← All guides

Privacy

What Your eSIM Provider Can See About Your Internet Use

What travel eSIM providers can see about your internet use: metadata, DNS and IP logging compared across Airalo, Holafly, Saily, Yesim and Holiday.com.

By the eSIM Verdict research desk Last checked 19 July 2026 15 min read

Some links on eSIMVerdict are affiliate links. If you buy through them we may earn a commission at no extra cost to you. Commercial relationships never affect rankings or conclusions; our assessments are based on independent research.

A travel eSIM is, functionally, your internet service provider for the duration of your trip. Every website you open, every app that phones home and every video you stream passes through infrastructure that your eSIM provider or its network partners control. That does not mean they can read your messages - almost all modern traffic is encrypted - but it does mean they can observe a surprising amount of metadata: how much data you use, when you use it, which servers you connect to and, unless you change your settings, every domain name your device looks up.

How much of that observation actually happens, and how long the records are kept, varies enormously between providers. Our research compared the published privacy policies of Airalo, Holafly, Saily, Holiday.com and Yesim as they stood on 19 July 2026. One provider publishes retention periods down to the month; another's website policy does not even name the company operating the service. Below we explain where an eSIM provider sits in the technical chain, what it can and cannot see, what the five policies actually say, and which mitigations genuinely reduce your exposure.

At a glance

  • Your eSIM provider and its partner carriers can see traffic volumes, timestamps, destination IP addresses, unencrypted server names (SNI) and, if you use the default carrier DNS, your full domain lookup history.
  • They cannot see the content of HTTPS traffic, which is the overwhelming majority of web and app traffic in 2026.
  • Holafly publishes the clearest retention schedule of the five: connection history is kept for 6 months, contract data for 7.5 years after termination.
  • Saily is owned by Nord Security, the NordVPN company; its policy names its analytics partners and sets retention at 3 years for plan data and 10 years for billing records.
  • The privacy policy published on holiday.com is dated September 2024, names no operating company, never mentions eSIM service and contains a clause permitting information to be shared or sold to marketing partners - at odds with the app's "no data collected" declaration on Google Play.
  • Where your traffic exits to the internet determines which country's laws govern the records; a 2025 Northeastern University study found travel eSIM traffic routinely breaks out in Hong Kong, Singapore and other third countries.

The technical chain: where your provider sits

When you use a travel eSIM, your data takes a longer path than it would on a domestic SIM. Your device attaches to a local radio network in the country you are visiting. But travel eSIMs are roaming products: your traffic is usually tunnelled from that visited network back to the core network of the sponsoring operator whose profile your eSIM carries, and only there does it exit, or "break out", to the public internet. The brand you bought from usually sits one layer further up still, as most consumer travel eSIM brands are resellers buying connectivity from wholesale aggregators.

This matters for two reasons. First, whoever operates the breakout point can observe your traffic metadata regardless of what the consumer brand's privacy policy says, because the packets physically transit its network. Second, the breakout country sets the legal jurisdiction for interception and data retention, a point we cover in detail in our guide to eSIM traffic routing.

A 2025 Northeastern University study, "eSIMplicity or eSIMplification? Privacy and Security Risks in the eSIM Ecosystem", tested 25 travel eSIM services including Airalo and Holafly and found that "in almost all cases the device's public IP address did not correspond to its physical location". The researchers observed an Ireland-based Holafly connection breaking out through China Mobile's Hong Kong network, documented resellers with access to user identifiers such as IMSI numbers, and found one wholesale platform that could locate an active eSIM profile to within roughly 800 metres.

What is visible to your eSIM provider

The realistic visibility of your eSIM provider and its upstream partners breaks down as follows.

Always visible: volumes and timing. Billing depends on metering, so every provider records how many megabytes you used and when. Session records typically include start and end timestamps, the visited network, and your device identifiers (IMEI and IMSI). Yesim's policy, for example, lists "number of minutes of voice call (incoming or outgoing), megabytes of data (incoming or outgoing), messaging (SMS)" among the data it processes.

Visible on the wire: destination IP addresses and SNI. Whoever operates the breakout point can log which server IP addresses you connect to. For most websites that is enough to identify the service, and TLS adds a further clue: the Server Name Indication field "includes the hostname in the Client Hello message, or the very first step of a TLS handshake" (Cloudflare). In plain terms, the exact domain you are visiting is sent unencrypted at the start of most secure connections, unless both your browser and the website support Encrypted Client Hello, which in 2026 is still far from universal.

