Built-in Browser VPNs Are Not Real VPNs
Opera VPN and Edge Secure Network are browser proxies, not device VPNs. What they protect, what they leave exposed, and when you need the real thing.
Published September 3, 2026· By Juan Martinez

Opera, Microsoft Edge, and Vivaldi all ship a free “VPN” you can switch on with one toggle — no app to install, no account to pay for. It’s a genuinely useful feature. It is also not the same thing as a VPN, and if you turned it on for privacy, you should know exactly what it does and doesn’t cover.
The short version: these are browser proxies, not device VPNs. They protect one application — the browser — and leave everything else on your machine connecting normally. A standalone VPN works one layer down, on the network itself.
What a “real” VPN does that a browser toggle doesn’t
A standalone VPN creates an encrypted tunnel at the operating-system level. Every app that touches the network — your browser, your email client, background updaters, a torrent client, system telemetry — rides through that tunnel. Your ISP sees one encrypted connection to the VPN server and nothing about what’s inside it.
A built-in browser “VPN” tunnels only the traffic of the browser it lives in. Opera states this plainly on its own product page: the free VPN “keeps your activity within the Opera browser private, but does not apply to your internet use outside of Opera.”[1] Vivaldi’s documentation is even more precise about the mechanism — the Proton integration is “a type of VPN called a ‘secure web proxy’, meaning that it only affects the web traffic for Vivaldi, and does not affect the network communications of your other apps.” It doesn’t even cover Vivaldi’s own mail client.[7] Firefox has the same arrangement through a Mozilla account: it proxies only Firefox’s own traffic and, in Mozilla’s words, “does not proxy traffic from other applications on the device.”[8]
There are three more gaps beyond scope:
- You don’t pick a location the way you would with a VPN. Opera’s free tier offers “3 general locations” (broad regions like Europe or Americas), not a country list.[1] Edge doesn’t let you choose at all — it “replaces your geolocation with a similar regional address” automatically.[4] That’s fine for basic IP masking; it’s not enough for reliably appearing in a specific country.
- No kill switch. A standalone VPN can be configured to cut your internet if the tunnel drops, so nothing leaks in the gap. Opera’s free tier doesn’t mention one, and a browser feature has nothing to kill — if it fails, the browser just connects directly and you may not notice.
- No choice of protocol, and limited control. You get what the vendor ships. Opera uses AES-256;[1] Edge routes through Cloudflare’s infrastructure.[4] Those are reasonable, but you can’t tune them, split-tunnel by app, or point specific traffic where you want it.
Edge Secure Network: even inside the browser, not everything is routed
Microsoft Edge Secure Network deserves a closer look because it’s the most conservative of the bunch by design. It’s “a service provided in partnership with Cloudflare,” gives you “5 GB of free data every month” tied to a personal Microsoft account, and in its default “Optimized” mode it only engages “when you visit an unsecure HTTP site or connect to an open Wi-Fi.”[4]
Read that again: by default it doesn’t route your normal HTTPS browsing at all. Streaming and video are explicitly excluded unless you turn them on per-site. There’s a “Select sites” mode where you list specific sites to always route — but out of the box, most of what you do in Edge goes direct. It’s built as a safety net for hostile networks and plaintext connections, not as a general-purpose “hide my browsing” layer, and the 5 GB cap reinforces that — heavy use isn’t the intent.[4]
On logging, Edge is reasonable: your Microsoft identity isn’t shared with Cloudflare, and Cloudflare deletes the diagnostic and support data it collects every 25 hours.[4][5]
“But mine has a no-logs audit”
Opera’s free VPN does, and the detail matters. Deloitte examined Opera’s free-VPN infrastructure for desktop, Android, and iOS between 18 June and 10 August 2024 — server configuration, deployment process, internal policies — and attested to Opera’s assertion that there is “no data logging functionality built into the VPN service, and no data whatsoever is collected about users’ browsing activity, browsing history, originating network address, or other identifying information.”[2] That’s a real audit, on the same footing as the audits some standalone VPNs publish.
It doesn’t change the category. The audit covers whether Opera logs your activity; it says nothing about the fact that the feature only protects one browser, gives you three regions instead of a country list, and has no kill switch. An audited proxy is still a proxy. (For context on what a no-logs audit does and doesn’t tell you, see What Is a No-Logs Audit?.)
One more thing to weigh if the built-in VPN is your only privacy layer: Opera’s consumer browser is controlled by Kunlun Tech, a China-based technology group that holds roughly 70% of the voting power.[3] That doesn’t override an independent audit, but jurisdiction and ownership are part of the picture.
Brave’s “Private Window with Tor” is a different thing again
Brave doesn’t have a built-in VPN, but its “Private Window with Tor” gets mistaken for one, so it belongs here. It routes that window’s traffic through the Tor network — three volunteer relays — so sites don’t see your real IP. But Brave is explicit that it’s not Tor Browser: “Private Windows with Tor Connectivity in Brave are just regular private windows that use Tor as a proxy. Brave does NOT implement most of the privacy protections from Tor Browser.”[6]
That means no anti-fingerprinting hardening, sites can tell you’re on Tor, and — in Brave’s own words — “some websites may be able to discover your real IP address, and someone watching your network traffic may be able to discover what sites you visit, if they are determined to.”[6] Brave’s own advice: “if your personal safety depends on remaining anonymous, we highly recommend using Tor Browser instead of Brave Tor windows.”[6] It’s a convenience feature for casual IP-hiding, desktop-only, and it’s a Tor proxy — not a VPN, and not full Tor Browser. Our Brave review covers where it fits, and VPN vs Proxy vs Tor covers how these tools differ as a class.
When the browser toggle is fine — and when it isn’t
Use a built-in browser “VPN” when you want to:
- Hide your IP from a specific website you’re visiting in that browser
- Get past a basic geo-block on a site (with the caveats above about region vs country)
- Add a layer on untrusted Wi-Fi for your browser session
Reach for a standalone VPN when you want to:
- Cover the whole device — every app, not just one browser
- Choose a specific country, tune the protocol, or split-tunnel
- Have a kill switch so a dropped connection doesn’t leak
- Rely on it as a real privacy layer rather than a convenience
The two aren’t competitors; they operate at different layers. If you want the device-wide kind, our Best VPN for Privacy picks are independently audited, no-logs options. If you mostly care about what your browser reveals, that’s a browser problem — start with the private browsers we’ve reviewed.