By Eric L.
09/08/2026 · 7 MIN READ

A "no logs VPN" is a provider that promises not to record what you do through its servers: which sites you visit, what you download, when you connect from which address.

The phrase has no legal definition, so on its own it means nothing. What matters is the specific list of what is and isn't stored, and whether that list is believable given how the service is built. This article explains what a VPN server can see, what a real no-logs policy has to say, and how to check a provider's claim without taking its word for it.

WHAT A PROVIDER CAN SEEFIG. 01
your real IP          technically yes
sites you visit       technically yes
timestamps            technically yes
page contents         no, encrypted
    └─ "no logs" means choosing
       not to keep the first three

What a VPN provider can see

Once you connect, the VPN server is where your traffic is decrypted and forwarded. Technically, the provider can see everything your ISP could see before: the domains you visit (via DNS and TLS server names), timestamps, data volume, your real IP address, and the server you connected to. It can't see the content of HTTPS pages, which is nearly everything today. The details of what is visible at each hop are in what can my ISP see.

So "no logs" is a promise not to write down what the server can see. Whether it's kept is a question of policy, architecture and incentives.

WHAT A PROVIDER CAN SEEFIG. 02
which server you connect to
when, and for how long
the names your traffic resolves
how much data moved
   └─ seeing is unavoidable;
      storing is a choice

Types of VPN logs: activity and connection

  • Activity logs: sites, DNS queries, connections, content metadata. A no-logs provider must not keep these, period.
  • Connection logs: your real IP, connection timestamps, server used. Some providers keep these briefly for abuse handling; a strict no-logs provider doesn't keep them tied to your identity.
  • Aggregate statistics: total data volume per period, number of active sessions, server load. These don't identify what you did, and almost every provider keeps some of them because billing and capacity planning need them.
  • Account data: email, subscription status, payment records. Unavoidable if you pay.

A provider that says it keeps nothing at all is either not running a business or not being precise. The honest version says which of these four it keeps and for how long.

THREE KINDS OF LOGSFIG. 03
connection  who connected, when
usage       which sites, which apps
aggregate   counters with no person
   └─ "no logs" almost always means
      the middle one only

What a real no-logs policy looks like

Look for specifics rather than slogans. Here's the shape a credible policy takes, using 404 VPN's privacy policy as an example. It states that the service doesn't store browsing history, DNS queries, traffic content or metadata, or the source IP address after the VPN connection is established. It also states what it does store: the account email, subscription status and plan, and aggregated technical statistics such as data volume per period and the date of last connection, kept while the account is active and deleted within 30 days of a deletion request.

A SLOGAN VS A LIST● A SLOGAN"zero logs"nothing to check● A LIST YOU CAN HOLD THEM TONOT STOREDSites you visitDNS queriesTraffic content, metadataSTOREDAccount emailSubscription and planAggregate statisticseach with how long it is keptOn a legal request, a provider with no activity or connection logs can hand over only the right column.
A list can be checked and quoted back to the provider; a slogan can't, and a legal request reaches only what is stored.

That last paragraph is the tell. A policy that lists the stored items is one you can hold the provider to. A policy that only repeats "zero logs" gives you nothing to check.

QUESTIONS WORTH ASKINGFIG. 04
which fields exactly are stored?
for how long?
under which jurisdiction?
who owns the company?
when was the last audit?
A policy that names a retention period is promising something a slogan never has to keep.

How to verify a no-logs VPN: questions to ask

  1. What exactly is stored, and for how long? If the answer is a list, good. If it's an adjective, no.
  2. Is DNS handled inside the tunnel, on the provider's own resolvers? Otherwise a third party gets the domain list.
  3. What happens on a legal request? A provider that keeps no activity or connection logs can only hand over what it has: account email and aggregate usage. A provider that keeps connection logs can hand over your IP history.
  4. Which jurisdiction, and has the policy been tested? Court cases and independent audits where the provider could produce nothing are the strongest evidence that exists.
  5. How are servers run? Diskless servers that hold everything in memory, and configurations that assign session addresses dynamically and wipe them on disconnect, make retention technically hard rather than just promised.
  6. How does the business make money? A paid subscription is a clear answer. Anything else deserves a closer look.
WHAT A SERIOUS POLICY HASFIG. 05
[ ] names the exact fields kept
[ ] names the retention period
[ ] names the jurisdiction
[ ] has an audit, with a date
[ ] says what a court order gets
An audit with no date attached is a press release, not evidence.

Why "free no-logs VPN" is a contradiction

Servers, bandwidth and staff cost money. A free service has to recover that somewhere: advertising built on your browsing, selling aggregated or not-so-aggregated data, injecting content, or using your device as an exit point for other customers. Each of those requires exactly the data a no-logs policy says isn't collected. There are a few honest free tiers funded by paid plans, with limits on data or servers; the rest should be assumed to log by design. A free tier that states its limits and is attached to a paid product is a different thing from a free app with no visible business.

WHAT IT NEVER COVERSFIG. 06
your logged-in accounts
cookies and fingerprint
what the sites themselves store
payment records
   └─ a policy governs one server,
      not the whole internet

What no-logs doesn't cover

  • The websites you use. They see the VPN's address but still see your account, cookies and browser fingerprint. The Privacy Checker shows how much a site learns without your IP.
  • Your device. Apps and the operating system keep their own histories.
  • Leaks. If DNS or IPv6 escape the tunnel, the ISP gets the domain list regardless of the provider's policy. Test with is my DNS leaking.

A policy is easier to judge when you pull the claims out of it first.

Prompt for an AI
Help me judge a VPN provider's no-logs claim.

Provider: (name). Jurisdiction: (if stated).
What the policy says it keeps: (quote it, or
"not stated").
Retention period: (quote it, or "not stated").
Audit: (who, when, or "none listed").
Ownership: (parent company, if stated).

Tell me which claims here are checkable and which
are just assertions, and what is missing that a
serious policy would include.
Do not rate the provider on reviews or star
ratings: work only from these facts.

The practical summary

"No logs" is worth exactly as much as the list behind it. Read for specifics, prefer providers that state what they do keep, check that DNS stays inside the tunnel, and be suspicious of anything free that can't explain its income. Then test your own connection, because a policy can't fix a leak.

A POLICY CAN'T FIX A LEAKYour devicetunnelVPN serverno-logs policy appliesDNS or IPv6 leakYour ISPgets the domain listregardless ofthe provider's policyThe policy governs the server. Whether DNS stays in the tunnel is something you test yourself.
The promise covers one server; a leak goes around it, straight to your ISP.

404 VPN keeps DNS inside the tunnel, both in its VLESS apps and in the WireGuard configs for Istanbul and Marseille (those resolve through 1.1.1.1 and 9.9.9.9), has a kill switch in the Android app, and publishes a privacy policy that lists what is stored and what isn't. You can read the security page for how the tunnel is built, or get started here.