If you have two computers behind NAT, the ZeroTier will help you punch through your NAT and let the computers talk to each other directly. It does it extremely well, and I haven't seen anything like it.
Cool thing is, it can do everything that a normal VPN can. When the other commenters talk about them hosting the 'server'. They're talking about configs, etc. Traffic doesn't usually go through their servers. Just in rare cases where your ISP is really hell bent of preventing you from UDP hole punching.
I personally use it as a replacement for AWS VPN Gateway using a ZT managed route and a couple of VPC route table entries. I detail that setup in my ZeroTier Terraform plugin: https://github.com/cormacrelf/terraform-provider-zerotier
EDIT: Just did. This[1] is amazing.
Highly underrated and too much under the radar afaik
You can run your own controller fir free, and it's also open source iirc, but it's not as nice (no web ui) and you're fully on your own.
If you're behind a restrictive firewall ZeroTier won't be able to punch through it, and will fall back to forwarding packets (encrypted) through ZeroTier servers, Even if a connection could've been made over TCP to the other client (because his firewall supports UPnP or is port forwarded) which creates a tunnel directly between them.
Note that UDP connections are always better for encapsulating TCP, but P2P TCP is better then TCP through an external server with limited bandwidth.
I'm a ZeroTier user though, and i've only encountered this to be a problem once. It's nice to know it'll always work well though.
Configuration & ease of use: ZT > Tinc Connectivity: Tinc > ZT
I know ZeroTier people are looking into solving this, so this might soon be obsolete information :)
Also tinfoilhats might prefer Tinc considering there's no central service anywhere.