VPN On, Still Tracked: Telemetry and the Quiet Power of Fingerprinting
How telemetry and fingerprinting work, and what to change today
Welcome to the first installment of a ten article browser series running throughout 2026. We’re starting with fingerprinting and telemetry, and next we’ll dig into a rare win for user privacy: “What is the privacy trifecta that Mullvad and Brave achieved?
You turn on a VPN, open a private window, and do everything “right.” Then the same ads show up anyway. The same products follow you from site to site. It can feel like the internet has a memory you can’t erase.
Most of the time, it’s not a mystery. Two different systems are working in parallel: telemetry (what your browser may send back to the company that made it) and fingerprinting (what websites learn about your device so they can recognize it again).
If you’re an everyday user who just wants a calmer, quieter browsing experience, this is good news. You don’t need to become technical. You need to understand what’s happening, pick a few high impact settings, and stop doing the “privacy habits” that accidentally make you easier to identify.
Why it matters
Tracking is often framed as “just ads,” but it’s really about profiles. Those profiles influence what content you see, what prices you get tested on, and what assumptions get made about you.
It also matters because cookie cleanup is no longer the whole game. Fingerprinting can identify your browser using device and browser characteristics, even if you clear cookies and even if you use a VPN. EFF describes fingerprinting as creating an identifier from many small details such as screen resolution, time zone, and software versions.
The goal here is not perfect invisibility. It’s fewer signals leaving your device, fewer stable identifiers following you around, and fewer surprises.
4) Browser Telemetry
Telemetry (tracking by the browser maker):
Major browsers offer settings that can send usage data and diagnostics back to their makers.
In Chrome, if “Help improve Chrome’s features and performance” is enabled, Chrome can send usage statistics such as how you use the browser, system information, performance, settings, and preferences.
In Microsoft Edge, optional diagnostic data can include feature usage, performance data, site load times, memory usage, and notably, websites you visit.
In Firefox, “technical and interaction data” is a defined setting you can turn off in Privacy and Security.
In Safari, Apple’s Safari privacy information notes that Fraudulent Website Warnings may send information to Google (and in some regions Tencent), and those parties may log your IP address when information is sent to them.
Fingerprinting (tracking by websites):
Websites can recognize you by combining “bits” of information your browser reveals to make the web work. EFF explains that the combined details can become a stable identifier derived from device and browser characteristics.
One important clarification:
A VPN primarily changes what websites learn about your network location (your IP address). It does not automatically change what your browser reveals about itself, which is why fingerprinting can still work. (This is a general principle. Needs verification: your VPN provider may bundle additional features like tracker blocking, but that is separate from the VPN tunnel itself.)
How it works
Telemetry: the built in reporting channel
Telemetry is usually framed as “help improve the product.” Sometimes it’s crash reports. Sometimes it’s performance and feature usage. Sometimes it’s more sensitive than people realize.
Edge is unusually clear that optional diagnostic data can include websites you visit, and it explains how to toggle that setting in the browser.
Chrome is clear that usage statistics can include a broad mix of usage and system information when the setting is enabled.
Firefox is clear about its “technical and interaction data” setting and where to disable it.
Safari’s Fraudulent Website Warning is a security feature, but it is also an example of “your browser talks to someone else” in the background, including third parties like Google in some cases.
The takeaway is simple: telemetry is not always “bad,” but it should be a choice you make consciously, not a default you never check.
Fingerprinting: recognition without cookies
Fingerprinting works by collecting many small details and combining them. EFF’s description includes examples like screen resolution, time zone, operating system version, and more.
This is why customization can backfire. Each extension, font, setting tweak, and unusual configuration can make you more unique. If your browser looks like a rare combination, it stands out.
Tor Browser’s approach is instructive even if you never use it day to day. Tor tries to make many users look similar by using defenses like letterboxing, user agent spoofing, and first party isolation.
Cross site tracking: pixels plus identifiers
Fingerprinting is one piece. Another is third party tracking embedded across many sites.
Meta Pixel is a common example. Meta describes it as JavaScript code used to track visitor activity on a website by loading a library of functions and sending events.
That pixel can connect “you visited this page” to “show you ads elsewhere,” especially when combined with other identifiers.
What to do about it (numbered list, quick wins plus hardened set)
These steps focus on everyday users and the four big browsers: Chrome, Edge, Safari, and Firefox.
