"No-logs" is the most-abused phrase in the VPN industry — it appears on every homepage, including services later caught with terabytes of connection records. Here is what the term should mean, what it cannot mean, and how to evaluate the claim without taking anyone's word for it.
What a real no-logs policy covers
| Data | Logged by a real no-logs VPN? |
|---|---|
| Sites you visit / DNS queries | Never |
| Your source IP ↔ VPN IP mapping | Never |
| Connection timestamps per user | Never |
| Per-user bandwidth totals | Never |
| Account email + billing record | Yes — unavoidable for a paid service |
| Aggregate server load / health | Yes — needed to run the fleet |
The distinction that matters: operational aggregates (how loaded is the Warsaw node right now) versus per-user activity records (which account connected to it at 21:04 and what they resolved). The first is how you keep servers healthy; the second is surveillance material.
What "no-logs" cannot mean
Traffic physically flows through the provider's servers, so a VPN could always look — no-logs means nothing is written down. This is why the phrase is a policy-plus-architecture claim, not a magic property. It is also why jurisdiction and daemon-level configuration matter more than the homepage badge: retention is impossible to comply with retroactively if the records never existed.
On our own fleet the enforcement is at the daemon level: logging directives are disabled in the VPN daemons and proxy services themselves (the OpenVPN status/log files, WireGuard peer dumps, and proxy access logs are all off), so there is no per-user activity file to seize, leak, or "accidentally" retain. Full detail is in our privacy policy.
How to evaluate a no-logs claim in practice
- Read the privacy policy's data-collection section, not the marketing page. Watch for "we may retain connection metadata for service quality" — that is logging, worded politely.
- Look for the mechanism, not just the promise. Does the provider describe how logging is disabled (daemon config, RAM-only servers, diskless boots)? Specific mechanisms are falsifiable claims; vibes are not.
- Audits and court records help. Independent audits are meaningful evidence; even better are court cases in which a provider demonstrably had nothing to produce.
- Check what the apps themselves phone home. A no-logs VPN with invasive in-app analytics is contradicting itself.
- Payment options tell you something. Providers serious about privacy minimize what billing can reveal.
Why no-logs matters even if "you have nothing to hide"
Your ISP in most countries retains browsing metadata for months to years and may sell aggregated forms of it. On any shared Wi-Fi, the network operator sees every domain you touch. A VPN moves that visibility to a party whose entire business depends on not keeping it — but only if the "not keeping it" part is real. That is the entire product. Everything else — speed, locations, price — is secondary to whether the activity records exist at all.