShield operates at the DNS layer inside Proton VPN, so it filters ads, trackers and known malware domains for every app on your device — browsers, games, news apps, smart-TV clients, IoT — not just one browser profile. It also reduces data use and often speeds up page loads on ad-heavy sites.

    A VPN hides your traffic from your ISP, but it can't stop the email or cloud provider that stores your data from scanning it. Proton Mail encrypts messages and attachments with zero-access encryption so Proton itself can't read them, and Proton Drive stores files, filenames and thumbnails with end-to-end encryption. Combining VPN + NetShield + Mail + Drive covers connection, network, inbox and storage — the four layers where surveillance actually happens.