The VPN Your Favorite Creator Sold You
The ad read has not changed in a decade: hackers, coffee shop Wi-Fi, your data. Almost none of that threat still exists. Here is what you are actually buying, and the renewal price they do not say out loud.

You Have Heard This Ad Roughly Four Hundred Times
Someone you watch pauses at the four-minute mark, shifts into their sponsor voice, and explains that when you use public Wi-Fi, hackers can see everything you do. Your passwords. Your bank login. Your identity, which is apparently something a stranger can pick up off the air at a Starbucks like a dropped receipt.
Then a code. Then 72 percent off. Then back to the video.
I have nothing against creators taking money. Ad reads pay for the thing I am watching for free. But I got curious about why this one specific product buys more of them than anything else, and the answer turns out to be more interesting than the product.
The Threat in the Ad Mostly Stopped Existing
The scenario in that ad used to be true, which is why it sold so well. In 2010 a developer released a Firefox extension called Firesheep that let anyone on the same network hijack the logged-in sessions of the people around them. It worked on Facebook, on Twitter, on nearly everything, because those sites sent your session cookie in plain text once you were past the login page.
It was a genuine emergency, and the industry fixed it. Sites encrypted the entire session instead of just the login page. Browsers started shaming plain HTTP with a "Not Secure" label. HSTS made downgrade attacks hard. Let's Encrypt made certificates free, which removed the last excuse small sites had.
Today the overwhelming majority of browsing time happens over encrypted connections. The person at the next table cannot read your bank session. They cannot see your messages. The encryption is happening between your browser and the site, and sitting on the same network does not get you inside it.
What they can still see is the shape of your traffic: which domains you connected to, roughly when, and roughly how much. That is a real privacy leak. It is not the leak in the ad.
You Did Not Remove the Middleman. You Picked a Different One.
Here is the part that reframed the whole thing for me.
Without a VPN, the entity that can see every domain you visit is your internet provider or whoever runs the network you are on. With a VPN, the entity that can see every domain you visit is the VPN company. The traffic still has to exit somewhere, and it exits at their server, unencrypted from that point forward to the destination.
That is not a shield. It is a transfer of trust from a company you did not choose to a company you chose off a YouTube ad.
Sometimes that trade is clearly worth it. US internet providers were freed to sell subscriber browsing data in 2017 when Congress repealed the FCC's broadband privacy rules, and they have every commercial reason to do it. Moving that visibility to a company whose entire business depends on not doing that is a rational swap. But it is a swap, and the ad never frames it as one.
Check Who Owns the Review Site
When I started comparing providers, I did what everyone does and read the roundups. Then I looked at who publishes them.
ExpressVPN was acquired in 2021 by Kape Technologies for around $936 million. Kape also owns CyberGhost, Private Internet Access, and ZenMate. It has also owned VPN review sites, the kind that publish ranked lists. So a meaningful slice of the "best VPN 2026" content industry has been graded by a company that owns several of the contestants.
Kape's earlier life is its own footnote. It was previously called Crossrider, and Crossrider's original business was a browser extension platform with a long, documented history of adware and ad injection. The company pivoted and rebranded years before the acquisitions. I am not saying that makes ExpressVPN bad software. I am saying the privacy company you are trusting with all of your traffic used to be in the business of putting things you did not ask for into your browser, and nobody mentions that in the ad read.
Ownership overlaps elsewhere too. Nord Security and Surfshark merged their holding structures in 2022 while continuing to run as separate brands. So two entries on your shortlist may answer to the same parent, and a head-to-head between them is a narrower contest than it looks. Worth knowing before you read Surfshark vs. NordVPN, and worth knowing that NordVPN vs. ExpressVPN is the one that actually crosses corporate lines.
Audits Are Real, and Narrower Than They Sound
Every major provider now advertises an independent no-logs audit. Deloitte, PwC, Cure53, and Securitum have all done them for one brand or another. These are not fake. They are narrower than the word suggests: an auditor examines configuration and process during a defined window and reports on what they saw.
An audit is a photograph, not a live feed. It does not bind the company's behavior next quarter, it does not cover what a court order might compel, and the scope is set by the client paying for it. Read the actual report and check what was in scope. Most people, including me until recently, read the press release.
Jurisdiction and corporate structure tell you more than any audit does. Proton operates out of Switzerland and open-sources its client apps, which means the code running on your machine can be inspected by anyone rather than vouched for by a vendor. That is a different and, in my opinion, stronger kind of evidence, and it is most of what separates NordVPN vs. Proton VPN and Proton VPN vs. ExpressVPN once you stop counting server totals.
The Renewal Is the Actual Business Model
This is the part I wish someone had told me at nineteen.
The $2.19 a month in the ad is not a monthly price. It is a two-year prepayment, sometimes with three extra months attached, charged as a single lump sum up front. You are handing over roughly $60 to $80 on day one.
Then it renews. Renewal is at or near list price, and list is frequently double or triple the promotional rate, charged annually to the card you forgot was on file. The discount is an acquisition cost. The renewal is the product.
Run the honest number before you subscribe. Take the two-year promo total, add one year of renewal at the real list rate, and divide by 36. That is what the first three years actually cost you per month. For most providers it lands somewhere between $5 and $9 rather than the number on the coupon.
If you subscribe, set a calendar reminder for eleven months out. Not twelve. Eleven, so you are ahead of the charge rather than arguing about it afterward.
Things It Genuinely Does
I am not anti-VPN. I pay for one. It earns its money on a short, specific list:
- Hiding traffic from your ISP or landlord's network. Real, legal, and the strongest everyday argument.
- Networks you do not control. Not because of hackers, but because campus, hotel, and workplace networks log and filter, and some inject.
- Censorship and travel. If you are somewhere that blocks a service you rely on, this is the tool.
- Torrenting. Whatever you are downloading, your ISP sees the swarm without one.
- Region-shifting streaming. Works inconsistently, violates the terms you agreed to, and services actively fight it. Do not buy a three-year plan for this.
Then there is the list of things it does not do, all of which the marketing implies it does. It does not stop Google or Meta from tracking you, because you are logged into their services and that is how the tracking works in the first place. It does not stop browser fingerprinting. It does not stop malware. It does not make you anonymous. If your threat model is a government, a consumer VPN is not the answer and you should be reading somewhere more serious than this.
What I Actually Pay For
I run Proton's free tier on my phone and a paid plan on my laptop. The free tier matters because it is one of the only ones not funded by selling something else, and how a free tier gets funded is the right question to ask about any privacy tool you are not paying for. A free VPN with no revenue model has a revenue model. You are it.
If you want the paid version, buy the one-year plan, not the three-year. Put the renewal in your calendar. And when the ad tells you a hacker at the coffee shop is reading your bank password, understand that the specific claim has been false for about a decade, and that everything genuinely useful about the product is stuff the ad has never once mentioned.
Ready to dig into the numbers? We have side-by-side breakdowns for every product mentioned in this article.

