What Does a “No-Logs” VPN Actually Mean?
A “no-logs” VPN is one that keeps no record of what you do while connected — no list of the sites you visit, no DNS lookups, and as little connection metadata as the service can run on. That is the promise. The catch is that “no-logs” is a marketing phrase, not a regulated term, so two providers can both claim it while keeping very different amounts of data. Understanding what the words should mean is the only way to tell an honest claim from a hollow one.
The two kinds of logs
There are two categories, and a real no-logs service treats them very differently. Activity logs are the sensitive ones: the websites and services you connect to, your DNS queries, and the content of your traffic. Connection logs — also called metadata — are timestamps, how long a session lasted, how much bandwidth you used, which server you chose, and the real IP address you connected from. A trustworthy no-logs provider keeps no activity logs at all, and keeps connection metadata to nothing that could identify a session after it closes.
The distinction matters because metadata alone can deanonymise you. If a provider records the time you connected and the IP you came from, and a website records the time a specific action happened, those two timestamps can be matched. That is why the strongest providers are so careful to keep no timestamped, per-user connection record — not merely no “browsing history”.
What “no-logs” usually leaves out
In practice, “no-logs” in an advertisement often means “no activity logs” while some connection metadata is still kept. Providers may argue, reasonably, that they need aggregate numbers — total active sessions on a server, total bandwidth — to keep the network running. That is legitimate as long as those figures are aggregate and cannot be tied to an individual. The problem is the providers that blur this line, keeping per-user connection records while still advertising “no-logs”. The word you are looking for in a policy is not “no-logs” but a plain description of exactly what is retained, and for how long.
Why the audit, not the policy, is the proof
A privacy policy is a promise a company writes about itself, so it proves nothing on its own. What turns a no-logs claim into evidence is an independent audit: an outside firm inspecting the systems and publishing a report with its name on it. The firms that do this are well known — Deloitte and KPMG on the accountancy side, and specialist labs like Cure53 and Securitum — and when one signs a report it stakes its own reputation on the finding. Our guide to which no-logs VPN claims are actually audited names the auditor and date for every major provider, because those two facts are the whole story.
How to read a no-logs audit
Read three things in any audit before you trust it. First, the date — most are “reasonable assurance” engagements that describe a single moment in time, so a report from three years ago says little about the servers running today. Second, the scope — did the auditor inspect the live servers and configuration, or only read the written policy? A server inspection is worth far more. Third, who commissioned it and what they were allowed to see; a provider that lets auditors roam is more convincing than one that hands them a narrow checklist.
A single audit is a photograph, not a guarantee. The best providers publish a fresh one every year, precisely because infrastructure changes and a one-off report ages badly. If the most recent audit you can find is old, treat the claim as stale rather than proven.
Words that should make you suspicious
Some phrases are red flags. “Independently audited” with no firm or date named is close to meaningless — ask which firm, and when. “We do not log any personally identifiable information” is a narrower promise than “no activity logs”, and the gap is where metadata hides. “Military-grade encryption” describes standard encryption everyone uses and tells you nothing about logging. And any claim of “total anonymity” is simply false: a VPN cannot make you anonymous, so a provider that says it can is either careless or dishonest.
Open-source apps: another verification signal
An audit checks the servers; open-source apps let anyone check the software on your device. When a provider publishes its client code — as Proton VPN, Private Internet Access, Mullvad and IVPN do — independent researchers can confirm that the app connects where it says, uses the encryption it claims, and does not quietly phone home with data the policy denies collecting. It is not a substitute for a server-side no-logs audit, because the app cannot see what the provider stores, but it closes a gap that a closed-source app leaves open. Reproducible builds go one step further, letting you confirm that the app you downloaded was built from exactly that published code. Where you can get both an infrastructure audit and open-source apps, you have two independent checks instead of one, and that is meaningfully stronger than either alone.
The honest bottom line
“No-logs” is worth wanting, but only when it is backed by a named, recent audit — and it is strongest of all when the claim has survived a real legal demand. A handful of providers have had servers seized or been subpoenaed and produced nothing, which is the closest thing to proof the industry offers. We cover those moments in the no-logs court cases, in detail. Until a claim is audited and, ideally, tested, treat it as a promise — not a fact.
No-logs, in plain terms
Is “no-logs” a legally defined term?
Do no-logs VPNs keep any data at all?
Can I verify a no-logs claim myself?
Does no-logs mean the VPN can't see my traffic?
What is the difference between a no-logs policy and a privacy policy?
The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.