What “no logs” actually means
"No logs" is the most repeated phrase in VPN marketing and among the least informative, because it is almost never accompanied by the list of things it refers to. Here is how to read it.
The categories that get confused
Arguments about logging usually come from two people meaning different things by the word. There are at least four distinct categories, and a policy that does not separate them is not saying much.
- Activity records
- Which sites, addresses or names an account reached, and when. This is the category people mean when they ask about logging, and the one whose absence is genuinely meaningful.
- Connection records
- That an account connected, from which address, at what time, for how long, and how much data it moved. Absent activity records, these still allow correlation over time, and they are often retained for capacity planning or abuse handling.
- Account records
- Whatever was needed to create and bill the account: an email address, a payment reference, a purchase history. A service that sells subscriptions necessarily holds some of this, and no policy can truthfully claim otherwise.
- Aggregate and operational data
- Totals, counters and error rates that are not attributable to an individual. Traffic totals per account fall in an awkward middle: they are required for any quota system, and they say something about usage without saying what it was.
How to read a policy
Read the privacy policy rather than the landing page. The landing page carries the slogan; the policy carries the commitments, and the gap between them is informative in itself.
Look for an explicit list, not an adjective
A policy worth trusting names the categories it does not retain — browsing activity, DNS queries, destination addresses, traffic contents. "We respect your privacy" commits to nothing.
Check what it admits to keeping
A policy that lists what it does hold — account email, payment reference, traffic totals — is being more useful than one that implies it holds nothing at all.
Find the retention periods
"Deleted when no longer necessary" is not a period. A specific number of days is a commitment that can be checked.
Note the jurisdiction
Where the company is established determines which authorities can compel disclosure and under what process. This is a legal constraint, and no technical claim overrides it.
Look for independent verification
An audit by a named firm, with a scope statement and a date, is meaningfully better than an unverified assertion. It confirms what was true on the days the auditors looked, which is a real but limited guarantee.
Wording worth noticing
- "We do not log your activity" followed by an exception for "service improvement" or "security purposes" broad enough to cover anything.
- "Military-grade encryption" as a substitute for a retention statement. It describes a cipher everyone uses and says nothing about what is kept.
- A no-logs claim on the landing page with no corresponding commitment anywhere in the privacy policy.
- An audit referenced without the firm's name, the scope, or the date.
- A free service with no stated business model. Operating capacity costs money, and if the subscription is not paying for it, something else is.
None of these prove bad faith on its own. Together they are a reasonable basis for scepticism, and they are all things you can check in a few minutes.
What actually constrains a provider
A promise is only as good as what makes it hard to break. Some structural properties do more work than any assurance.
- Data that is never collected cannot be disclosed, lost in a breach, or compelled. Minimisation is the only guarantee that does not depend on the operator's continued good behaviour.
- Short retention windows limit how far back any compelled disclosure can reach.
- Separating account identity from traffic handling means that neither system on its own answers the question of who did what.
- Published, dated policy changes let you see what was promised at a particular time rather than only what is promised now.
The realistic position is that using any provider means extending some trust to it, because it necessarily sits where it can observe your destinations. The reasonable goal is to choose one that has arranged things so that trusting it requires as little as possible — and to know what you are trusting it with.
Common questions
Can a VPN really keep no logs at all?
Not literally. Any service that bills, enforces a quota or handles abuse necessarily holds some records. The meaningful version of the claim is the absence of activity records — which sites you reached and when — and that is what a policy should state explicitly.
What is the difference between activity logs and connection logs?
Activity records say where you went. Connection records say that you connected, from which address, when, and how much data moved. A provider can truthfully say it keeps no activity records while still holding connection records, which is why the distinction is worth insisting on.
Does a no-logs audit prove anything?
It confirms that the auditors found what the policy describes, on the days they looked, within the scope they were given. That is meaningfully better than an unverified claim and considerably weaker than a permanent guarantee. The scope and date are the parts to read.
Does jurisdiction matter for a no-logs VPN?
Yes. Where a company is established determines who can compel it to disclose what it holds. It cannot be compelled to produce records it never created, which is why data minimisation matters more than the jurisdiction on its own.