You mean on a VPS that you also rented from someone else, therefore essentially moving your traffic from your ISP to...?
You also don't get the benefit of your traffic getting mixed together under the same address, since VPS providers will assign you an individual address.
I would never do anything illegal via that VPN though, since it would be trivial to trace it back to me. I'm sure OVH wouldn't hesitate to hand over my details if the authorities requested them. But as a privacy protection on public wifi, it works well.
When choosing a VPN, you should think about what you're trying to achieve and what you're trying to protect yourself from. Most non-tech people I know that use VPNs, use them to bypass geo-restrictions. For that purpose, these giant commercial ones are probably fine.
A VPN provider that easily bows to authorities is a VPN provider that will lose a massive portion of their user base. Some server farm probably profits very little from VPN servers, so if some government (or even some IP lawyer) knocks on their door, then they won't take the risk.
Because you need to give your name and credit card data to get a VPS, and in the end you're still sending encrypted data through someone's network.
VPN vendors are extracting value out of your monthly subscription like anybody else. Though the shadier ones might _also_ sell any metadata (to whom?), but we're not talking about these, and selling data is not a necessary precondition to being a VPN vendor.
In reality, the only people that are really interested in knowing in aggregate and in specific where people connect to when trying to hide are governments. And they don't pay, but just put a tap somewhere and if an alarm is triggered, send a court order to get logs and data upstream. That applies for both VPN and VPS vendors. So the goal is finding someone that has as minimal logs and invoicing data as legally possible.
Pick a cheap, untrusted VPS provider and you're getting just as exploited as if you were using a cheap, untrusted VPN provider.
It's also trivial to map the traffic of your VPS to you, since there's a 1:1 relationship between the IP your VPS uses and your actual IP.
Additionally IP lawyers may have much more success in threatening litigation to get your provider to rat you out. The provider would get little reward from not doing that, since harboring torrenters is probably not their main business.
The presumption is that the business of VPN providers is fully based on providing privacy, giving them a strong perverse incentive to abuse their access to this information and for whichever purposes. Plus, their whole infrastructure is orientated towards providing VPN services, with their own software, making the effort involved in collecting their customers' data and behaviour much smaller and more scalable.
VPS providers, on the other hand are in the business of offering hosting. What software their customer chooses to use on their VPS, and for what purpose, is anyone's guess. While the VPS provider could technically log and exploit the incoming and outgoing traffic from customers who happen to be running VPN software on their VPS, the effort involved in handling the myriad of bespoke VPN setups used by such a small proportion of their customers would be utterly pointless.
If you're implying that they'd do something illegal like blackmail, then I don't think that would be a wise course of action for a company to take. VPN companies are, in the worst case, still limited by TLS. So the amount of blackmail material is pretty small,meaning they would be taking a massive risk for very little reward.
A VPS server can easily log your connections. All they'd need to log are incoming packets to your VPS, and the destination address of outgoing packets from your VPS. No need to concern themselves with what software you are using under the hood.
For an analogy, if your motivation for using physical storage space was to hide your stuff from prying eyes, but were legitimately concerned that a business may have an economic or political incentive to take a peek, what would be a safer bet? Would it be to use a business specialising in storage, that uses standard storage modules all in the same location, and who knows most of its customers are interested in hiding their objects? Or would it be to rent an apartment from an estate agent that rents out all sorts of property for any number of purposes?
It’s trivial to pinpoint my location just based on IP. Setup a cloudflare worker and dump the request object, it gets very close, down to giving you the rough zip code area. Using something like NordVPN (even with a server in the same country I’m in) changes my IP proximity to something much more broad.
Then in cafes and public networks where I absolutely don’t trust the network
If you are paying with say your credit card, I guess the only benefit is that the vpn may have a better privacy policy and/or jurisdiction than your isp.