Your Own VPN Server for Five Dollars a Month
Rent a small VPS, run Algo or plain WireGuard, import one config per device. It costs $4-6 per month, you control the whole machine, and no provider logs your traffic - but one exit IP means no anonymity, no streaming catalogs, and you are your own support desk.
The dirty secret of the VPN market is that its core product is a five-dollar-per-month cloud server with a free protocol on top. Renting one yourself removes the subscription, the provider's logging and the trust problem in one move - and costs less than almost every commercial plan [1][2]. It is not the right answer for everyone, but for a specific, common situation it is the best deal in the industry.
What you get
Your own machine at a known address, running your own tunnel, with no operator between you and the server. Connection metadata lives on hardware you control. Nothing to "trust" beyond the hosting provider's physical custody of the machine - which is the same trust any VPN operator asks for, minus the marketing.
WireGuard is the right protocol for this: about 4,000 lines of kernel-audited code (versus OpenVPN's hundreds of thousands), fast, and built into modern kernels, phones, routers and laptops [1].
What you lose
A commercial VPN gives you a pool of shared IPs, streaming-friendly ranges, obfuscation for censored networks, and a support desk. Your single VPS gives you one IP that identifies everything you do on it - shared by your devices, correlated across sites, and useless against IP-based blocking. You also inherit the admin work: kernel updates, SSH hardening, key rotation.
The honest framing: self-hosting is excellent for privacy from the VPN industry, neutral for privacy from websites, and poor for anonymity or catalog-unblocking [3].
The setup, honestly minimal
- Rent a small instance - Hetzner CX22 (EUR 4.51/mo incl. VAT), OVH or Netcup equivalent. Pick a location near you or near what you want to appear as.
- Run Algo (Trail of Bits' setup script) on it:
apt install python3-pip && git clone https://github.com/trailofbits/algo && cd algo && python3 -m venv env && source env/bin/activate && pip install -r requirements.txt && ./algo. It generates a config per device you name and hardens the box [2]. - Install the WireGuard app on your devices and import the config QR/HTML Algo prints.
- Done: every device now tunnels to your own server. Nothing else touches plaintext.
Alternatives: plain WireGuard by hand if you enjoy editing configs [1]; Outline if you want a point-and-click manager with access keys (it left Google for the nonprofit Outline Foundation in 2025) [4]; Streisand, the original generator, is archived and should not be used anymore [3].
The costs and limits, named
- Money: $4-6/month, comparable to the cheapest intro-tier VPN and cheaper than most renewals. No "3-year discount" games because there is no sales team.
- One exit IP: everything you do shares one address. Traffic correlation across sites is trivial for anyone looking. If that bothers you, a commercial VPN's rotating pool is marginally better and a Tor stack is strictly better.
- Streaming: datacenter IP ranges are blocked by the major catalogs. Expect it to fail.
- Censorship: plain WireGuard is handshake-fingerprintable; national firewalls detect and cut it. Pair the same server with AmneziaWG or VLESS+Reality instead [4].
- You are the provider: legal exposure for what leaves your line, uptime responsibility, and nobody to email when it breaks at midnight.
When to choose which
Self-host if: one stable exit is enough, you want the cheapest honest privacy, you are comfortable with a shell, or you are pairing with obfuscation for travel. Buy a commercial service if you need many locations, streaming catalogs, or anonymity-by-crowd. Do both if you are serious: a personal server for daily use plus a vetted commercial account for the cases a fixed exit cannot cover.
Start with the decision guide to confirm your use case fits a fixed exit, then compare commercial providers on logging evidence for the days you need more than one hop.
Common pitfalls, named
The most common failure is not the setup - it is the mismatch between expectation and mechanism. Three show up constantly:
- Wrong vantage point expectations. People rent a server in Frankfurt expecting Swiss-style privacy law. The law that governs the hosting provider matters; a Hetzner instance answers to German process, which is fine for most purposes and irrelevant to the marketing stories people bring with them.
- No backups. A VPS is a rented machine. Take one export of your WireGuard configs per device, store them offline, and re-provisioning after a host hiccup takes twenty minutes instead of a weekend.
- Port exhaustion and NAT quirks. Some hosts share IPv4; make sure your instance has a dedicated IPv4 address or your "private" exit shares its reputation with strangers.
None of these are hard, but all of them surprise people who came from one-click commercial apps. The own-server guide you are reading exists because the hour of setup is the only real cost - everything after that is cheaper and more honest than a subscription whose renewal price is hidden until year two.
Router and multi-device reality
WireGuard runs natively on most modern routers (OpenWrt has a first-class package), which turns the single server into a whole-house tunnel: every device behind the router gets the same exit without installing anything. The trade-off is the same fixed exit for everything - including devices whose traffic you might want split. WireGuard's AllowedIPs per peer handles the split per device: one peer entry with 0.0.0.0/0 for full tunnel, a narrow one for split tunnel to specific networks.
For a household, the shape that works: one Algo box, a peer per person per device class, the router peer for the shared devices. Print the QR codes Algo generates. When a phone is replaced, import the QR once and move on.
The honest bottom line, restated
A self-hosted server is the closest thing the market has to a commodity: the software is free and world-class, the hardware is a commodity, and the only thing you actually pay for is a machine at an address. If your threat model is "hide my browsing from my ISP and my hotel network" - the most common real reason to buy a VPN - then a personal server covers it for less money than any subscription's renewal tier, with nobody in the middle to trust [2]. Start from the decision guide, and if your answer turns out to need many locations or catalogs, pick from commercial providers on evidence rather than on the size of the discount banner.
// FAQ
Is a self-hosted VPN more private than a paid one?
Against your VPN provider - yes, there is none. Against your destination sites - no, your single VPS IP identifies all your traffic. It removes one observer and concentrates another.
Can I stream Netflix with my own server?
Usually not. Streaming platforms block datacenter IPs aggressively. A residential-looking IP from a commercial VPN pool works better for catalogs.
What does it cost?
Hetzner and OVH small instances run EUR 4-6 per month including IPv4. The software is free. Time cost: an hour for the first setup, minutes for each new device.
What if I need obfuscation for a censored country?
Plain WireGuard is trivially detectable by national firewalls. Use Amnezia (AmneziaWG obfuscation) or VLESS+Reality on the same server - the base setup is identical.