What does a VPN actually hide?
Less than the advertising implies, and the honest description is narrow: a VPN encrypts traffic between your device and the VPN server, and replaces your IP address with the server's.
What it genuinely does:
Hides your traffic from the local network. On public Wi-Fi, the network operator and anyone else on it cannot see what you are doing. This is a real benefit, though far smaller than it once was, because the overwhelming majority of web traffic is now HTTPS-encrypted anyway.
Hides your browsing from your ISP, who otherwise sees which domains you connect to. The VPN provider sees it instead — you have moved trust, not eliminated it.
Hides your IP address from sites you visit, which changes apparent location.
Circumvents geographic restrictions, when the service has not detected and blocked the VPN.
What it does not do:
It does not make you anonymous. You are still logged into accounts, still carrying cookies, still identifiable by browser fingerprinting. Sites know who you are because you told them.
It does not stop tracking. Advertising identifiers, cookies, pixels and account activity all continue.
It does not protect against malware or phishing. Beyond bundled extras, encrypting a connection to a malicious site does not help.
It does not hide activity from the sites you use, from your employer on a managed device, or from anyone with access to the endpoint.
The trust question is central. A VPN provider can see everything your ISP could. "No-logs" claims are marketing unless independently audited, and several providers have been found retaining data they denied holding. Free VPNs are especially suspect — the service costs money to run, and if you are not paying, the data usually is the product.
Where a VPN is genuinely the right tool: hostile networks, accessing a work network remotely, and jurisdictions with pervasive ISP-level monitoring.