Culvert VPN

Should you use a VPN at home?

At home the Wi-Fi is yours, so a VPN mainly hides site names and DNS from your ISP and keeps your home IP out of websites' logs. Useful, not essential.

Privacy: who sees what · 4 min read · By Culvert VPN

At home the Wi-Fi is yours, so the biggest reason to use a VPN elsewhere, the network owner watching your traffic, does not apply. What remains is your ISP, which sees every site name and DNS lookup that leaves the house, and your home IP address, which is stable for weeks and appears in the logs of every site you visit. A VPN at home hides the first and replaces the second. Whether that is worth a little speed and some fiddling with local devices depends on how much either bothers you.

What is different at home

On public Wi-Fi three parties can see your traffic: whoever runs the network, other people on it, and the ISP behind it. At home the first is you and the second is your household, which leaves the ISP. That is a smaller threat, but it is not nothing, and it is the one that has your name and address on file.

The other difference is that home traffic is easy to attribute. A café's address is shared by hundreds of strangers a day. Your home address is shared by the people who live there, held for weeks or months, and tied to a physical location by the ISP. A site that logs it has logged where you live.

What your ISP sees at home

Without a VPN: the DNS name of every site anyone in the house visits, because the router uses the ISP's resolver by default; the server name in every HTTPS handshake; every destination address; and the volume and timing. The ISP post goes through each. Whether your ISP does anything with that view, from nothing at all to selling categories of it to advertisers, depends on where you live and on the ISP, and its own privacy policy is the place to find out.

With a VPN on your phone: the ISP sees one encrypted stream from your phone to the VPN server. The rest of the household's traffic is unchanged, because a VPN app on your phone covers your phone.

Reasons to leave it on at home

  • You would rather your ISP did not have a list of site names. This is the main one. It is not about hiding anything in particular; it is that the list exists and you did not agree to it.
  • You do not want your home address in every site's logs. A shared VPN exit address replaces it. Sites you sign in to still know you; sites you do not are left with an address shared by many people.
  • Consistency. A VPN that is on at home is already on when you walk out of the door onto a café network. Android's Always-on VPN makes this automatic and is easier to trust than remembering to switch it on.
  • Your home network is not entirely yours. Shared houses, landlord-provided internet, and ISP-supplied routers you cannot log in to all move "home" some way toward "someone else's network".

Reasons to leave it off, or to make exceptions

  • Local devices. With a VPN routing all traffic to a remote server, your phone can lose sight of things on the same Wi-Fi: casting to a TV, a printer, a smart speaker, a home camera. Some VPN apps keep local addresses reachable; many do not.
  • Speed. A nearby server on a modern phone costs a few milliseconds and a little throughput. A distant one costs more. Home is where you notice most, because home broadband is usually the quickest connection you use. The speed post explains what to expect.
  • Sites that treat shared addresses with suspicion. Extra login checks and more frequent CAPTCHAs are common from a VPN address, because many people share it.
  • Banking and other apps that check location. Some flag a sign-in from a new city as suspicious, which a VPN exit in another country will trigger.

Most of those are reasons for an exception rather than for turning the VPN off. Split tunnelling handles them: pick the apps that should stay outside the tunnel, the banking app, the casting app, and leave everything else inside. The split tunnelling post explains how Android does it and why an exclude list, where apps installed later are protected by default, is the safe way round.

A sensible default

For most people: leave the VPN on with Always-on enabled, exclude the two or three apps that need to see the local network or your real location, and pick the nearest healthy server so the speed cost stays small. That gets the ISP out of the site-name business and keeps your home address out of logs without daily attention.

On the provider side, the trade is that the VPN now has the view the ISP had. Culvert VPN does not log the websites you visit, your DNS queries or the contents of your traffic; its servers see only an opaque connection id, and it keeps your client IP address for up to 30 days for abuse handling, as set out in its privacy policy.

For a VPN that stays on at home without getting in the way, Culvert VPN works with Android's Always-on setting, lets you exclude the apps that need the local network, and picks the nearest healthy server for you, on Google Play.

Questions people also ask

Does a VPN on my phone protect the other devices on my home Wi-Fi?

No. A VPN app on your phone carries your phone's traffic only. Everything else in the house still talks to the internet directly through the router.

Why can't I cast to my TV when the VPN is on?

With the tunnel up, your phone's traffic is routed to the VPN server, and it can lose sight of devices on the same Wi-Fi. Exclude the casting app with split tunnelling, or pause the VPN while you set it up.

Will a VPN at home slow my broadband down?

A nearby server on a modern phone costs a few milliseconds of latency and a little throughput; a distant or busy one costs more. Home broadband is usually the quickest connection you use, so it is where you notice most.