VPN Logging Policies Explained: What “No Logs” Really Means

By  |  Updated: September 25, 2026  |  ~19 min read

A VPN logging policy tells you what the provider can know about your connection—and what it could later disclose, lose in a breach, or use for analytics. The phrase “no-log VPN” is not a regulated technical standard. One service may mean it keeps no browsing history; another may also avoid source IP addresses, timestamps, session duration, DNS requests, and per-user bandwidth. Both can advertise “no logs,” yet expose users to different correlation risks.

This guide separates VPN-tunnel activity from ordinary account and payment records, compares six providers using verifiable evidence, and explains why an audit is useful without treating it as a permanent guarantee.

Quick answer

Do no-log VPNs keep any data?

Usually, yes—but “no logs” should apply to identifiable VPN activity, not every record needed to run a subscription. A provider can still retain an email address, account status, payment reference, app version, support message, or aggregated server load. The crucial test is whether it stores the source IP, exact connection time, assigned VPN IP, DNS queries, destinations, or traffic content in a combination that links a customer to an online action.

The strongest choices minimize that linkability by design, document every exception, submit production infrastructure to recurring independent review, publish the report, and show how legal requests were handled.

4 layersTraffic, session metadata, operational telemetry, and account data need separate analysis.
6 providersCompared on policy detail, audits, report access, infrastructure, and app transparency.
5–6 reviewsConsecutive no-logs assurance cycles reported by Proton VPN and NordVPN by 2026.
0%Anonymity any VPN can guarantee: logins, cookies, malware, and payments still identify users.

VPN logging policies explained, including activity logs, connection metadata, and no-logs evidence

Table of Contents

Start with the data pathWhat Are VPN Logs?

When you connect, the encrypted tunnel hides destinations and traffic content from the local network and normally from your internet service provider. The VPN server then forwards requests to the internet. Depending on its design, the provider may be technically able to observe the IP address entering the tunnel, connection timing, DNS lookups, destinations, and traffic not independently protected by HTTPS.

A VPN log is a retained record created by the service or its supporting systems. Some values must exist briefly in memory so a live session works—an authentication service may need to know that an account reached its device limit. Ephemeral processing is not the same as writing a timestamped record to persistent storage, but the policy should explain the difference.

1. Your deviceKnows your account, apps, cookies, and requested services.
2. ISP / Wi-FiSees your source IP and connection to a VPN endpoint, plus timing and volume.
3. VPN providerRoutes the live session. Policy and architecture govern what persists.
4. DestinationSees the exit IP but can recognize logins, cookies, fingerprints, or submitted data.
A VPN shifts trust; it does not eliminate it. The U.S. Federal Trade Commission advises users to inspect permissions, terms, encryption, and third-party sharing instead of trusting a label. Its VPN app guidance also notes that a VPN does not make a user fully anonymous.

Four separate questionsThe Types of VPN Data—and Why the Distinction Matters

Policies become confusing when they call one category “usage data” and another “service data.” Ignore the label and inspect the fields. Risk depends on whether records can answer who connected, when, through which exit, and what they accessed.

1. Traffic or activity logs — highest risk

Destinations, URLs, DNS queries, content, browsing history, downloaded files, or app activity. A privacy-focused VPN should not retain these.

2. Connection metadata — correlation risk

Source IP, assigned VPN IP, precise timestamps, duration, server, and per-session bandwidth. Combinations can correlate an identity with an observed event.

3. Operational and diagnostic data

Aggregate server load, active-connection totals, app version, crash reports, failure reason, or coarse location. Risk depends on precision, retention, identifiers, and consent.

4. Account, payment, and support data

Email, subscription status, payment reference, tax country, and support correspondence can identify a customer without revealing tunnel activity.

Data fieldWhat it revealsPreferred treatmentQuestion to ask
Destinations / DNSSites and services contactedNever retainDoes “no activity logs” explicitly include DNS?
Source IPYour household or networkNever persist with a sessionIs it removed before analytics logs?
Precise time + exit IPCan correlate an observed actionAvoid persistent recordsAre times aggregated or deleted at disconnect?
Live device countWhether an account is in use nowMemory only where possibleDoes state disappear after disconnect?
Crash diagnosticsDevice/app detailsOpt-in, minimized, short retentionWhich analytics processor receives it?
Email / payment referenceCustomer identity and purchaseCollect only what billing requiresCan you use an alias or private payment?

Marketing versus architectureWhat Should a “No-Log VPN” Actually Mean?

A defensible promise means the provider does not retain enough VPN-session information to reconstruct browsing or connect a named customer to an action through an exit. It should rule out traffic content, DNS queries, source IP, assigned exit IP, precise timestamps, and destination history—not merely say “we do not monitor browsing.”

