VPN Logging Policies Explained: What “No Logs” Really Means
A VPN logging policy tells you what the provider can know about your connection—and what it could later disclose, lose in a breach, or use for analytics. The phrase “no-log VPN” is not a regulated technical standard. One service may mean it keeps no browsing history; another may also avoid source IP addresses, timestamps, session duration, DNS requests, and per-user bandwidth. Both can advertise “no logs,” yet expose users to different correlation risks.
This guide separates VPN-tunnel activity from ordinary account and payment records, compares six providers using verifiable evidence, and explains why an audit is useful without treating it as a permanent guarantee.
Do no-log VPNs keep any data?
Usually, yes—but “no logs” should apply to identifiable VPN activity, not every record needed to run a subscription. A provider can still retain an email address, account status, payment reference, app version, support message, or aggregated server load. The crucial test is whether it stores the source IP, exact connection time, assigned VPN IP, DNS queries, destinations, or traffic content in a combination that links a customer to an online action.
The strongest choices minimize that linkability by design, document every exception, submit production infrastructure to recurring independent review, publish the report, and show how legal requests were handled.

Table of Contents
Start with the data pathWhat Are VPN Logs?
When you connect, the encrypted tunnel hides destinations and traffic content from the local network and normally from your internet service provider. The VPN server then forwards requests to the internet. Depending on its design, the provider may be technically able to observe the IP address entering the tunnel, connection timing, DNS lookups, destinations, and traffic not independently protected by HTTPS.
A VPN log is a retained record created by the service or its supporting systems. Some values must exist briefly in memory so a live session works—an authentication service may need to know that an account reached its device limit. Ephemeral processing is not the same as writing a timestamped record to persistent storage, but the policy should explain the difference.
Four separate questionsThe Types of VPN Data—and Why the Distinction Matters
Policies become confusing when they call one category “usage data” and another “service data.” Ignore the label and inspect the fields. Risk depends on whether records can answer who connected, when, through which exit, and what they accessed.
1. Traffic or activity logs — highest risk
Destinations, URLs, DNS queries, content, browsing history, downloaded files, or app activity. A privacy-focused VPN should not retain these.
2. Connection metadata — correlation risk
Source IP, assigned VPN IP, precise timestamps, duration, server, and per-session bandwidth. Combinations can correlate an identity with an observed event.
3. Operational and diagnostic data
Aggregate server load, active-connection totals, app version, crash reports, failure reason, or coarse location. Risk depends on precision, retention, identifiers, and consent.
4. Account, payment, and support data
Email, subscription status, payment reference, tax country, and support correspondence can identify a customer without revealing tunnel activity.
| Data field | What it reveals | Preferred treatment | Question to ask |
|---|---|---|---|
| Destinations / DNS | Sites and services contacted | Never retain | Does “no activity logs” explicitly include DNS? |
| Source IP | Your household or network | Never persist with a session | Is it removed before analytics logs? |
| Precise time + exit IP | Can correlate an observed action | Avoid persistent records | Are times aggregated or deleted at disconnect? |
| Live device count | Whether an account is in use now | Memory only where possible | Does state disappear after disconnect? |
| Crash diagnostics | Device/app details | Opt-in, minimized, short retention | Which analytics processor receives it? |
| Email / payment reference | Customer identity and purchase | Collect only what billing requires | Can you use an alias or private payment? |
Marketing versus architectureWhat Should a “No-Log VPN” Actually Mean?
A defensible promise means the provider does not retain enough VPN-session information to reconstruct browsing or connect a named customer to an action through an exit. It should rule out traffic content, DNS queries, source IP, assigned exit IP, precise timestamps, and destination history—not merely say “we do not monitor browsing.”
That does not mean the company knows nothing about a paying customer. Subscription services process credentials, payment records, fraud signals, and support tickets. A good policy separates these systems and states purposes and retention periods. “Anonymous analytics” also deserves scrutiny: removing a name is weak protection if a stable device identifier, exact timestamp, or IP remains.
RAM-only servers help, but do not prove no logging
Diskless servers reduce artifacts on a seized or retired machine and make standardized redeployment easier. They do not stop records being streamed to remote logging, authentication, or analytics systems. Treat RAM-only infrastructure as one control, not a substitute for policy scope and configuration review.
