VPN/TOR

Posted March 24, 2024 · Updated September 23, 2026

Hide your ID

VPN and TOR are not the same thing. Each serves a different purpose but can be used in tandom to enhance your privacy.

Their purposes differ in that one focuses on anonymity (TOR) and the other on privacy (VPN)

VPN or Virtual Private Network is a service that provides servers, typically scattered around the planet, to act as an intermediary between your ISP and the internet. There are many of these providers out there but make sure to read their TOS before you choose. Also note the country where they are located because some nations have laws that could present a risk to your identity.

When you use a VPN whether via a browser plugin, desktop client or router configuration or mobile app, your traffic is encrypted when it leaves your network. It is sent to your chosen VPN provider's service to a server located in any number of geographic locations of your choosing. From there that traffic is decrypted and forwarded on to your destination be it a web site, chat, email or any other internet based service. Your ISP only knows you connected to the VPN's IP and nothing more. Your IP is one that belongs to the VPN service and is not tracable back to you.

One distinction worth knowing: a browser plugin only protects traffic from that browser. A desktop client, router-level setup, or mobile app-wide VPN protects everything on that device or network - every app on your PC, including your email client, not just what you're doing in a browser tab. If you want full coverage, use the desktop app or router configuration rather than just a browser extension.

Look for a VPN located in one of these nations which have strong privacy laws governing VPN provides. There may be others and this can change so do research.

  • Switzerland
    Panama
    Malaysia
    Romania
    British Virgin Islands

Verify that they do NOT retain any connection or transfer logs and that your payment data is not in any way linked to your usage.

Where is the company based - and what does that country's own law actually say? This is really two separate questions, not one:

  • Is the country part of an intelligence-sharing alliance? Providers based outside the ones often called the "Five Eyes" (US, UK, Canada, Australia, New Zealand) or its larger "Nine Eyes" and "Fourteen Eyes" extensions have a structural advantage, since member countries can more easily request and share data on each other's behalf.
  • Separately - and just as important - what does that specific country's own domestic privacy law require? Some countries have genuinely strong, enforceable data-protection law regardless of alliance membership: Switzerland's federal data protection law is considered one of the strictest in the world, and EU member countries operate under the GDPR, which gives users enforceable rights over their own data. On the flip side, watch for countries with mandatory data-retention laws that legally require providers to log connection data regardless of what their marketing promises - a "no logs" claim from a company based somewhere with a mandatory retention law on the books should be read skeptically, since the law may simply override the policy.

A few jurisdictions worth knowing specifically (this changes over time, so treat it as a snapshot, not permanent): India now requires (as of April 2026, under a CERT-In directive) any VPN provider operating there to retain customer names, IPs, and usage logs for at least 5 years - which is why several major VPN providers pulled their physical servers out of India entirely rather than comply. Russia requires VPN providers to register with the government and enforce state content-blocking; most reputable providers have withdrawn their servers rather than comply. China tightly restricts VPN use to a small number of state-approved providers. The UK's Investigatory Powers Act requires UK-based providers to retain "Internet Connection Records" for up to 12 months. By contrast, the EU is a case where alliance membership and mandatory retention law are NOT the same thing - its old blanket data-retention directive was struck down by the European Court of Justice back in 2014, and a unified replacement still wasn't in force as of early 2026.

Here's the important part about jurisdiction: it's the server's physical location that mostly matters here, not just where the company is headquartered. A VPN company incorporated in a privacy-friendly country can still operate a server sitting physically inside a country like the ones above - and that server, and anything that touches it, becomes subject to local law regardless of where the parent company lives. That's exactly why reputable providers pulled hardware out of India rather than argue the law didn't apply to them. A good provider can still have a server in a bad location - it's normal, since users want the location options. What matters is what you do about it: check the provider's server list before you need it, and simply don't pick a server sitting in a country with a mandatory retention law when you don't have to. Favor providers that publish which servers are RAM-only/diskless (never write to persistent storage), since a server in a questionable jurisdiction that never touches a disk is a meaningfully smaller risk than one that does.

How to actually read a VPN's privacy policy (what to check before trusting any provider, free or paid)

How is it paying its bills? A VPN service costs real money to run. If you're not paying for it, something else is - ads, selling aggregated usage data, or in a few documented past cases, quietly using free users' devices as exit nodes for a separate paid network. A vague policy that doesn't say which of these applies is the red flag.