That does not mean the company knows nothing about a paying customer. Subscription services process credentials, payment records, fraud signals, and support tickets. A good policy separates these systems and states purposes and retention periods. “Anonymous analytics” also deserves scrutiny: removing a name is weak protection if a stable device identifier, exact timestamp, or IP remains.

Use a linkability test: can the provider connect (1) you or your source IP, (2) to a precise VPN session, (3) to an exit IP or destination? Breaking those links through minimization, aggregation, short-lived memory, and separated systems matters more than the slogan.

RAM-only servers help, but do not prove no logging

Diskless servers reduce artifacts on a seized or retired machine and make standardized redeployment easier. They do not stop records being streamed to remote logging, authentication, or analytics systems. Treat RAM-only infrastructure as one control, not a substitute for policy scope and configuration review.

Aggregated data can be compatible with no activity logs

A network can count total connections and monitor server-level bandwidth or CPU load without retaining browsing. “Server A carried 4 TB today” is capacity data; “account 123 used 4.2 GB through server A from 14:03 to 15:11” is user-level metadata.

Want the broader buying shortlist? Compare privacy evidence with speed, apps, support, and price in our best VPN providers guide.

Get Surfshark — Unlimited Devices →

Evidence snapshotNo-Logs Policies Compared Across Six VPN Providers

This compares published claims and external evidence, not overall product quality. “Latest relevant review” means a no-logs assurance engagement or infrastructure review that examined logging controls—not a generic app penetration test.

ProviderPublished VPN-session positionLatest relevant review*Report accessOther signals
Proton VPNNo traffic, DNS, destination, or user-identifiable session metadataSecuritum, 2026; fifth consecutive annual reviewFull reports publicOpen-source apps; transparency report; encrypted servers
NordVPNNo browsing activity, source IP, traffic, or connection logs under stated policyDeloitte, completed 2025; sixth assuranceAccount holdersRecurring assurance; RAM-based fleet
ExpressVPNNo activity or IP/timestamp/duration connection logs; limited daily statistics describedKPMG, report issued 2025 under ISAE 3000Public PDFTrustedServer RAM fleet; transparency reports
SurfsharkNo traffic, source/destination IPs, sites, DNS, files, or per-user transfer dataDeloitte, 2025 ISAE 3000 assurancePublic PDFRAM servers; aggregate live counts and OS metrics
Private Internet AccessNo browsing or connection activity retained under published policyDeloitte, third review completed 2025Full report publicOpen-source apps; RAM servers; court and transparency record
MullvadNo traffic, DNS, IP, timestamp, duration, or per-user bandwidth logsRadically Open Security infrastructure review, 2023Public reportsNo-email numbered accounts; open-source apps

*Audit scopes and assurance levels differ. Policies and infrastructure can change after an assessment.

Visible evidence signals (four-point factual checklist)

Segments: relevant logging review in 2025–2026; full report without paid access; documented RAM-only production fleet; open-source consumer apps. This is not a privacy score.

PIA4/4
Proton VPN3/4
ExpressVPN3/4
Surfshark3/4
NordVPN2/4
Mullvad2/4

A missing segment is not proof of logging. Encrypted disks can enforce no-logs, and open-source apps do not reveal server-side behavior.

All six make strong activity-logging claims, but evidence differs. Proton’s recurring public infrastructure reviews are easy to inspect. NordVPN reports a longer series, though its report is account-gated. ExpressVPN and Surfshark publish assurance reports and document RAM-based fleets. PIA combines recent recurring assurance, open-source apps, RAM infrastructure, transparency reports, and court tests. Mullvad minimizes account data aggressively, while its specifically relevant infrastructure/no-logging review is older than its newer app and security assessments.

Proof, not promisesHow to Verify a VPN’s No-Logs Claim

The strongest case is cumulative: specific policy language, privacy-preserving architecture, recurring third-party review, accessible findings, transparent ownership, and a real-world record that agrees with the promise.

1. PolicyExcluded and collected fields, purposes, retention, recipients.
2. DesignSeparated authentication, aggregate monitoring, hardened storage.
3. ReviewExperts inspect production configuration and operations.
4. RecordRepeat audits, request reports, and incident disclosure.

Read the audit scope before the conclusion

A mobile-app code audit does not verify server logging. Check the date, production systems sampled, protocols and specialty servers covered, exclusions, point-in-time versus period scope, auditor independence, assurance level, and remediation retest.

Prefer the complete report to a press release

The report shows the claim, responsible entity, criteria, scope, limitations, and auditor wording. “Nothing came to our attention” is limited-assurance language; “reasonable assurance” is stronger but still not a guarantee.