Aggregated data can be compatible with no activity logs
A network can count total connections and monitor server-level bandwidth or CPU load without retaining browsing. “Server A carried 4 TB today” is capacity data; “account 123 used 4.2 GB through server A from 14:03 to 15:11” is user-level metadata.
Want the broader buying shortlist? Compare privacy evidence with speed, apps, support, and price in our best VPN providers guide.
Get Surfshark — Unlimited Devices →Evidence snapshotNo-Logs Policies Compared Across Six VPN Providers
This compares published claims and external evidence, not overall product quality. “Latest relevant review” means a no-logs assurance engagement or infrastructure review that examined logging controls—not a generic app penetration test.
| Provider | Published VPN-session position | Latest relevant review* | Report access | Other signals |
|---|---|---|---|---|
| Proton VPN | No traffic, DNS, destination, or user-identifiable session metadata | Securitum, 2026; fifth consecutive annual review | Full reports public | Open-source apps; transparency report; encrypted servers |
| NordVPN | No browsing activity, source IP, traffic, or connection logs under stated policy | Deloitte, completed 2025; sixth assurance | Account holders | Recurring assurance; RAM-based fleet |
| ExpressVPN | No activity or IP/timestamp/duration connection logs; limited daily statistics described | KPMG, report issued 2025 under ISAE 3000 | Public PDF | TrustedServer RAM fleet; transparency reports |
| Surfshark | No traffic, source/destination IPs, sites, DNS, files, or per-user transfer data | Deloitte, 2025 ISAE 3000 assurance | Public PDF | RAM servers; aggregate live counts and OS metrics |
| Private Internet Access | No browsing or connection activity retained under published policy | Deloitte, third review completed 2025 | Full report public | Open-source apps; RAM servers; court and transparency record |
| Mullvad | No traffic, DNS, IP, timestamp, duration, or per-user bandwidth logs | Radically Open Security infrastructure review, 2023 | Public reports | No-email numbered accounts; open-source apps |
*Audit scopes and assurance levels differ. Policies and infrastructure can change after an assessment.
Visible evidence signals (four-point factual checklist)
Segments: relevant logging review in 2025–2026; full report without paid access; documented RAM-only production fleet; open-source consumer apps. This is not a privacy score.
A missing segment is not proof of logging. Encrypted disks can enforce no-logs, and open-source apps do not reveal server-side behavior.
All six make strong activity-logging claims, but evidence differs. Proton’s recurring public infrastructure reviews are easy to inspect. NordVPN reports a longer series, though its report is account-gated. ExpressVPN and Surfshark publish assurance reports and document RAM-based fleets. PIA combines recent recurring assurance, open-source apps, RAM infrastructure, transparency reports, and court tests. Mullvad minimizes account data aggressively, while its specifically relevant infrastructure/no-logging review is older than its newer app and security assessments.
Proof, not promisesHow to Verify a VPN’s No-Logs Claim
The strongest case is cumulative: specific policy language, privacy-preserving architecture, recurring third-party review, accessible findings, transparent ownership, and a real-world record that agrees with the promise.
Read the audit scope before the conclusion
A mobile-app code audit does not verify server logging. Check the date, production systems sampled, protocols and specialty servers covered, exclusions, point-in-time versus period scope, auditor independence, assurance level, and remediation retest.
Prefer the complete report to a press release
The report shows the claim, responsible entity, criteria, scope, limitations, and auditor wording. “Nothing came to our attention” is limited-assurance language; “reasonable assurance” is stronger but still not a guarantee.
Use court records carefully
A case in which a provider could not produce logs is useful for that request and time. It does not prove every server, feature, subsidiary, or later configuration behaves identically. Transparency reports are strongest when they publish request categories, counts, periods, and outcomes.
A five-minute policy auditHow to Read a VPN Privacy Policy
Identify the legal entity and effective date, then search for IP address, timestamp, DNS, destination, bandwidth, device, diagnostics, analytics, retention, delete, processor, law enforcement, and merger. Read account and website sections separately from the VPN-service section.