Visible by default: DNS queries. Unless you configure encrypted DNS, your device sends every domain lookup - every site, every app backend, every tracker - to resolvers assigned by the carrier. This is the single richest browsing record an access network holds.

Coarse location. The network always knows roughly where you are, because it must route calls and data to your device. For a travel eSIM this is typically cell-level or city-level rather than GPS precision, but the Northeastern study shows wholesale platforms can query it. What this means for lawful access requests is covered in our guide to eSIMs and government tracking.

What is not visible

HTTPS content is off limits. The pages you read, the messages you send in Signal or WhatsApp, your banking sessions, your passwords: all of this is encrypted between your device and the destination server. No eSIM provider, aggregator or carrier can read it without breaking TLS, which they cannot do silently. Holafly's policy makes the point from the other direction, stating that its network partners "only access technical data required for connectivity and cannot see details such as names, emails, payment information, or browsing activity".

The honest summary: your provider sees the envelope, not the letter. But envelopes - who you talked to, when, how often, for how long - are exactly what advertising profiles and legal disclosure requests are built from.

The privacy policies compared

Provider Controller and jurisdiction Usage data logged (per policy) Published retention Analytics and sharing disclosures
AiraloAiralo Policy does not attach data terms to a named national regulator in the summary sections; GDPR-style rights offered IP address, device data, pages visited and time on page, location derived from IP and device "Only for as long as we need it", plus legal and eKYC retention duties; no fixed schedule Service providers, distribution partners, Trustpilot; marketing events
HolaflyHolafly Holafly Limited, Dublin, Ireland (GDPR) Site interactions, IP, device data, ID documents where required; IMSI, MSISDN and IP shared with carriers Contract term plus 7.5 years; connection history and call recordings 6 months Third-party providers for advertising and communications; carriers get technical data only
SailySaily Saily Inc., Delaware, USA; part of Nord Security group Account activity, network usage data, IP in access logs; call detail records and SMS metadata for its number service Plan data 3 years from last use; billing 10 years; marketing lists 1 year after last plan Google Analytics, Firebase, Stripe, PayPal, Adyen, Nord group companies named
Holiday.com No entity named in the website policy; app developed by Expressco Services, LLC (ExpressVPN family) Site policy covers clicks, browser type, IP, referring URL, timestamps; silent on mobile network data "Unless and until you ask us to delete"; no schedule Policy permits sharing or selling information to "marketing partners and affiliates"; Play Store listing declares no data collected
YesimYesim Genesis Group AG, Baar, Switzerland (Swiss FADP and GDPR) Call minutes, data megabytes, SMS counts, IP, device metadata, behavioural analytics "As long as necessary"; no specific timeframes Payment, fraud prevention and connectivity partners; analytics tools in app and site

Airalo: broad collection, vague retention

Airalo's policy discloses collection of IP address, device information, page-level browsing behaviour on its own services and location inferred from IP and device. Retention is framed as "only for as long as we need it, or are required legally to retain it", with identity documents held longer where eKYC rules apply. There is no published schedule, which makes it impossible to say when a given record disappears. Sharing covers hosting, payments, distribution partners and the review platform Trustpilot. For the service itself, see our full Airalo review.

Holafly: the clearest retention numbers

Holafly Limited, registered in Dublin, publishes the most specific schedule of the five: customer contract data is kept for the contract term plus 7.5 years, while "connection history and call recordings" are kept for 6 months. It also states which technical identifiers - IMSI, MSISDN and IP addresses - flow to network carriers. A 6-month connection history is a genuine log of your usage metadata, but at least you know it exists and when it ends.

Saily: Nord Security ownership cuts both ways

Saily is Nord Security's eSIM, launched by the company behind NordVPN, and the corporate controller is Saily Inc. in the United States with group entities including Saily UAB in Lithuania. The VPN heritage shows in the product: the app offers a virtual location feature with "115+ virtual locations", an ad blocker and web protection, which are traffic-filtering features a plain eSIM does not have. The policy is unusually specific about partners (Google Analytics, Firebase, Stripe, PayPal, Adyen) and retention: data plan data 3 years from last usage, billing information 10 years, marketing contact 1 year after your last plan. It states plainly that "we do not record the content of your voice calls". Those are long retention windows, but they are at least published. More in our Saily review.

