Apple's Private Relay vs VPNs: Different Problems

People call iCloud Private Relay 'Apple's VPN.' Architecturally it's almost the opposite of one — and that difference is the whole point.

The fastest way to misunderstand iCloud Private Relay is to call it “Apple’s VPN.”

Everyone does it. The feature lives under Settings, it hides your IP address, it makes some websites think you’re somewhere you’re not — so people file it in the same drawer as the VPN they downloaded off a YouTube sponsorship. And then they’re surprised when their torrent client still leaks their real address, or when a site still geoblocks them, or when it turns out the thing they thought was protecting their whole phone was protecting exactly one app.

Private Relay is not a VPN. Architecturally it’s closer to the opposite of one. And the difference isn’t pedantic — it’s the entire design, and it tells you precisely what the feature does and doesn’t do.

What a VPN Actually Is

A VPN is one hop to one company. Your traffic goes into an encrypted tunnel, comes out at a server the provider runs, and from there heads to wherever it was going. The local network can’t read the tunnel. The destination sees the VPN’s IP instead of yours.

The catch, which I’ve written about before, is that the VPN provider now sees everything your ISP used to see. You didn’t remove the observer. You swapped a regulated company in your own country for an opaque one incorporated somewhere that sounds privacy-friendly, and called the swap “privacy.” One entity sits in the middle and, by construction, can see both who you are and where you’re going. You’re trusting that they don’t look, or don’t keep it, or don’t get subpoenaed. That’s the model. It’s a single point of trust.

What Private Relay Actually Is

Private Relay is two hops through two different companies that were specifically chosen so that neither one can see the whole picture.

The first hop — the ingress — is run by Apple. It sees your real IP address, because it has to; it’s the thing you connect to. But the hostname you’re visiting is encrypted, so Apple knows who you are and nothing about where you’re going.

The second hop — the egress — is run by a separate content provider, not Apple. It decrypts the destination and makes the outbound connection. It sees where you’re going, but it received your traffic from Apple’s relay, so it never sees your real IP. It knows the destination and nothing about who you are.

That split is the whole invention. In a VPN, one party holds both halves of the secret and you trust them not to combine them. In Private Relay, the two halves are deliberately handed to two parties who’d have to collude to reassemble them — and Apple designed the protocol so that even Apple can’t do it alone. DNS gets the same treatment: Private Relay resolves names using Oblivious DoH, which sends your queries through a relay that separates the resolver’s view of what you’re asking from who’s asking. It’s the same principle applied to the lookup itself.

This is a fundamentally better trust model than a VPN for the narrow thing it covers. Nobody in the path sees both your identity and your browsing. That’s not a stronger version of what a VPN does. It’s a different thing.

The Word “Narrow” Is Doing a Lot of Work

Here’s where the “it’s basically a VPN” people get burned.

A VPN, for all its faults, captures everything. Every app, every protocol, every packet leaving the device goes through the tunnel. Private Relay captures almost none of that. It covers Safari browsing, DNS resolution, and a slice of insecure http:// traffic from apps. That’s the list. Your third-party browser doesn’t use it. Your email client doesn’t use it. Your games, your delivery apps, your work VPN, that random utility that phones home — none of them touch Private Relay. They keep using your carrier’s DNS and your real IP, exactly as before.

So the person who turns on Private Relay thinking they’ve cloaked their device has cloaked their web browsing in one browser. Everything else is wide open. This isn’t a flaw; it’s the scope Apple chose. But the “Apple’s VPN” framing hides it completely, and the gap between what people think they enabled and what they actually enabled is where the trouble lives.

It Won’t Let You Lie About Where You Are

The other tell that Private Relay isn’t a VPN: it refuses to move you.

The entire consumer VPN business runs on picking an exit country. Watch the other region’s catalog, get the cheaper prices, look like you’re in a different place. Private Relay does the opposite on purpose. The egress assigns you an IP that preserves your general region — country-level, and for large countries a broad area within it — specifically so that location-based services keep working and you don’t get dumped into the wrong local results. Apple treats “you still appear to be roughly where you are” as a feature. A VPN treats “you appear to be wherever you paid to appear” as the product. Those are opposite goals, and no amount of squinting makes them the same tool.

And of course, like a VPN, Private Relay does nothing about the identity you hand over voluntarily. Log into an account and the site knows you’re you, IP or no IP. Relaying your address doesn’t relay your cookies, your session, or your login. It never claimed to.

Judge It By the Right Job

Private Relay is a targeted fix for two specific leaks that plain web browsing springs: your IP address, which has quietly become a cross-site tracking key, and your DNS queries, which are a plaintext log of every domain you visit handed straight to whoever runs your resolver. It closes both, for browsing, with a design where no single party can reconstruct your activity. For that job, it’s genuinely good — better than routing the same traffic through one VPN company that sees all of it.

What it isn’t is a device-wide cloak, a way to fake your country, or a reason to skip thinking about the apps that never touch it. Calling it “Apple’s VPN” gets every one of those wrong. It’s not a VPN. It’s a smaller, sharper tool that happens to solve part of the same problem better — and understanding the architecture is the difference between using it for what it’s good at and trusting it for things it never touches.

Continue the conversation

← Back to Blog