You pay your internet service provider every month to connect you to the world online. You might not realize, however, that the same company delivering your web pages, streaming videos, and video calls can also see nearly everywhere you go on the internet. It doesn’t matter if you’re browsing in incognito mode or clearing your cookies religiously.

This isn’t theoretical. A Federal Trade Commission investigation in 2021 found that major ISPs collect troves of personal data and use it to build detailed profiles that include race, sexual orientation, demographics, and real-time location. Some providers even share this information with third parties, from advertisers to data brokers. Meanwhile,  regulatory changes have given oversight agencies new tools to hold ISPs accountable.

Those protections, however, only go so far. The real power to limit what your ISP knows about you still rests in your hands. In this guide, we will look more closely at the technical and routine measures you can take to protect your data.

Key Takeaways

  • Even with HTTPS or incognito mode, your provider can see the websites you visit, when you’re online, and patterns in your behavior.
  • ISPs may not read encrypted pages, but domain names, timestamps, and connection data are enough to build detailed profiles.
  • ISPs can combine browsing, device, and location data for advertising, analytics, or partnerships, depending on their policies and local laws.
  • Comprehensive privacy tools and settings can significantly limit your ISP’s visibility and help you reclaim your privacy.

What Can Your Internet Provider See?

Every time you visit a website or use an app, your request passes through your internet service provider’s (ISP) network. While modern encryption standards have made it harder for ISPs to read the full content of your online activity, it has not made your browsing invisible. Even with today’s privacy protections, your ISP can still see key browsing information.

What ISPs Can See Even With HTTPS

Encryption standards, such as HTTPS, protect the actual content of the pages you visit. This means your ISP generally cannot read what you type into forms, the articles you view, or the messages you send on secure sites.

However, encryption does not hide everything. Your ISP can still see the websites and email addresses you’re emailing to and from, including domain names, timestamps, connection duration, and data volumes, creating a surprisingly detailed map of your daily routines and interests.

This information might seem limited on its own, but it provides a consistent record of your activity across time. Knowing which sites you visit and how often can reveal far more than you might expect.

What ISPs Can See on Unencrypted Websites

When you visit websites that still use unencrypted HTTP connections, the visibility increases significantly. In these cases, your ISP can see the full URL of the pages you visit, including specific paths and parameters.

This means they may be able to view page content, search queries, and even form submissions. In some cases, that can include usernames, passwords, or other personal information transmitted without encryption.

While most major websites now use HTTPS by default, unencrypted traffic still exists. Any time a connection is not fully secured, your ISP’s view becomes much more detailed.

How Metadata Reveals Your Behavior

Even without access to page content, the data your ISP collects, often called metadata, can build a surprisingly detailed picture of your habits. Metadata includes things like the websites you visit, when you visit them, how long you stay, and how frequently you return.

Over time, these patterns can reveal your daily routines, work hours, sleep schedule, and interests. Repeated visits to certain types of websites may also hint at topics such as health concerns, financial activity, or personal beliefs.

When combined across devices, apps, and services on your home network, this metadata creates a broader view of your household’s behavior. Even without seeing exact content, your ISP can still build a detailed map of how you spend your time online.

Can Your Internet Provider See Your Search History?

In most cases, yes. Your internet provider can see key parts of your search activity, even if they cannot view every detail of what you search for.

When you use modern websites that rely on HTTPS encryption, your ISP typically cannot see the exact search terms you enter into a search engine. However, they can still see that you visited a search engine like Google, along with the time, frequency, and duration of those visits. They can also see the domains of the websites you click on from your search results. Over time, this creates a record of the types of information you look up, even without exposing the exact queries themselves.

If you visit websites that do not use encryption, your ISP may be able to see full URLs, including your search queries and the pages you view. It is also important to understand that private browsing or incognito mode does not hide your activity from your ISP. These modes only prevent your browser from storing your history locally on your device. Your internet provider still sees the traffic passing through its network.

How ISPs Use Your Data

Internet service providers didn’t always operate like data brokers, but that has changed. In 2021, the Federal Trade Commission (FTC) revealed that six major U.S.-based ISPs combine web browsing, app usage, and location data across their product lines to create hyper-granular dossiers on you.

Do ISPs Sell or Share Your Data?

