Skip to content
Clearward

What Does a “No-Logs” VPN Actually Mean?

Published Jul 5, 2026✓ Fact-checked Aug 20, 2026

A “no-logs” VPN is one that keeps no record of what you do while connected — no list of the sites you visit, no DNS lookups, and as little connection metadata as the service can run on. That is the promise. The catch is that “no-logs” is a marketing phrase, not a regulated term, so two providers can both claim it while keeping very different amounts of data. Understanding what the words should mean is the only way to tell an honest claim from a hollow one.

The two kinds of logs

There are two categories, and a real no-logs service treats them very differently. Activity logs are the sensitive ones: the websites and services you connect to, your DNS queries, and the content of your traffic. Connection logs — also called metadata — are timestamps, how long a session lasted, how much bandwidth you used, which server you chose, and the real IP address you connected from. A trustworthy no-logs provider keeps no activity logs at all, and keeps connection metadata to nothing that could identify a session after it closes.

The distinction matters because metadata alone can deanonymise you. If a provider records the time you connected and the IP you came from, and a website records the time a specific action happened, those two timestamps can be matched. That is why the strongest providers are so careful to keep no timestamped, per-user connection record — not merely no “browsing history”.

What “no-logs” usually leaves out

In practice, “no-logs” in an advertisement often means “no activity logs” while some connection metadata is still kept. Providers may argue, reasonably, that they need aggregate numbers — total active sessions on a server, total bandwidth — to keep the network running. That is legitimate as long as those figures are aggregate and cannot be tied to an individual. The problem is the providers that blur this line, keeping per-user connection records while still advertising “no-logs”. The word you are looking for in a policy is not “no-logs” but a plain description of exactly what is retained, and for how long.

Why the audit, not the policy, is the proof

A privacy policy is a promise a company writes about itself, so it proves nothing on its own. What turns a no-logs claim into evidence is an independent audit: an outside firm inspecting the systems and publishing a report with its name on it. The firms that do this are well known — Deloitte and KPMG on the accountancy side, and specialist labs like Cure53 and Securitum — and when one signs a report it stakes its own reputation on the finding. Our guide to which no-logs VPN claims are actually audited names the auditor and date for every major provider, because those two facts are the whole story.

How to read a no-logs audit

Read three things in any audit before you trust it. First, the date — most are “reasonable assurance” engagements that describe a single moment in time, so a report from three years ago says little about the servers running today. Second, the scope — did the auditor inspect the live servers and configuration, or only read the written policy? A server inspection is worth far more. Third, who commissioned it and what they were allowed to see; a provider that lets auditors roam is more convincing than one that hands them a narrow checklist.

A single audit is a photograph, not a guarantee. The best providers publish a fresh one every year, precisely because infrastructure changes and a one-off report ages badly. If the most recent audit you can find is old, treat the claim as stale rather than proven.

Words that should make you suspicious

Some phrases are red flags. “Independently audited” with no firm or date named is close to meaningless — ask which firm, and when. “We do not log any personally identifiable information” is a narrower promise than “no activity logs”, and the gap is where metadata hides. “Military-grade encryption” describes standard encryption everyone uses and tells you nothing about logging. And any claim of “total anonymity” is simply false: a VPN cannot make you anonymous, so a provider that says it can is either careless or dishonest.

Open-source apps: another verification signal

An audit checks the servers; open-source apps let anyone check the software on your device. When a provider publishes its client code — as Proton VPN, Private Internet Access, Mullvad and IVPN do — independent researchers can confirm that the app connects where it says, uses the encryption it claims, and does not quietly phone home with data the policy denies collecting. It is not a substitute for a server-side no-logs audit, because the app cannot see what the provider stores, but it closes a gap that a closed-source app leaves open. Reproducible builds go one step further, letting you confirm that the app you downloaded was built from exactly that published code. Where you can get both an infrastructure audit and open-source apps, you have two independent checks instead of one, and that is meaningfully stronger than either alone.

The honest bottom line

“No-logs” is worth wanting, but only when it is backed by a named, recent audit — and it is strongest of all when the claim has survived a real legal demand. A handful of providers have had servers seized or been subpoenaed and produced nothing, which is the closest thing to proof the industry offers. We cover those moments in the no-logs court cases, in detail. Until a claim is audited and, ideally, tested, treat it as a promise — not a fact.

No-logs, in plain terms

Is “no-logs” a legally defined term?
No. There is no regulation that defines “no-logs”, so any VPN can use the phrase. That is exactly why an independent audit matters: it replaces the company's unregulated wording with an outside firm's verified finding about what is actually kept.
Do no-logs VPNs keep any data at all?
Most keep some aggregate operational data, such as the total number of active sessions on a server or total bandwidth, wiped constantly and not tied to any individual. That is different from logging your activity. The test is whether anything kept could ever be traced to a specific person and session.
Can I verify a no-logs claim myself?
Not directly, but you can check the evidence. Look for a named independent audit with a recent date and a server-level scope, RAM-only infrastructure, and ideally a real transparency report or a court case where the provider had nothing to hand over.
Does no-logs mean the VPN can't see my traffic?
No. A no-logs provider chooses not to record your activity, but it still routes your traffic and can see which sites you connect to while you are connected. No-logs is a promise not to keep that information, which is why the provider's proven honesty is what you are really relying on.
What is the difference between a no-logs policy and a privacy policy?
A privacy policy describes everything a company does with data, including billing and marketing. The no-logs claim is one specific part of it: whether the VPN records your activity while you use the service. Read the no-logs section closely, because a company can have a polished privacy policy and still keep more connection metadata than you would expect.

The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.