- Identify the operator and owner. Confirm the contracting entity, parent company, incorporation, and data sharing with sister services.
- List fields it does not collect. A precise list covering IPs, traffic, DNS, times, exit IP, and duration beats “we respect privacy.”
- List fields it does collect. Note telemetry, device data, coarse location, cookies, support, payments, fraud checks, and attribution.
- Map purpose, retention, and recipients. “Service improvement” is incomplete without a deletion period and processor list.
- Check deletion and exceptions. Look for legal holds, chargebacks, abuse controls, backups, dedicated IPs, and beta features.
- Compare words with evidence. Confirm auditors examined relevant server operations after the current architecture was deployed.
Green flags
- Specific excluded fields
- Explicit retention periods
- Opt-in diagnostics
- Named processors
- Recurring infrastructure review
- Public reports and clear ownership
Red flags
- “No browsing logs” with no IP/time answer
- “May collect” without limits
- Undefined “anonymous” IDs
- Broad sale or sharing rights
- No deletion schedule
- Audit badge without scope or date
Law meets system designJurisdiction, Intelligence Alliances, and Legal Requests
Home jurisdiction determines which authorities can compel a provider and what process applies. But “Five Eyes bad, offshore good” rankings miss the point: a country cannot obtain historical activity data that was never created, while a provider in a fashionable jurisdiction can still expose users by retaining it voluntarily.
Evaluate incorporation, physical operations, server locations, ownership, request history, and technical separation together. Local rules may cause a provider to remove physical servers, offer virtual locations, or withdraw rather than change network-wide logging.
A lawful request can require existing records. Depending on local law, prospective preservation or targeted monitoring may also be possible. Historical no-logs protection is not immunity from future compulsion. High-risk users should minimize account identity, compartmentalize, consider multi-hop or Tor where appropriate, and consult our VPN guide for journalists.
Be precise about protectionWhat a No-Logs Policy Does—and Does Not—Protect
| Scenario | What no-logs helps with | What remains exposed |
|---|---|---|
| Historical legal demand | Reduces stored session records | Account, payment, support, and web data may exist |
| Server seizure | Minimization and RAM reduce artifacts | Live memory, remote systems, keys, or poor configuration matter |
| Provider breach | Less activity history to steal | Credentials, email, billing, and support data |
| Website tracking | Hides residential IP | Logins, cookies, fingerprints, submitted identity |
| Traffic correlation | Shared exits add ambiguity | Observers watching both ends can compare timing and volume |
| Compromised device | Protects network transport | Malware, keylogging, and stolen sessions bypass it |
No-log status says nothing by itself about leak protection or kill-switch behavior. Pair it with our guides to preventing DNS leaks and how VPN kill switches work.
Choose for your threat modelA Practical No-Logs VPN Checklist
| Check | Strong answer | Why it matters |
|---|---|---|
| Activity fields | No traffic, destinations, URLs, or DNS logs | Prevents browsing reconstruction |
| Connection fields | No persistent source IP, exit IP, exact time, or duration link | Reduces correlation |
| Diagnostics | Optional, minimized, with processors and retention named | Telemetry is a common exception |
| Independent review | Recent, recurring, production-relevant, detailed | Tests implementation |
| Report access | Full report public with scope and limitations | Makes evidence verifiable |
| Infrastructure | Reproducible deployment, limited admin, RAM or encrypted storage | Reduces accidental persistence |
| Account minimization | Email optional or alias-friendly; private payments | Limits subscription identity |
| Transparency | Named owner, legal entity, request counts, incident reports | Creates accountability |
Balanced mainstream pick: Surfshark’s 2025 Deloitte report examined its no-logs implementation, while RAM-only servers and unlimited simultaneous devices make it practical for households. Re-check the live policy for your platform and region.
Check Surfshark’s Current Offer →Common questionsVPN Logging Policy FAQ
Can a VPN claim “no logs” and still collect data?
Yes. The phrase may apply only to browsing. Account data, payments, aggregate metrics, app versions, crash reports, or connection summaries may still be processed. Ask whether retained fields link a person or source IP to a session, exit, or destination.
