Larofly

Every time you open a browser, someone sees it before you do. Not a movie hacker — your ordinary internet provider. This article explains, without paranoia or technical jargon, what they really see, what they don't, and which measures change the picture.

What the provider actually sees

When you type an address, your device asks a DNS server for the site's IP. That request is usually unencrypted, and the provider handles it. Then a connection to the site opens.

So the provider sees: which sites you visit, when, how long you stay, how much traffic you use, and from which device. If the site uses HTTPS — and nearly all of them do — the content of pages, messages and passwords stays hidden. The address does not.

A useful mental model: the provider sees the envelopes, not the letters. Where you wrote, how often and how thick the envelope was — all visible. What is inside — not.

What it does with that data

Three things, in ascending order of consequence.

Statistics. Aggregated load data, used to plan networks. Harmless.

Advertising profiles. Depending on your country and contract, browsing history can feed marketing segments. This is why you see ads for a product you only looked at once.

Legal requests. In most jurisdictions providers keep connection metadata for a set period and must hand it over on a lawful request.

None of this is a conspiracy — it is how the infrastructure works. The question is which of it you want to reduce.

What does not help, contrary to popular belief

Incognito mode. It clears local history and cookies. Your provider still sees every address. Incognito protects you from the next person using your laptop, not from the network.

Switching DNS to a public resolver. It helps against DNS-based filtering and can be a bit faster, but the connection to the site itself is still made from your address, through your provider.

A browser "VPN" extension. It only covers browser traffic, and often only some of it. Everything else — apps, updaters, messengers — leaves as usual.

What actually changes the picture

An encrypted tunnel. Your traffic goes out through an intermediate server: the provider sees only that you are connected to that server, not which sites you open. The site, in turn, sees the server's address instead of yours. This is the only measure that changes both halves of the picture at once.

Encrypted DNS (DoH/DoT). Hides which names you resolve. Sensible in addition, not instead.

A tracker blocker. Cuts out advertising scripts that follow you between sites. Solves a different problem — one the provider isn't part of — but is worth having.

How to choose an intermediate service sensibly

Three questions worth asking before anything else.

Does it keep activity logs? If a service records what you open, you have swapped one observer for another.

Where is it registered and where are the servers? Jurisdiction determines what can be requested from it.

How does it earn money? A free service without a visible business model is usually paid for with your data.

Speed matters too, but far less than most people assume: for browsing and video, any modern protocol on a nearby server is more than enough.

A reasonable baseline

You don't need a security-researcher setup. For an ordinary person a simple combination works: an encrypted connection when you need privacy or access, encrypted DNS in the browser, and a tracker blocker. That closes the everyday layer — the one that leaks the most and costs the least to fix.

Awareness beats paranoia. Knowing what is visible and to whom is already most of the job.

Wrap-up

Your provider sees which sites you visit, when and for how long. Incognito mode and a different DNS do not change that. What does change it is an encrypted connection on a modern protocol — plus a tracker blocker and encrypted DNS for the rest.

If you want to start right now: 7 days free, no card required.

7 days free, no card required. Setup takes two minutes.

Start in Telegram