Use court records carefully

A case in which a provider could not produce logs is useful for that request and time. It does not prove every server, feature, subsidiary, or later configuration behaves identically. Transparency reports are strongest when they publish request categories, counts, periods, and outcomes.

The Center for Democracy & Technology’s Signals of Trustworthy VPNs asks providers to disclose ownership, business model, logging, retention, law-enforcement handling, and security practices—a useful baseline that exposes what a “zero logs” badge omits.

A five-minute policy auditHow to Read a VPN Privacy Policy

Identify the legal entity and effective date, then search for IP address, timestamp, DNS, destination, bandwidth, device, diagnostics, analytics, retention, delete, processor, law enforcement, and merger. Read account and website sections separately from the VPN-service section.

  1. Identify the operator and owner. Confirm the contracting entity, parent company, incorporation, and data sharing with sister services.
  2. List fields it does not collect. A precise list covering IPs, traffic, DNS, times, exit IP, and duration beats “we respect privacy.”
  3. List fields it does collect. Note telemetry, device data, coarse location, cookies, support, payments, fraud checks, and attribution.
  4. Map purpose, retention, and recipients. “Service improvement” is incomplete without a deletion period and processor list.
  5. Check deletion and exceptions. Look for legal holds, chargebacks, abuse controls, backups, dedicated IPs, and beta features.
  6. Compare words with evidence. Confirm auditors examined relevant server operations after the current architecture was deployed.

Green flags

  • Specific excluded fields
  • Explicit retention periods
  • Opt-in diagnostics
  • Named processors
  • Recurring infrastructure review
  • Public reports and clear ownership

Red flags

  • “No browsing logs” with no IP/time answer
  • “May collect” without limits
  • Undefined “anonymous” IDs
  • Broad sale or sharing rights
  • No deletion schedule
  • Audit badge without scope or date

Law meets system designJurisdiction, Intelligence Alliances, and Legal Requests

Home jurisdiction determines which authorities can compel a provider and what process applies. But “Five Eyes bad, offshore good” rankings miss the point: a country cannot obtain historical activity data that was never created, while a provider in a fashionable jurisdiction can still expose users by retaining it voluntarily.

Evaluate incorporation, physical operations, server locations, ownership, request history, and technical separation together. Local rules may cause a provider to remove physical servers, offer virtual locations, or withdraw rather than change network-wide logging.

Concrete example: India’s CERT-In directions require covered consumer VPN providers serving India to register specified customer information and maintain certain ICT logs. Its official FAQ distinguishes consumer VPNs from enterprise/corporate VPNs and says logs may be stored abroad if they can be produced to CERT-In. Concrete law is more useful than a generic alliance map.

A lawful request can require existing records. Depending on local law, prospective preservation or targeted monitoring may also be possible. Historical no-logs protection is not immunity from future compulsion. High-risk users should minimize account identity, compartmentalize, consider multi-hop or Tor where appropriate, and consult our VPN guide for journalists.

Be precise about protectionWhat a No-Logs Policy Does—and Does Not—Protect

ScenarioWhat no-logs helps withWhat remains exposed
Historical legal demandReduces stored session recordsAccount, payment, support, and web data may exist
Server seizureMinimization and RAM reduce artifactsLive memory, remote systems, keys, or poor configuration matter
Provider breachLess activity history to stealCredentials, email, billing, and support data
Website trackingHides residential IPLogins, cookies, fingerprints, submitted identity
Traffic correlationShared exits add ambiguityObservers watching both ends can compare timing and volume
Compromised deviceProtects network transportMalware, keylogging, and stolen sessions bypass it

No-log status says nothing by itself about leak protection or kill-switch behavior. Pair it with our guides to preventing DNS leaks and how VPN kill switches work.

Choose for your threat modelA Practical No-Logs VPN Checklist

CheckStrong answerWhy it matters
Activity fieldsNo traffic, destinations, URLs, or DNS logsPrevents browsing reconstruction
Connection fieldsNo persistent source IP, exit IP, exact time, or duration linkReduces correlation
DiagnosticsOptional, minimized, with processors and retention namedTelemetry is a common exception
Independent reviewRecent, recurring, production-relevant, detailedTests implementation
Report accessFull report public with scope and limitationsMakes evidence verifiable
InfrastructureReproducible deployment, limited admin, RAM or encrypted storageReduces accidental persistence
Account minimizationEmail optional or alias-friendly; private paymentsLimits subscription identity
TransparencyNamed owner, legal entity, request counts, incident reportsCreates accountability

Balanced mainstream pick: Surfshark’s 2025 Deloitte report examined its no-logs implementation, while RAM-only servers and unlimited simultaneous devices make it practical for households. Re-check the live policy for your platform and region.

