Also on CyberFence: compare CyberFence to other VPNs side-by-side · check your public IP and geolocation .

Person holding an iPhone showing data usage and privacy settings screen in a warmly lit home library, viewed from over the shoulder

When you browse the web on mobile data, your phone carrier — Verizon, AT&T, T-Mobile, or any other — is the company routing every single one of your internet requests. That means they see every website you visit, every app that connects to the internet, and roughly how long you spend on each. They know your browsing history before Google does, and in many cases they profit from it.

A VPN changes this picture significantly, but not completely. Understanding exactly what a VPN hides from your carrier and what it doesn't is important for setting accurate expectations about mobile privacy.

What Your Phone Carrier Can See Without a VPN

When you're connected to mobile data without a VPN, your carrier acts as the pipe through which all of your internet traffic flows. Here's what they see:

  • Every domain you visit — Even on HTTPS sites, your carrier sees the domain name of every website you visit. When you visit your bank's website, your healthcare provider's patient portal, a mental health resource, or any other website, your carrier logs that destination. They may not see the specific page within the site (the full URL), but they see the domain — which is often enough to understand exactly what you're doing online.
  • DNS queries — When your phone looks up a website address, it sends a DNS query. By default, these queries go through your carrier's DNS servers, giving them a real-time log of every domain your phone contacts — including apps that connect in the background.
  • The IP addresses you connect to — Your carrier sees the destination IP address of every connection your phone makes. Even for HTTPS connections where the content is encrypted, the destination is visible.
  • Timestamps and volume — Your carrier knows when you connect to each service and how much data you transfer — useful for building detailed behavioral profiles even without reading content.
  • App traffic patterns — Many apps don't use HTTPS for all communications. For any unencrypted app traffic, the carrier can see the actual content.

US phone carriers are legally permitted to collect and sell this data. Under FCC rules that were revised in 2017, carriers can use your browsing data for advertising purposes. Major carriers have operated data monetization programs that sell subscriber data to data brokers, advertisers, and in documented cases, to location aggregators who resold it to bounty hunters and law enforcement without court orders.

What a VPN Hides From Your Phone Carrier

When you connect to a VPN on your phone before browsing, your carrier's visibility into your traffic changes substantially:

  • The websites you visit — All of your browsing traffic is encrypted inside the VPN tunnel before it leaves your phone. Your carrier sees encrypted data flowing to the VPN server's IP address — not the websites you're actually visiting. From the carrier's perspective, you're just sending encrypted data to one IP address repeatedly.
  • Your DNS queries — With a VPN active, your DNS queries are resolved through the VPN provider's DNS servers, not your carrier's. The carrier can no longer see what domains your phone is looking up. CyberFence routes DNS queries through its own encrypted resolver, so your carrier gets no domain-level visibility into your browsing.
  • The content of your communications — Any unencrypted app traffic that would otherwise be readable in transit is wrapped inside the VPN's AES-256-GCM encryption layer, making the content unreadable to the carrier.
  • The destination of your connections — Instead of seeing connections to dozens of different websites, your carrier sees all traffic going to a single VPN server IP. They cannot determine which websites or services you're actually communicating with.

What a VPN Does NOT Hide From Your Carrier

A VPN provides significant privacy from your carrier, but it's important to be accurate about what it doesn't conceal:

  • That you're using a VPN — Your carrier can see that you're connected to a VPN server. The VPN traffic pattern is identifiable — they know you're using encrypted tunneling software even if they can't read what's inside. Using a VPN is entirely legal in the US, and carriers cannot block or restrict it under current net neutrality frameworks, but they do know you're using one.
  • The IP address of the VPN server — Your carrier sees the destination IP of the VPN server. They cannot, however, determine what's inside the encrypted tunnel or what sites you're visiting through it.
  • The volume and timing of your traffic — Carriers can still see how much data you're transferring and when. This metadata has some analytical value but reveals far less than full browsing history.
  • Your phone's identity — Your carrier always knows your phone's identity (IMEI, SIM details, phone number) and your account information. A VPN doesn't anonymize you at the carrier level — it only restricts what they can see about your internet activity.

Hide Your Browsing From Your Carrier

CyberFence encrypts all mobile traffic with AES-256-GCM encryption and routes DNS through its own resolver. Verizon, AT&T, and T-Mobile see encrypted data to one IP — not your browsing history. Works on iOS and Android.

See Plans →

What Carriers Actually Do With Your Data

The concern about carrier surveillance isn't hypothetical. US carriers have documented histories of data monetization practices:

  • AT&T's "Internet Preferences" program operated for years and sold subscriber browsing data to advertisers. Opting out required paying a higher price — effectively charging for privacy.
  • Verizon's "precision ID" service sold subscriber location and browsing data to third parties including data brokers, who sold it to a wider market without subscribers' knowledge.
  • Location data scandals resulted in FCC fines against all four major US carriers for selling real-time location data to aggregators who resold it to law enforcement without court orders. The FCC issued hundreds of millions in fines but the data had already been sold.
  • Supercookies (UID headers) were inserted by Verizon and AT&T into subscribers' HTTP traffic, allowing third-party websites to track users across sessions even after clearing browser cookies. The FCC reached settlements over this practice in 2016.

These aren't edge cases — they're the documented, mainstream practices of the largest US telecoms operating under the weakest possible regulatory framework for data privacy. A VPN removes your browsing data from this ecosystem.

On Wi-Fi vs. Mobile Data

Everything discussed above applies specifically to mobile data connections, where your carrier is the network provider. On Wi-Fi, your carrier is not the network provider — your internet service provider (ISP) or the Wi-Fi network operator is. The privacy dynamics shift, but the VPN protection is equally valuable:

  • On home Wi-Fi: your ISP (Comcast, Spectrum, AT&T Fiber, etc.) plays the same visibility role as your mobile carrier does on mobile data. A VPN hides your browsing from your home ISP in exactly the same way.
  • On public Wi-Fi: the network operator (coffee shop, hotel, airport) can see your traffic. Other users on the same network may be able to intercept it. A VPN encrypts and hides your traffic from both.

CyberFence auto-connects on untrusted networks, so the protection applies automatically whether you're on mobile data or a public Wi-Fi connection — you don't need to manually activate it when switching networks.

Does VPN Traffic Work the Same on 5G?

Yes. 5G uses different radio technology than 4G LTE, but the fundamental network architecture is the same for data privacy purposes. Your 5G carrier still routes your internet traffic and has the same visibility into unencrypted connections. A VPN on a 5G connection provides the same privacy protections as on 4G — your carrier sees encrypted traffic to a VPN server, not your actual browsing destinations.

5G's higher speeds mean VPN overhead is proportionally less noticeable — the encryption/decryption processing is the same, but the raw throughput headroom is larger, so the practical impact on usable speed is smaller than on slower 4G connections.

What CyberFence Provides for Mobile Privacy

  • AES-256-GCM encryption on all mobile data and Wi-Fi traffic — carrier and ISP see only encrypted data flowing to one IP
  • Encrypted DNS resolution — your carrier cannot see your DNS queries; domain lookups go through CyberFence's own resolver
  • Auto-connect on untrusted networks — protection activates automatically when connecting to public Wi-Fi without manual action
  • Zero-log policy — CyberFence does not record what websites you visit; no browsing history exists to be subpoenaed, sold, or breached
  • US-operated infrastructure — your traffic exits from US-based servers, keeping it under US law and avoiding foreign data handling
  • iOS and Android coverage — full VPN and Web Shield protection on both platforms under a single plan that also covers desktop

Your phone carrier's business model includes selling your behavior. A VPN on your phone removes the product — your browsing history — from that transaction. What remains is exactly what the carrier needs to provide service: encrypted data packets and your account credentials. Your actual internet activity becomes private.

Stop Your Carrier From Selling Your Browsing — Start Free

Download CyberFence from the App Store or Google Play. AES-256-GCM encryption, encrypted DNS, auto-connect on every network. Try it free — available on iPhone, iPad, and Android.

View Plans →

Want to go deeper? Read the CyberFence competitor comparison hub , our free IP address checker , or the CyberFence DNS leak test .