Wi-Fi security · Plain-English answer
It is a sensible habit. A VPN wraps all your traffic in encryption before it leaves your device, so the hotspot operator and anyone else on the network cannot see which sites you visit or interfere with your connection. It also covers apps that handle encryption poorly. It cannot vet the hotspot itself.
HTTPS already encrypts most website content, so the VPN's contribution on public Wi-Fi is everything HTTPS leaves out. It hides which domains you visit from the network, covers apps and background services that use weak or no encryption, and makes tampering with your traffic, such as injected redirects on sketchy hotspots, ineffective.
Crucially, it protects you even when you have connected to a malicious network without realising, because your traffic is already sealed before the network touches it. That converts the worst case scenario from disaster into inconvenience.
Connect the VPN immediately after passing any captive portal login, and leave the kill switch on so a momentary drop cannot spill traffic onto the open network. Keep the Allow LAN option off in public places, since you do not want to be reachable by strangers' devices.
ROOT keeps no activity logs and its free tier needs no card, so there is no cost barrier to making this routine. After connecting, a quick glance at /tools/my-ip/ confirms the tunnel is carrying your traffic.
ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.
Get ROOT VPN, free