Check Surfshark’s Current Offer →

Common questionsVPN Logging Policy FAQ

Can a VPN claim “no logs” and still collect data?

Yes. The phrase may apply only to browsing. Account data, payments, aggregate metrics, app versions, crash reports, or connection summaries may still be processed. Ask whether retained fields link a person or source IP to a session, exit, or destination.

What is the difference between activity and connection logs?

Activity logs describe what passed through the VPN: destinations, DNS, URLs, or content. Connection logs describe the tunnel: source IP, time, duration, server, assigned address, or bandwidth. Connection metadata can still enable correlation.

Are “zero logs” and “no logs” different?

Not reliably. Both are marketing phrases, not standardized certifications. Read exclusions, collected fields, retention, and audit scope rather than assuming “zero” is stricter.

Does RAM-only infrastructure guarantee no logging?

No. It clears local state on reboot but does not stop remote logging. It helps when paired with disabled activity logs, controlled deployment, restricted administration, and review.

Can a no-log VPN identify me from payment?

The provider or processor may know you purchased a subscription. That differs from knowing what you did through it. For more separation, use an alias-friendly signup and a clearly separated billing/authentication design.

Are free VPNs always unsafe or heavily logged?

No. Some subscriber-funded services offer constrained free tiers under the same policy. Risk rises when ownership and revenue are unclear, permissions are unrelated, advertising SDKs are embedded, or data sharing is broad. See Are free VPNs safe?

Is an audited VPN automatically safe?

No. An audit supports a claim only within its scope and window. It may exclude apps, authentication, new features, rented servers, or later changes. Prefer recurring reviews, full reports, and remediation evidence.

Which jurisdiction is best?

No country wins universally. Examine concrete obligations, process, ownership, server law, and request history. Data minimization usually matters more than an “offshore” label.

Can a VPN be forced to start logging one person?

Possibly, depending on law and architecture. A historical no-logs policy limits past records; it does not guarantee immunity from prospective targeted measures. High-risk users should not rely on one consumer VPN as their only anonymity layer.

Bottom Line: Choose the Evidence, Not the Badge

A trustworthy policy names the activity and connection fields never retained, then lists account data, telemetry, processors, purposes, and deletion periods. Strong providers reinforce the text with privacy-preserving architecture, recurring production-relevant audits, complete reports, transparent ownership, and request outcomes.

For ordinary privacy, prioritize no traffic or DNS logs, no persistent IP-and-time linkage, and a recent review. For higher risk, add account minimization, public reports, open-source apps, compartmentalized identity, and a threat model that does not assume VPN equals anonymity.

Disclosure: This article contains affiliate links. Purchases may earn us a commission at no extra cost to you. Affiliate relationships do not change the evidence checklist. Policies and controls can change; verify current legal documents. This is general information, not legal advice.

Sources & comparison methodology

We reviewed provider policies, the latest relevant assurance or infrastructure reports located for this update, transparency materials, and official guidance. We excluded unsupported market-wide percentages and did not turn jurisdiction into an invented score. The visual checklist counts disclosed evidence; it is not a quality ranking.

  • ExpressVPN: privacy policy updated January 2026; KPMG ISAE 3000 reasonable-assurance report issued May 2025 on controls as of February 28, 2025; H1 2026 transparency report.
  • NordVPN: sixth no-logs assurance by Deloitte Lithuania under ISAE 3000, completed at the end of 2025 and announced February 2026; full report through a Nord Account.
  • Surfshark: Deloitte ISAE 3000 report on implementation as of June 10, 2025, including disabled service/container logging, RAM servers, aggregate counts, and OS health metrics.
  • Proton VPN: privacy policy modified July 2025; 2026 Securitum report and prior annual reports. The 2026 review found no examined records linking users to browsing, DNS, destinations, content, or identifiable connection metadata.
  • Private Internet Access: third Deloitte review completed in 2025 and announced February 2026; 2022/2024 history; open-source apps, RAM servers, court tests, and quarterly reports.
  • Mullvad: policy updated June 2026; 2023 Radically Open Security infrastructure audit. Newer app/security assessments were not mislabeled as fresh no-logs audits.
  • External context: FTC VPN guidance; CDT Signals of Trustworthy VPNs; Indian CERT-In section 70B directions and May 2022 FAQ.

Cut-off: September 21, 2026. “Public report” means accessible without payment or customer login. “Open-source apps” means consumer VPN clients, not only a protocol. “RAM-only fleet” requires documentation about production servers, not one test machine.

Share this:

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *