Skip to main content
Back to blog

What a No-Logs Policy Actually Means, and How to Check One

VPN

What a No-Logs Policy Actually Means, and How to Check One article illustration

Every serious VPN provider says it keeps no logs. None of them means quite the same thing by it, and none of them is using a phrase that has a legal definition behind it. What matters is narrower and duller than the marketing suggests: what a provider is technically able to hand over when somebody asks for it.

What a no-logs policy actually is

A no-logs policy is a promise about what a company does not retain. It is not a certification. No standards body issues it, no regulator approves it before it goes on a homepage, and two providers can display the same phrase while holding very different amounts of data about you.

That makes the phrase nearly useless on its own, and it makes the document behind it genuinely useful. The privacy policy is where a promise gets specific, and the specificity is the entire signal. A policy that enumerates what is stored, field by field, is making a claim you can hold it to. A policy that says “we do not log your activity” and stops there has told you nothing about connection timestamps, bandwidth totals, or the email address attached to your account.

One thing to separate out early, because it causes a lot of confusion. A no-logs claim is about the provider. It says nothing about whether your traffic is going through the tunnel at this moment, which is a different question with its own answer, and one you can settle yourself by checking whether your VPN is actually working.

Three kinds of data, and only one of them is really in dispute

Activity logs. The sites you visited, the DNS queries your device made, the contents of your traffic. This is what people picture when they hear the word logs, and it is the one category essentially every commercial provider says it does not keep. A provider retaining this would be selling the opposite of its own product.

Connection metadata. When you connected, from which IP address, to which server, for how long, and how much data you moved. This is the category that actually varies between providers, and it is the category that identifies people. You do not need to know which sites somebody visited to place them on a particular server at a particular minute. When a policy turns vague, this is usually what the vagueness is covering.

Account data. Your email address, your payment record, your support tickets. Every provider that bills you holds some of this, no audit removes it, and it is the easiest of the three to compel, because it sits in ordinary business systems rather than on a VPN server.

The distance between the first category and the third is where the phrase does its marketing work. “No logs” invites you to hear the first one and forget the third.

What the minimal end of the market looks like. Mullvad publishes its whole account data model rather than describing it. An account is a randomly generated number with an expiry date attached, with no username, no password and no email address, and where WireGuard is used it stores an account number, a public key and a tunnel address. Its policy states that it never stores activity logs of any kind. You can disagree about the provider and still recognise the shape of the claim: it says what exists, not just what does not.

What an independent audit adds, and what it does not

An audit is the strongest evidence generally available for a no-logs claim, and it is narrower than the marketing built on top of it.

Take the most recent example in this market. NordVPN commissioned Deloitte Lithuania to carry out an assurance engagement on its no-logs claims under ISAE 3000 (Revised). The work ran from 10 November to 12 December 2025, the report was issued on 12 December 2025, and the conclusion, in the company’s own summary, is that its systems “are designed and implemented in line with our no-logs statement”. The pricing and feature detail sits in our NordVPN review if you want the commercial picture alongside it.

Read that conclusion closely, because it is doing something more limited than “this provider keeps no logs”. It measures the systems against the provider’s own statement of what it does. Where that statement is narrow, a clean result is narrow with it.

Two further limits, both stated by NordVPN rather than raised by a critic. The first is that this is a point-in-time assessment, covering the systems as they ran during that window and making no claim about the period after it. The second is that the report is not public: the company says that because of the technical nature of the report it does not publish excerpts, and that users can read the full version by logging in to their account. What most readers can actually see, then, is a summary of a document they will never read.

None of that makes the exercise theatre. A provider that repeatedly pays a large audit firm to inspect its server configurations is accepting a cost and a risk that a provider making the same claim in a footer never takes on. It is real evidence about a defined scope at a defined moment, which is a useful thing and not the same thing as proof.

The moments a claim gets tested without warning

Audits are scheduled, scoped and paid for by the subject. The involuntary tests are more informative, and there have been very few of them in public.

The clearest one in this market is NordVPN’s disclosure of a 2018 breach at a Finnish datacentre, published in 2019. A single server was reached without authorisation through a remote management account the datacentre had added without NordVPN’s knowledge. In its own account, the company says the intruder “did not find any user activity logs because they do not exist”, and that the incident “effectively showed that the affected server did not contain any user activity logs”.

That is a provider narrating its own worst week, so read it as an interested account rather than a neutral one. The structure of the event is what makes it worth citing anyway. Nobody chose the timing, nobody negotiated the scope, and whatever sat on that disk had been sitting there all along. A scheduled audit cannot manufacture that kind of evidence, which is why an unplanned incident, handled openly, tends to move informed opinion more than another clean report does.

What you can actually do about it

Read what a policy enumerates, not what it denies. Denials are cheap and close to unfalsifiable. A list of stored fields is a commitment that can be checked against behaviour. If you cannot find a specific account of what is kept, you have not found a no-logs policy, you have found a slogan.

Weigh the jurisdiction, then hold it loosely. Where a company is incorporated shapes which courts can compel it and which retention rules it operates under, so it is a real factor. It is also routinely oversold. A provider that genuinely holds nothing is in much the same position wherever it is registered, and a provider holding plenty is not rescued by a favourable address.

Ask them directly. Almost nobody does this and it costs nothing. If you are in the UK, data protection law gives you a right of access, which lets you ask an organisation whether it is using or storing your personal information and ask for copies of it. The Information Commissioner’s Office is explicit that anyone can make one of these requests, that you do not need a solicitor, and that organisations usually have one month to respond. Similar rights exist in a number of other countries, so it is worth checking what applies where you are. Two caveats belong in the same breath: the request cannot surface something a provider genuinely does not hold, and the ICO notes that an organisation can sometimes refuse to provide some or all of the information. Treat whatever comes back as a data point rather than a verdict. It is still a better source than a homepage.

Judge the disclosure, not the slogan. How a provider behaves when something goes wrong is more informative than what it claims while everything is fine. A published incident timeline, a named auditor, a dated scope and an admission of what was not covered are all signs of a company that expects to be checked.

A logging policy is a promise about a company, and you will never fully verify it from the outside. What sits entirely within your reach is the other half of the question: whether your connection is behaving the way you think it is. Compare your visible IP, ISP and location before and after connecting with the VPN check, then run the Network Leak Check to see whether anything is still reaching the internet outside the tunnel. If you want the broader picture of who sees what once the tunnel is up, what your ISP can actually see covers where that visibility moves to rather than disappears. And our VPN review methodology sets out how logging claims, account data, policy clarity and jurisdiction are weighed here, including where an affiliate relationship sits in that.

The useful version of this phrase is not a badge. It is a question you can ask of any provider, in the same words every time: what exactly do you store, who has checked, when, and what did they not look at.