# VPN provider no logs: what the claim means and how to check it URL: https://webvpn.org/no-logs-vpn/ Updated: 2026-09-09 What a VPN provider with no logs must not record, how to read a no-logs policy, what audits and court cases prove, and where free no-logs VPNs fit in. ## Why the logging question decides everything A VPN server sees what your internet provider used to see: your real address on one side and every destination on the other. If the provider writes that down, the VPN has not removed a record of your activity, it has moved the record to a different company in a different country. A VPN provider with no logs is the only kind that actually removes it. That is why the no-logs claim, not server count or speed, should decide which VPN you install. This guide breaks down what a real no-logs policy excludes, how to tell a verified policy from a slogan, and what the free options look like. ## The three kinds of logs Providers use the phrase loosely, so start by separating what could be logged: - Activity logs record where you went: domains, IP addresses of destinations, DNS queries and sometimes content of unencrypted traffic. No serious provider admits to keeping these. - Connection logs record when you connected, from which real address, to which server, and how much data moved. Many providers that advertise no logs still keep some of this, sometimes for days. - Aggregate metrics record totals per server, such as current load or bandwidth used across all users. These cannot identify anyone and are needed to run the service. A VPN with a strict no logs policy keeps only the third category. When a policy says it keeps no activity logs but is silent on connection logs, read that silence as an answer. ## What a good policy states explicitly A trustworthy policy names the data it does not collect rather than making a general promise. Look for these exact items, phrased in plain language: - Your originating IP address is never stored. - Connection and disconnection timestamps are never stored. - The VPN server address assigned to your session is never stored. - DNS queries are resolved on the provider's own servers and not retained. - Bandwidth is not tracked per account beyond what is needed for a free tier's limit. - Payment records are kept separately and cannot be linked to VPN sessions. Mullvad's policy at mullvad.net is a useful reference for how short and specific this can be, and Proton VPN's at protonvpn.com shows a policy paired with published audits. Read the current text on those sites, because policies are revised. ## Audits: what they prove and what they cannot An independent audit is a named security firm examining the provider's servers, configuration and sometimes source code, then publishing what it found. A good audit report states its scope, its dates, the methods used and any findings. A press release that mentions an audit without linking the report is not an audit. Audits have limits. They confirm the state of the systems on the days the auditors looked. They do not guarantee that the configuration remained unchanged afterwards, and they rarely cover every server. Treat a recent audit as strong evidence that the provider's practice matches its policy, and treat an audit older than a couple of years as a reason to ask what has changed. ## Court cases: the only real-world test The strongest evidence that no logs exist comes when someone with legal authority demands them. Public court records and law-enforcement statements from several countries describe orders served on VPN providers. In the cases where the provider genuinely retained nothing, the outcome was that no user data could be produced, and in some cases servers were seized and found empty of useful records. For a reader, the lesson is simple. A provider can point to a documented case where it was asked and had nothing to give. That is a fact you can check in the public record, and it carries more weight than any marketing page. Providers with a documented history of handing over logs after promising not to keep them also exist, and that history is equally checkable. ## RAM-only servers and other design choices Several providers now run servers that boot from a read-only image and hold everything else in memory. When the machine restarts, whatever was in RAM disappears. This does not by itself prove that nothing was written elsewhere, but it removes the easiest place for logs to accumulate and it makes physical seizure of a server far less useful. Related design choices worth looking for include running DNS resolvers in-house so queries never reach a third party, accepting cash or anonymous payment so that billing cannot be tied to identity, and publishing a warrant canary or transparency report that lists legal requests received. None of these replace an audit, but together they show a provider that has thought about the problem. ## Proton VPN's no-logs policy as an example Because Proton VPN no-logs policy is one of the most searched phrases on this topic, here is how it lines up against the checklist. Proton states that it does not log IP addresses, connection timestamps, session lengths or browsing activity. The policy has been examined by an external firm on more than one occasion and the reports are published. The apps are open source, DNS is handled on Proton's servers, and the company publishes a transparency report of legal requests. That combination of a specific policy, published audits and open code is what a verified no-logs claim looks like. It is still worth reading the current policy and the most recent report yourself, since dates and scope are what make the evidence current. ## Is there a free no-logs VPN? Running servers costs money, so a free VPN with no paid product has to earn revenue another way, and logging traffic for advertisers is the usual one. Security vendor reports have documented free VPN apps that did exactly that, including some with millions of installs. The safe form of free is a limited tier of a paid, audited product. Proton VPN's free plan runs under the same no-logs policy as its paid plans, with fewer locations and lower priority on speed. If you need a no logs VPN that is free, that is the shape to look for: a company with a paid tier, a published policy and an audit that covers the free users too. ## A five-minute policy review Before installing any VPN, spend five minutes on the provider's own site: - Open the privacy policy and search for the words IP, timestamp and DNS. Each should appear in a sentence saying it is not stored. - Find the audit page. Note the auditor's name, the date and whether the full report is linked. - Look for a transparency report or a documented legal case. Note whether any user data was ever produced. - Check who owns the company and in which country it is registered. - Confirm the apps are open source or at least that the protocol is WireGuard or OpenVPN. If any of the first three steps come up empty, the no-logs claim is unverified and you should treat the provider as one that may log. ## What to do with this today Slogans are free and audits are expensive, which is exactly why the audit is the thing to look for. Pick the provider you are considering, run the five-minute review above, and write down the audit date. If the date is recent and the policy names the specific data it excludes, you have found a provider whose no-logs claim you can defend. If not, the are VPNs safe guide will help you weigh the alternatives, including Tor. ## FAQ Q: What does a VPN with a strict no logs policy actually not store? A: At minimum, it does not store your real IP address, the times you connected and disconnected, the VPN server addresses assigned to you, your DNS queries and the sites or services you reached. Some providers keep aggregate counts such as total server load, which is fine as long as nothing can be tied to a single user. Q: Is there a no logs VPN that is free? A: Yes, in a limited form. Proton VPN offers a free tier under the same audited no-logs policy as its paid plans, with fewer servers and lower speed. Free VPNs from companies with no paid product and no audit usually log traffic to pay for the servers, so treat them as the opposite of no-logs. Q: How is a no logs claim ever verified? A: Through two kinds of evidence. Independent audits, where a named security firm inspects servers and code and publishes a report. And real-world tests, where a court or police order demands logs and the provider can show that nothing existed. A provider with neither is asking you to take its word. Q: What is Proton VPN's no-logs policy? A: Proton VPN states that it does not log your IP address, connection times, session length or online activity, and has had that policy examined by an external audit firm more than once. Read the current policy and the latest audit on protonvpn.com, since both are updated over time. Q: Is NordVPN a no-log VPN? A: NordVPN publishes a no-logs policy and has commissioned repeated independent audits of it. As with any provider, confirm the date and scope of the most recent audit on the company's own site rather than relying on a summary, because scope varies between audits.