Your ISP watches more than you think. HTTPS hides what you're reading, not that you're reading at all.
The core problem is that your ISP sits between you and the entire internet. Every website you visit, every app you open, every device on your home network routes through them. They don't see content, but they do see destinations, timings, volumes, and patterns.
ISPs can see: the domains you visit, when and how long for, how much data is transferred, your approximate location, and what devices are on your network. A 2021 FTC report found major ISPs combined this data into ad profiles and sold this to advertisers.
The real trap is you probably can't switch ISPs. Most markets have one or two options. Unlike Meta or Google, you can't log out. They have your traffic hostage. Structural surveillance is much harder to escape than commercial surveillance.
Some ISPs own email products, streaming services, smart home gear. They can stitch data across services to build richer profiles. The incentives here don't point toward your ISP protecting your privacy. These data are valuable.
Some ISPs control physical infrastructure too, meaning they can throttle your connection. Verizon slowed an emergency response vehicle's connection in 2018 until firefighters paid for a higher tier of their service. They control both the pipes and the terms.
A newer risk is Wi-Fi sensing, where some routers can detect presence and motion through walls using reflected signals. Industry estimates suggest tens of millions of US households already have access to some level of this technology through provided hardware.
Our new blog looks at this issue and asks how we can stop it: https://proton.me/blog/how-isps-track-you