Does "no logs" actually say what it means? A precise policy specifies exactly which data categories it does and doesn't keep - connection timestamps, session duration, bandwidth, source IP, DNS queries. Vague boilerplate like "we may collect information necessary to provide the service" leaves room to log more than the marketing page implies.

Has the no-logs claim been independently audited? Look for a named third-party audit firm and a publication date. A claim with no audit behind it is just a promise.

What's the actual retention window? A trustworthy policy states a specific, short period (days, not months) and says data is then deleted or irreversibly aggregated.

Track record matters as much as the current policy. Search "[provider name] data breach" or "[provider name] logs" before committing - there have been well-documented cases of "no-log" VPNs caught with large databases of connection logs after a breach.

What do they need from you to sign up? A privacy-respecting provider asks for as little as possible, often just an email. A "free" VPN wanting a phone number or broad device permissions is part of the price you're paying.

A free, portable fallback worth knowing about: Psiphon. No install required, no admin rights needed - download the single .exe and launch it when you need it. Originally built as a censorship-circumvention tool (it grew out of University of Toronto's Citizen Lab) rather than a privacy-first VPN, so it's better thought of as "get me uncensored access right now" than "hide everything I do." Their published privacy policy is more transparent than most free tools: they discard your IP immediately after deriving your rough location, never log full URLs, and never share raw user data with third parties - retained at most 90 days, then aggregated and deleted. The catch: it's ad-supported, and those ad partners (Google, Freestar) set their own tracking cookies under their own separate policies. Official site and full privacy policy: psiphon.ca.

Psiphon: where are its servers, and does it work everywhere?

Worth being clear on what this is first: Psiphon is a standalone app, not a subscription VPN service - there's no account to create, no monthly fee, and nothing to install. You download the .exe (or mobile app) and run it directly, unlike a typical VPN where you'd sign up, install a client, and pick a server from a list.

Psiphon runs a centrally managed network of proxy servers hosted on cloud infrastructure, estimated at somewhere between roughly 26 and 43 countries depending on the source and when it was checked - this kind of thing shifts over time, so treat any specific number as a snapshot, not permanent. Coverage is concentrated mostly in Europe and North America (US, Canada, UK, France among the bigger hubs), with a smaller footprint in Asia-Pacific (India, Japan, Singapore) and essentially no presence in South America, Africa, or Australia. In countries with heavier censorship, Psiphon also leans on additional workarounds beyond its core server list - mirrors, alternate proxies, even distributing working configs through channels like Telegram - since a fixed list of server addresses is exactly what a censor would just block.

Real-world status varies a lot by country. Russia has blocked Psiphon outright since December 2021, alongside most major VPN and circumvention tools - it still partially works there through those alternate access methods, but it's an ongoing fight, not a sure thing. India hasn't blocked it, but the legal environment is trending more hostile: a 2022 data-retention law technically applies to VPN/circumvention providers, though enforcement has largely failed since providers just relocate infrastructure outside Indian jurisdiction - and a stricter framework aimed specifically at circumvention tools has reportedly been in development. Bottom line: don't assume it'll work the same way in every country - check current status for your specific situation before relying on it somewhere access really matters.

TOR

The Onion Router is built of layers...like an onion. Originally developed by US Military's DARPA it has become known as the "Dark Web". While there is a lot of dark stuff there, I believe the main reason it is "dark" is that it is invisible to the rest of the internet including search engines. It can only be accessed via the TOR network. It uses a modified mozila browser as a base (Firefox) so all of your activites pass through a web interface.

TOR is not a VPN. It is not intended to hide you in the same way. TOR is a network of volunteers offering access to their computers and networks to serve as a relay to take your input and pass it along to another relay and eventually to an "exit node" and on to your destination. Because TOR exit nodes are well known IP many sites may block your access if you are using TOR. This is less of a problem for VPN's though it can happen there. At least a VPN allows you to disconnect and reconnect to a different location and IP. You can chose another ID on TOR but cannot select any specific country or route and you will still come out of a known exit node. Your ISP will know you connected to a TOR entry node.

TOR is all volunteer and there are no fees, not terms of service and no logs on activities. No one in between the enterance and exit nodes has a clue who you are or what you are doing. Everything between is encrypted and anonymous.

You can use both. Connect to your VPN first then to TOR and your ISP does not know your using TOR. Combining the two networks enhances your privacy.