Back to the journal

Privacy

What hotel and café Wi-Fi learns about you

Shared networks see more than most travellers assume — not the contents of your messages, but a detailed record of who you talk to and when. Here is what changes when you bring your own connection.

6 min read

Encryption has genuinely fixed the worst problem with public Wi-Fi: the contents of what you send are no longer readable by whoever runs the network. What it has not fixed is everything around the contents, and that surrounding layer is often more revealing than people expect.

Quick takeaways

  • Encryption hides what you said, not who you said it to.
  • A captive portal usually asks for an identifier before it lets you online.
  • Your own mobile connection removes the operator of the network from the picture.
01

The metadata is the part that survives encryption

When you load a page or open an app over a shared network, the operator of that network can see which servers you contacted, roughly how much data moved, and exactly when. They cannot read the message you sent. They can generally tell that you opened a particular messaging app, a particular bank, or a particular dating service, and how long you spent there.

For most travellers, most of the time, this is uninteresting to everybody involved. It stops being uninteresting when the pattern itself is sensitive — a journalist's contacts, a lawyer's clients, a person leaving a situation they do not want traced. Those are not exotic cases, and the point of thinking about it in advance is that you cannot retroactively decide a network should not have seen something.

02

Captive portals collect before they connect

The sign-in page between you and hotel Wi-Fi is not decoration. It commonly asks for a room number, a surname, an email address, or a phone number, and it always records the device identifier it hands access to. That ties a device to a person and a location at a timestamp, in a log kept for as long as whoever runs the network keeps logs.

Airports, cafés, and transit systems do the same with varying degrees of enthusiasm. Reading the terms is rarely worth the time; assuming that the sign-in created a record connecting your device to your name is the safer default, and it is usually correct.

03

Bringing your own connection changes who is in the room

A mobile data connection does not remove intermediaries — a carrier still routes your traffic — but it removes the ones you know least about. You are no longer joining a network run by a business whose security practices you cannot inspect, alongside other guests you cannot see, behind a portal that asked for your surname before it let you online.

It also removes a whole class of practical failure: the hotel network that intercepts DNS, the café router that has not been updated in four years, the transit Wi-Fi that quietly injects into unencrypted pages. A data-only travel eSIM is not a privacy product on its own, but it means the network your phone is attached to is one you brought rather than one you found.

Shared Wi-Fi is not dangerous in the way it was a decade ago, and it is not neutral either. The contents are protected; the pattern, the timing, and the identity you handed over at the portal are not. Carrying your own connection is the simplest way to keep that record from being created at all.

Browse SilentSIM plans