Privacy planning starts with the connection situation, information to protect, who can see the path, and a specific protective action.
Original explanatory diagram by VPN in Focus. Read the article for context and limitations.
This week’s focus

Before comparing brands, name the information you want to protect, the observer you are concerned about, and the evidence behind the proposed solution. A clearer question usually produces a more useful privacy decision.

A VPN advertisement often compresses several ideas into a single word: protection. That word can refer to an encrypted tunnel, an IP-address change, a filter, or a bundle of separate services. Without a specific question, it is easy to assume the purchase solves all of them equally well.

The first VPN in Focus briefing starts with the question rather than the subscription. This is a practical explainer, not a report of a new security incident. The aim is to make ordinary privacy claims easier to assess before you spend time or money on them.

Question one: what information matters?

A website seeing your home IP address is different from an account recognizing that you signed in. A VPN may change the first relationship while leaving the second intact. Write down the information you want to protect in one sentence. If that sentence contains several unrelated problems, split it into smaller ones.

For example, “I do not want a cafe network to inspect my routed traffic” is a more actionable goal than “I want to be invisible online.” It identifies a network context and leaves room to discuss HTTPS, VPN routing, and the limits of both.

Question two: who is the observer?

Privacy is relational. The local network, the internet provider, the VPN operator, and the destination website do not all see the same information. A route change can reduce one observer’s visibility while introducing another organization into the path.

That does not make VPNs useless. It makes provider selection part of the privacy decision. Look for a policy and evidence relevant to the information you care about, rather than treating the app’s connection animation as proof of everything behind it.

Question three: what supports the claim?

A feature description tells you what is advertised. An audit can offer evidence about a defined scope. A reproducible test can describe behavior under particular conditions. These are different kinds of support, and none should be silently substituted for the others.

When a review says a service is fast, ask where, when, on which device, and compared with what baseline. When it says a provider is private, ask which data and which policy. Specific answers are easier to evaluate than an unexplained numerical score.

One useful action today

Open the settings of the VPN you already use, or read the documentation of one you are considering. Identify its kill-switch behavior and any split-tunneling exceptions. Write a short note about what is included in the tunnel and what is not.

If that is difficult, start with the connection explainer. Understanding your current setup is a useful privacy improvement even if it does not lead to a new purchase.

Sources & further reading

Provider statements describe advertised capabilities. They are not independent performance measurements. Sources were consulted while preparing this article on September 24, 2026.

  1. WireGuard: protocol and conceptual overview
  2. Electronic Frontier Foundation: HTTPS Everywhere and browser encryption
  3. Proton VPN: kill-switch behavior

About the author

Daniel’s section looks beyond product headlines to the details: how an audit is scoped, what a protocol changes, and where a feature has limitations. Weekly briefings turn these subjects into practical reading and checklists.

Daniel Brooks is a fictional contributor profile created for this publication. This profile does not represent a verified individual or professional credentials. Read our editorial policy.