What is the difference between activity and connection logs?
Activity logs describe what passed through the VPN: destinations, DNS, URLs, or content. Connection logs describe the tunnel: source IP, time, duration, server, assigned address, or bandwidth. Connection metadata can still enable correlation.
Are “zero logs” and “no logs” different?
Not reliably. Both are marketing phrases, not standardized certifications. Read exclusions, collected fields, retention, and audit scope rather than assuming “zero” is stricter.
Does RAM-only infrastructure guarantee no logging?
No. It clears local state on reboot but does not stop remote logging. It helps when paired with disabled activity logs, controlled deployment, restricted administration, and review.
Can a no-log VPN identify me from payment?
The provider or processor may know you purchased a subscription. That differs from knowing what you did through it. For more separation, use an alias-friendly signup and a clearly separated billing/authentication design.
Are free VPNs always unsafe or heavily logged?
No. Some subscriber-funded services offer constrained free tiers under the same policy. Risk rises when ownership and revenue are unclear, permissions are unrelated, advertising SDKs are embedded, or data sharing is broad. See Are free VPNs safe?
Is an audited VPN automatically safe?
No. An audit supports a claim only within its scope and window. It may exclude apps, authentication, new features, rented servers, or later changes. Prefer recurring reviews, full reports, and remediation evidence.
Which jurisdiction is best?
No country wins universally. Examine concrete obligations, process, ownership, server law, and request history. Data minimization usually matters more than an “offshore” label.
Can a VPN be forced to start logging one person?
Possibly, depending on law and architecture. A historical no-logs policy limits past records; it does not guarantee immunity from prospective targeted measures. High-risk users should not rely on one consumer VPN as their only anonymity layer.
Bottom Line: Choose the Evidence, Not the Badge
A trustworthy policy names the activity and connection fields never retained, then lists account data, telemetry, processors, purposes, and deletion periods. Strong providers reinforce the text with privacy-preserving architecture, recurring production-relevant audits, complete reports, transparent ownership, and request outcomes.
For ordinary privacy, prioritize no traffic or DNS logs, no persistent IP-and-time linkage, and a recent review. For higher risk, add account minimization, public reports, open-source apps, compartmentalized identity, and a threat model that does not assume VPN equals anonymity.
Disclosure: This article contains affiliate links. Purchases may earn us a commission at no extra cost to you. Affiliate relationships do not change the evidence checklist. Policies and controls can change; verify current legal documents. This is general information, not legal advice.
Sources & comparison methodology
We reviewed provider policies, the latest relevant assurance or infrastructure reports located for this update, transparency materials, and official guidance. We excluded unsupported market-wide percentages and did not turn jurisdiction into an invented score. The visual checklist counts disclosed evidence; it is not a quality ranking.
- ExpressVPN: privacy policy updated January 2026; KPMG ISAE 3000 reasonable-assurance report issued May 2025 on controls as of February 28, 2025; H1 2026 transparency report.
- NordVPN: sixth no-logs assurance by Deloitte Lithuania under ISAE 3000, completed at the end of 2025 and announced February 2026; full report through a Nord Account.
- Surfshark: Deloitte ISAE 3000 report on implementation as of June 10, 2025, including disabled service/container logging, RAM servers, aggregate counts, and OS health metrics.
- Proton VPN: privacy policy modified July 2025; 2026 Securitum report and prior annual reports. The 2026 review found no examined records linking users to browsing, DNS, destinations, content, or identifiable connection metadata.
- Private Internet Access: third Deloitte review completed in 2025 and announced February 2026; 2022/2024 history; open-source apps, RAM servers, court tests, and quarterly reports.
- Mullvad: policy updated June 2026; 2023 Radically Open Security infrastructure audit. Newer app/security assessments were not mislabeled as fresh no-logs audits.
- External context: FTC VPN guidance; CDT Signals of Trustworthy VPNs; Indian CERT-In section 70B directions and May 2022 FAQ.
Cut-off: September 21, 2026. “Public report” means accessible without payment or customer login. “Open-source apps” means consumer VPN clients, not only a protocol. “RAM-only fleet” requires documentation about production servers, not one test machine.