Holiday.com: strong product, weak paperwork

Holiday.com's eSIM is built by the ExpressVPN team, and the Android app is published by Expressco Services, LLC. The Google Play data safety declaration states "no data collected" and "no data shared with third parties". Yet the privacy policy linked from that listing, last updated 30 September 2024, names no operating company, never mentions eSIM or mobile service, and includes the clause: "We may share or sell your Active and/or Passive Information to our marketing partners and affiliates." Our research suggests this is a generic legacy document rather than a description of the eSIM's actual practice, but a privacy-branded company should not leave it standing. Note also that the eSIM does not include a VPN and does not change your IP address; ExpressVPN sells that separately.

Yesim: Swiss base, open-ended retention

Yesim's controller is Genesis Group AG in Baar, Switzerland, operating under the Swiss Federal Act on Data Protection and GDPR. Swiss jurisdiction is a modest plus. The policy is candid that it processes call, data and SMS volumes, IP address, device metadata and "activity logs and behavioural analytics data", and lists payment, fraud prevention and connectivity partners as recipients. Retention is defined only as "as long as necessary", with no timeframes. See our Yesim review for the wider service.

Advertising and analytics: the other data stream

Network metadata is only half the picture. The apps and websites you buy eSIMs through run their own trackers, disclosed to varying degrees in the same policies. Saily names Google Analytics and Firebase. Yesim discloses behavioural analytics and diagnostics tooling. Airalo describes open-rate and click-through tracking and sharing with distribution partners. Holiday.com's website policy contains the broadest marketing language of the five. None of this touches your browsing traffic on the eSIM itself, but it shapes the customer profile each company holds, and it is the data most likely to feed advertising systems.

Jurisdiction: breakout location decides whose rules apply

Records are governed by the law of the place where they are created and held. If your traffic breaks out in Hong Kong, Singapore or an EU member state, the retention and lawful-access rules of that jurisdiction apply to the carrier-side logs, whatever the consumer brand's policy says. The Northeastern study found breakout locations were frequently undisclosed and sometimes surprising, including traffic transiting Chinese-operated infrastructure. Before relying on any provider's policy, it is worth understanding where your traffic actually exits, because the sponsor carrier at that exit point is a data controller you never chose.

Mitigations and their limits

Encrypted DNS. Switching your device or browser to DNS over HTTPS or DNS over TLS (Cloudflare 1.1.1.1, Quad9, NextDNS) removes the richest single record - your lookup history - from the carrier's view. Limits: the destination IPs and SNI hostnames of your actual connections remain visible, and your chosen DNS provider now sees the queries instead.

A VPN. A VPN tunnel hides destination IPs, SNI and DNS from the eSIM provider and every carrier in the chain; all they see is an encrypted stream to one VPN server, plus volumes and timing. It also fixes the jurisdiction problem by moving your breakout point to a country you choose. Limits: the VPN provider now occupies exactly the position the carrier held, so you are trading one observer for another and should choose accordingly. Traffic volume and timing patterns remain visible to the carrier regardless. Our guide to the best eSIMs for VPN users covers which providers work smoothly with tunnels; note that Saily's virtual location feature is itself a tunnel of this kind.

What does not help. Incognito mode does nothing at the network layer. And "privacy-branded" marketing is not a control: check the policy, not the tagline.

Advantages and disadvantages

Advantages of travel eSIMs for privacy

  • No retail ID checks in most destinations, unlike many local SIM purchases; compare eSIMs with local SIMs on this point.
  • HTTPS keeps content unreadable regardless of provider.
  • Some providers (Holafly, Saily) publish concrete retention schedules you can hold them to.
  • Breakout abroad means your home carrier no longer sees your travel browsing metadata, unlike roaming on your domestic plan.

Disadvantages

  • Metadata - volumes, timestamps, destination IPs, SNI, default DNS - is visible to parties you did not pick.
  • Breakout jurisdiction is often undisclosed and can be a third country with weak oversight.
  • Retention at some providers is open-ended ("as long as necessary").
  • Reseller chains mean wholesale platforms hold identifiers and coarse location for profiles they serve.

Who should choose what

  • You want documented, finite retention: Holafly's 6-month connection history and published schedule is the clearest commitment of the five.
  • You want privacy tooling built in and named processors: Saily, with the caveat that its 3-year and 10-year retention windows are long and its parent is a US entity.
  • You want European or Swiss jurisdiction for the customer relationship: Holafly (Ireland) or Yesim (Switzerland).
  • You already run a VPN on every device: the provider's policy matters far less; pick on price and coverage using our budget eSIM guide, and route everything through the tunnel.
  • You care most about the app not tracking you: Holiday.com's Play Store declaration is the strongest on paper, but the contradictory website policy needs resolving before we would rely on it.