The providers then placed users into sensitive categories, including race, sexual orientation, and income level, and shared real-time location data with third parties, ranging from advertisers to analytics firms. While many ISPs promise not to sell your data outright, they allow extensive sharing and monetization through partners and affiliates, using definitions that don’t always align with what consumers would consider a sale.

They then monetize these datasets by selling them to data brokers and market researchers. Bundling internet, streaming, and smart home services multiplies the data collection points across your digital life.

How ISPs Build Profiles About You

The scale of this data collection is massive, encompassing not only the domains you visit but also the devices, operating systems, browsers, and applications you use, as well as the specific times of day you’re most active online.

When you have smart home devices, streaming services, and multiple family members sharing the same connection, all that activity flows through your ISP’s servers and can be correlated, aggregated, and analyzed to build predictive models about your household’s behavior, interests, and purchasing patterns.

Real Examples of ISP Tracking Practices

Some providers have gone further with network-level tracking technologies. Between 2012 and 2016, Verizon Wireless inserted supercookies into all unencrypted web traffic from mobile customers, allowing the company and its advertising partners to track users. The practice only ended after the Federal Communications Commission (FCC) required explicit customer consent. AT&T experimented with a similar tool but halted it quickly after public outcry.

While these supercookie programs have largely ended, privacy advocates warn that ISPs could still employ network-level identifiers that bypass browser-based protections if regulations don’t prevent it.

Are Internet Providers Allowed to Track You?

The fragmented regulatory landscape around ISP privacy shifted in 2024 when the Federal Communications Commission issued the Safeguarding and Securing the Open Internet order, reclassifying broadband internet as a telecommunications service. This change requires ISPs to protect the confidentiality of customer proprietary network information and restricts how they use or share it without explicit consent.

The order also gives the FCC direct enforcement authority over ISP privacy practices and allows it to hold broadband providers accountable for failing to safeguard customer information, sharing data without consent, and misrepresenting privacy protections. Before issuing the order, the FCC imposed nearly $200 million in fines against major wireless carriers for sharing customer location data with third parties without prior consent, sending a clear message that ISP privacy violations now carry real consequences.

At the same time, state-level privacy laws have been multiplying, with more on the way. California, Colorado, Virginia, Connecticut, and other states have granted consumers the right to access, correct, and delete personal data that ISPs hold, to opt out of targeted advertising and data sales, and to limit the use of sensitive data such as location, health data, and children’s information.

Globally, about 80% of the world’s population now has some form of data protection law, with Europe leading at 99% population coverage, Africa at 83%, and many countries in Asia, Latin America, and other regions implementing frameworks that regulate how ISPs and other service providers collect, store, and share personal information.

How to Limit What Your ISP Can See

A handful of practical tools and settings can shrink your ISP’s view from a detailed surveillance feed to a fuzzy outline of your online activity. Here’s how to start.

Use a VPN for Private Browsing

A virtual private network encrypts all your internet traffic and routes it through a server you choose, effectively hiding your browsing destinations from your ISP. When you connect to a reputable VPN, your ISP sees only an encrypted tunnel to the VPN server and the total volume of data flowing through it. Your ISP can’t see which websites you’re visiting, which apps you’re using, or what content you’re accessing. Your DNS queries, those lookups that reveal every domain you want to reach, are also handled by the VPN provider.

Because you’re moving trust from your ISP to your VPN provider, it is wise to choose a reputable provider with clear, audited no-logs policies, and strong encryption. Free VPN services often fund themselves by logging and selling your data, a practice that defeats their entire purpose. You can use VPNs selectively for sensitive activities: financial transactions, medical research, sending confidential emails, or browsing private topics. McAfee’s integrated VPN makes this simple, encrypting your traffic with one click when needed.

Enable Encrypted DNS in Your Browser and Devices

Domain Name System queries are among the easiest ways ISPs track your browsing, and encrypted DNS is one of the easiest fixes. DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) encrypt your lookups and send them to a resolver you choose, blocking your ISP’s view. In major browsers, including Firefox, Chrome, Edge, and Safari, enabling it typically takes just a few clicks in your browser’s privacy or security settings.

