Your ISP Can See Every Site You Visit. Your State Can Subpoena That.
Since 2017, U.S. ISPs can collect and sell browsing data. Compare what an ISP can observe through a direct connection, VPN, and private browser route.

Every website you visit. Every search you run. Every link you click. Your internet service provider sees all of it. Not the content of encrypted pages, but the domains. The timestamps. The frequency. The patterns.
They do not just see it. They are legally allowed to sell it. And your state can compel them to hand it over.
This is not a conspiracy theory. This is federal law.
What Your ISP Actually Sees
Even with HTTPS encrypting the content of your connections, your ISP still has visibility into a surprising amount of your activity:
Your ISP's View of Your Browsing
What They See
- Every domain you visit (DNS queries)
- When you visit each site (timestamps)
- How long you stay (session duration)
- How much data you transfer (volume)
- Which servers you connect to (IP addresses)
- SNI headers revealing exact hostnames
What HTTPS Hides
- Page content (text, images)
- Form submissions (passwords, etc.)
- Specific URLs within a domain
- Messages and communications
HTTPS protects the content. It does not protect the fact that you visited. Your ISP knows you went to a health website, a legal resource, a dating platform, or a political organization. They know how often. They know for how long. They know the pattern.
That metadata is often more revealing than the content itself.
The Law That Made Selling Your Data Legal
In 2017, Congress voted to repeal the FCC's broadband privacy rules under Senate Joint Resolution 34. These rules, finalized in late 2016, would have required ISPs to get your explicit consent before collecting and selling your browsing data.
The repeal passed the Senate 50-48 and the House 215-205. It was signed into law in April 2017.
The practical effect: U.S. internet service providers, Comcast, AT&T, Verizon, Spectrum, and others, can collect your browsing data and sell it to advertisers, data brokers, and other third parties without asking your permission.
Your ISP is not just your internet provider. It is a data broker that happens to give you internet access.
Your State Can Subpoena Your Browsing History
The commercial sale of data is one problem. Government access is another.
Law enforcement can obtain your browsing records from your ISP through several mechanisms:
- Subpoenas: in many jurisdictions, a subpoena (not a warrant) is sufficient to obtain subscriber information and basic connection records from ISPs. No judge needs to approve it.
- Court orders: under 18 U.S.C. § 2703(d), the government can obtain more detailed records with a court order, which requires a lower standard of proof than a warrant.
- Search warrants: for the most detailed data, a warrant is required. But the Fourth Amendment's application to digital records remains contested and varies by circuit.
- National Security Letters: the FBI can issue NSLs without any court involvement, compelling ISPs to hand over subscriber data with a gag order preventing the ISP from disclosing the request.
The data your ISP collects about you is not just a marketing asset. It is a legal liability. Every domain you visit is a record that can be produced in court proceedings: divorce cases, custody battles, employment disputes, insurance investigations.
What ISPs Actually Do With Your Data
ISPs do not just passively collect data. They actively monetize it:
- AT&T operated "Internet Preferences," a program that tracked customer browsing to serve targeted ads. Customers could opt out, for an extra $29/month.
- Comcast/Xfinity collects browsing data and shares it with advertising partners. Their privacy policy explicitly permits this.
- Verizon was caught injecting "supercookies", unique tracking identifiers, into customers' HTTP traffic without consent. The FCC fined them $1.35 million in 2016, but the practice revealed the extent of ISP tracking capabilities.
You pay your ISP for internet access. They then sell records of what you do with that access. You are both the customer and the product.
VPNs Shift the Problem. They Do Not Solve It.
VPNs are the conventional answer to ISP surveillance. Encrypt your traffic, route it through a VPN server, and your ISP can only see that you are connected to the VPN. They cannot see the individual sites you visit.
The problem: a VPN shifts your trust from the ISP to the VPN provider. You are still trusting a single company with your complete browsing history. And VPN providers have their own issues:
- "No-log" claims are often unverifiable. Multiple VPN providers that advertised "no-log" policies have been caught logging user data. IPVanish provided user logs to the FBI in 2016 despite a no-log policy. PureVPN did the same in 2017.
- VPN providers can be subpoenaed too. If your VPN provider keeps any records, those records are subject to the same legal processes as ISP data.
- VPN traffic is increasingly detectable. ISPs can identify VPN connections by their traffic patterns. This matters as VPN-blocking legislation advances.
- CISA has warned against personal VPN use. The U.S. government itself has cautioned that VPNs "simply shift residual risks from the ISP to the VPN provider."
A VPN does not eliminate surveillance. It redirects it. The fundamental problem, a single entity seeing all your browsing, remains.
Routing changes who sees what
A private route changes the observer. Your ISP sees the connection to the routing service. The routing service handles the destination connection. This is a trust shift, not invisibility.
Browser isolation changes where the page runs. Your local network connects to the isolation service instead of loading that page directly. Timing and traffic volume can remain visible.
What your ISP sees
Direct connection
- Destination connection metadata
- DNS queries when sent through the ISP
- Connection timestamps
- Data volume per site
VPN
- Connected to VPN server
- VPN traffic volume
- Connection timestamps
- VPN provider sees everything
- Trust shifted, not removed
Ghost or Shield
- Connection to Legba
- Connection timestamps
- Traffic volume to Legba
- Destination fetched elsewhere
Exact visibility depends on DNS, transport, product configuration, and the observer's position. Do not interpret a private route as a promise of anonymity or zero logging.
Your Health Searches Are Not Private
This matters most for the searches you would never want linked to your name. Health information is the most common example.
Researching symptoms, conditions, medications, reproductive health, mental health resources, addiction treatment, all of these create ISP records. Those records can be accessed by:
- Insurance companies: in jurisdictions where data brokers sell ISP data to insurance underwriters.
- Employers: through legal discovery in employment disputes.
- Law enforcement: through the legal mechanisms described above.
- Anyone who buys data broker packages: since ISP data flows into the broader data broker ecosystem.
HIPAA protects health records held by medical providers. It does not protect the fact that you visited WebMD's page on depression, or a local addiction treatment center's website, or a reproductive health clinic's site. That metadata is ISP data, not medical data. It has no legal protection.
One extension. Two browser modes.
Ghost gives your browser a private route. Shield opens a page in an isolated browser off your device. Both stay scoped to the browser.
Legba does not promise invisibility, zero logs, or immunity from legal process. Use the mode that matches the job, then evaluate the remaining trust points.
Reduce the ISP's view
Your ISP watches everything you do online. They sell it to advertisers. Your state can subpoena it. Data brokers package it and resell it. And since 2017, none of this requires your consent.
VPNs, private routes, and remote browsers all move trust. None eliminates it. Compare which traffic is routed, which operator handles the destination, and which data each party can retain.
Make the observer map explicit.
Continue the privacy review
Related reading on ISP visibility, VPN trust, and isolated browser sessions.
Browser isolation vs VPN: which tool fits in 2026?
VPNs protect a network path. Browser isolation changes where web content runs. Compare their scope, limits, and best uses.
Stop Using Incognito Mode for Security. It Doesn't Work.
Incognito mode doesn't protect you from malware, phishing, or tracking. Here's what it actually does and what you need instead for real browser security.
The cookie conspiracy: how websites track you and what isolation changes
The truth about cookie tracking, price discrimination myths, and how isolated browser state changes cross-session tracking.
Free for 30 days. No card required.
Choose what changes
Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.