The verdict

No travel eSIM is a privacy product. Every provider here can, directly or through partners, observe when you are online, how much you transfer and which services you connect to; that is inherent to operating an access network, not a scandal. The meaningful differences are in documentation. Holafly publishes the most concrete retention schedule. Saily is the most transparent about processors, though it keeps records for years and answers to US law. Yesim offers Swiss jurisdiction but open-ended retention. Airalo is broad but vague on timelines. Holiday.com has the best app-store declaration and the weakest website policy, an inconsistency we hope the ExpressVPN team fixes.

Whichever provider you choose, two settings change the picture more than any policy: encrypted DNS removes your lookup history from the carrier path, and a reputable VPN reduces the provider's view to volumes and timing. If your browsing abroad genuinely needs to stay private, configure both and treat the eSIM as what it is - a pipe.

Frequently asked questions

Can my eSIM provider see which websites I visit?

Partially. It or its network partners can see the IP addresses you connect to, the unencrypted SNI hostname in most TLS connections and, if you use default settings, your DNS lookups. That reveals which sites and apps you use, but not what you do on them.

Can my eSIM provider read my messages or emails?

No. WhatsApp, Signal, iMessage and modern email connections are end-to-end or transport encrypted. The provider sees that your device exchanged traffic with those services, including timing and volume, but not the content.

Does a VPN hide everything from my eSIM provider?

Not everything. A VPN hides destinations, SNI and DNS, leaving the provider only volumes, timestamps and the VPN server address. Usage patterns remain visible, and your trust shifts to the VPN operator, who now sees what the carrier would have seen.

Which travel eSIM provider logs the least?

None of the five claims a no-logs network. Holafly publishes the shortest concrete window for usage records (6 months of connection history). Holiday.com's app declares no data collection on Google Play, but its website policy contradicts that, so we cannot yet call it the lightest logger with confidence.

Does my eSIM provider know my location?

Roughly, yes. Any mobile network must know which cells serve your device, and the 2025 Northeastern study showed wholesale eSIM platforms could locate active profiles to within about 800 metres. This is coarser than GPS, and it is separate from any app-level location permission you grant.

Sources and fact-checking notes

  • Airalo data collection, sharing and retention - https://www.airalo.com/more-info/privacy-policy - accessed 19 July 2026
  • Holafly controller, carrier data sharing, 7.5-year and 6-month retention - https://esim.holafly.com/privacy-policy/ - accessed 19 July 2026
  • Saily controller, partners, 3/10/1-year retention, call content statement - https://saily.com/legal/privacy-policy/ - accessed 19 July 2026
  • Saily ownership by Nord Security - https://nordsecurity.com/blog/stress-free-travel-esim-saily - accessed 19 July 2026
  • Saily virtual location, ad blocker, web protection - https://saily.com/security-features/ - accessed 19 July 2026
  • Yesim controller (Genesis Group AG), data categories, Swiss FADP - https://yesim.app/privacy-policy/ - accessed 19 July 2026
  • Holiday.com website privacy policy text and 30 September 2024 date - https://holiday.com/privacy-policy - accessed 19 July 2026
  • Holiday.com app developer (Expressco Services, LLC) and Play data safety declaration - https://play.google.com/store/apps/details?id=com.holiday.esim - accessed 19 July 2026
  • Holiday.com eSIM has no VPN and cannot change IP address - https://www.tomsguide.com/computing/vpns/expressvpns-holiday-com-esim-is-a-dream-for-privacy-focused-jet-setters and https://www.expressvpn.com/blog/introducing-holiday-com-esim/ - accessed 19 July 2026
  • Northeastern University study (traffic breakout, IMSI exposure, 800 m location accuracy) - https://www.itnews.com.au/news/travel-esims-secretly-route-traffic-over-chinese-and-undisclosed-networks-study-619659 - accessed 19 July 2026
  • SNI visibility in the TLS handshake and Encrypted Client Hello - https://www.cloudflare.com/learning/ssl/what-is-sni/ - accessed 19 July 2026

Photo credits: Japanexperterna.se (CC BY-SA 2.0), Carl Lender (CC BY 2.0), all via Wikimedia Commons.