Turn off telemetry you don’t want.
In Chrome, review “Help improve Chrome’s features and performance” and turn it off if you prefer not to send usage statistics and crash reports.
In Edge, review “Send optional diagnostic data to improve Microsoft products” and decide whether you want that on, especially since it can include websites you visit.
In Firefox, uncheck “Allow Firefox to send technical and interaction data to Mozilla.”
In Safari, review Fraudulent Website Warning with the right mindset: it’s a safety feature, and disabling it can reduce some data sharing, but it can also reduce protection from phishing. Apple notes information may be sent to Google (or Tencent in some regions) and those parties may log IP addresses.Block third party cookies, and use your browser’s built in tracking protections.
Firefox’s Total Cookie Protection separates cookie storage by site to reduce cross site tracking.
Safari’s WebKit tracking prevention work includes partitioning third party storage and other protections, and it documents “anti fingerprinting” as part of its approach.
Edge includes Tracking Prevention with levels such as Balanced and Strict, designed to reduce tracking with different compatibility tradeoffs.Keep extensions lean, because uniqueness is the enemy of anti fingerprinting.
Aim for a small set of trusted extensions, rather than stacking many “privacy” add ons.Recommended extension set (with caveats).
If you want one practical baseline, a strong approach is a single, reputable content blocker. uBlock Origin is widely used, and the uBlock Origin project notes that Chrome users may need uBlock Origin Lite (Manifest V3) while the full extension remains available for Firefox, and currently for Edge.
Caveat 1: Chrome is phasing out Manifest V2, which affects extensions like the original uBlock Origin, so you may need an MV3 compatible blocker such as uBlock Origin Lite.
Caveat 2: On Safari, extension style blockers work differently, and uBlock Origin’s own documentation notes Safari support was dropped after Safari 13. If you use Safari, consider built in protections first, then add a reputable content blocker app if you want one. (Needs verification: which specific content blocker is best for your needs and region.)Use a stable browser setup and stop constantly tinkering.
Pick a reasonable configuration and keep it consistent. Frequent changes can increase uniqueness. The paradox is that obsessive tweaking can make you more identifiable.Separate “everyday browsing” from “sensitive browsing.”
For everyday life, a hardened profile is usually enough. For higher sensitivity, consider a separate browser or profile with stronger defaults. Tor Browser is designed to reduce fingerprinting by making users look more similar.
If you prefer staying in Firefox, Resist Fingerprinting exists as an advanced setting in about:config, but it can cause site breakage and it does not “turn Firefox into Tor.”Treat a VPN as one layer, not the solution.
A VPN is still useful for network privacy, but fingerprinting happens higher up in the stack. Pair the VPN with browser hardening if your goal is to be tracked less.Measure before and after so you don’t guess.
Start with your current baseline, change one setting, then retest. This prevents “security theater” and helps you keep only what makes a real difference.
If you want to learn by testing, my Tools page includes a digital risk calculator, a tracker simulator, and a fingerprint auditor:
https://cyberlifecoach.pro
Framework tie in
A simple mapping that fits this topic is the NIST Privacy Framework.
Identify P: Understand what data is processed and by whom. In practice, that means distinguishing telemetry (browser maker) from fingerprinting and pixels (websites and third parties).
Control P: Adjust settings to manage collection and sharing. Turning off optional diagnostic data, blocking third party cookies, and limiting permissions are direct control moves.
Protect P: Reduce exposure to privacy harms. Using strong tracking prevention modes, keeping a lean extension set, and using anti fingerprinting approaches in high sensitivity contexts are protective habits.
Takeaway
Call to action
Test your setup and learn what actually changed with my tools, including a digital risk calculator, a tracker simulator, and a fingerprint auditor:





To avoid tracking, NymX CLI allows users to use the Nym Mixnet free of charge, while using NymX as a modern smtp(s) and ftp(s) replacement. And it uses SURBs so that the receiver of any kind of data does not know from where the anonymous data originated.
https://github.com/Ch1ffr3punk/NymX
Best regards
Ch1ffrepunk
the VPN hides your traffic fro your local WiFi and ISP. “Value-added” VPN’s add malware scanning & blocking, ad & tracker blocking - for a fee. Google Chrome is a big offender. Use an alternate browser, such as Brave, where the developers stripped out the telemetry from Chrome and use anti-fingerprinting technology.