For most modern HTTPS sites, encrypted DNS closes a major tracking gap. Recent versions of Windows, macOS, iOS, and Android support system-wide encrypted DNS, meaning every application on your device benefits from the protection. To enable this feature, look for  Secure DNS or Private DNS in your network preferences and choose a trusted resolver such as Cloudflare (1.1.1.1), Google, or Quad9.

Secure Your Home Router

Your router settings can help you reclaim your privacy. Start by changing the default administrator password, as these credentials are widely documented and represent the most common attack vector. Next, check for firmware updates quarterly to ensure manufacturers are regularly patching vulnerabilities. Enable WPA3 encryption or ensure WPA2 is active with a strong password.

Consider also setting up a guest network for smart home devices to isolate them from your primary computers and phones. This will reduce both privacy risks and the chance that a compromised Internet of Things (IoT) device could snoop on your main traffic.

Adjust Your ISP Privacy Settings

Log in to your ISP’s web portal or mobile app and look for privacy or marketing settings that let you opt out of targeted advertising, data sharing with affiliates, and profiling for marketing purposes. Privacy laws in several states require ISPs to include a “Do Not Sell or Share My Personal Information” option.

These settings can limit what your ISP does with your data, such as packaging and sharing it with advertising networks and data brokers. You may also request a shorter data retention period or ask for copies of the information they have about you. These settings are often buried deep on their websites or presented in dense legal language, but devoting 20 minutes to digging through the options is time well spent.

Depending on your state, you may also have the legal right to request deletion of certain personal data your ISP has collected and correct inaccuracies. Check your state attorney general’s website for guidance on how to exercise these rights. While ISPs may refuse requests in some circumstances, the simple act of submitting a request signals that you’re paying attention and expect accountability.

Use Privacy-Focused Browsers and Extensions

Using a browser designed with privacy in mind complements the other protections we have outlined. Browsers such as Firefox and Brave include built-in tracker blocking, HTTPS-only modes that block unencrypted pages, and anti-fingerprinting features that prevent websites from building your profile.

Browser extensions such as uBlock Origin block trackers and analytics scripts, while HTTPS Everywhere ensures encrypted connections when sites support them. On the other hand, Privacy Badger learns and automatically blocks tracking domains. Remember that browser protections don’t extend to mobile apps and desktop software. That’s why VPNs and encrypted DNS are valuable for protecting all your devices’ traffic, not just web browsing.

FAQs

Can my internet provider see my search history in incognito mode?

No. Incognito or private browsing does not hide your activity from your internet provider. It only prevents your browser from saving your history, cookies, and form data on your device. Your ISP can still see the websites you visit, when you access them, and other connection data as your traffic passes through their network.

Can my ISP see exactly what I search on Google?

In most cases, no. If you are using a secure (HTTPS) connection, your ISP cannot see the exact search terms you type into Google or other search engines. However, they can see that you visited a search engine and the websites you clicked on afterward. Over time, this still provides a general picture of what you are researching.

Can my internet provider see what I do when I use a VPN?

A VPN significantly limits what your ISP can see, but it does not make you invisible. When you use a VPN, your ISP can see that you are connected to a VPN server and how much data you are using. They cannot see the websites you visit, the apps you use, or the content you access inside that encrypted connection.

How long do internet providers keep browsing history?

The duration varies depending on the provider, local laws, and internal policies. Some ISPs retain connection logs and metadata for months or longer, while others may keep data for shorter periods. In some cases, regulations may require providers to retain certain records for legal or compliance reasons.

Can my internet provider see deleted browsing history?

Yes. Deleting your browsing history only removes records from your device. Your ISP’s records are separate and unaffected when you clear your browser history. They may still retain logs of your activity depending on their data retention policies.

Final Thoughts

Even with every protection in place, your ISP will still know you’re online, how much data you’re using, and whether you’re connected to a VPN or using an encrypted DNS resolver. State-level actors with legal authority can compel ISPs to produce connection logs they keep about you.

No single tool creates perfect anonymity, and stacking too many privacy layers can sometimes break legitimate services or frustrate you enough to disable protections entirely. You can meaningfully protect your privacy by adjusting a few settings, installing McAfee VPN , and using encrypted DNS to cut off major streams of data collection. Don’t aim to be invisible, but to shrink the amount of data your ISP passively collects, limit what they can monetize, and prevent them from building a detailed behavioral profile without your consent.