Skip to content
VPNmine
PRIVACY AND LAW

What "no-logs VPN" actually means

No-logs never means no records. Every provider that runs servers keeps something, because accounts, billing and abuse handling require it. A meaningful claim states exactly what is stored, why, and for how long, and distinguishes connection metadata from the contents of your traffic.

4 min read

Illustration of a text document and a prohibited sign, joined by a dashed tunnel line on a dark grid.

"No-logs" is the most repeated claim in this industry and the least specific. Taken literally it would mean a service that records nothing at all, which is not a thing that can exist: an account has to be stored somewhere, a payment has to be reconciled, and a server under attack has to be defended.

What the phrase should mean is that the provider does not keep the records that would let it, or anyone who compels it, reconstruct what you did.

The categories that matter

Traffic content. What you actually sent and received. No serious provider stores this; storing it would be enormous and indefensible.

Browsing history and DNS queries. Which sites you opened. This is the category that matters most, because it is small enough to store cheaply and revealing enough to be worth something. A no-logs claim that does not explicitly cover DNS queries is not covering the most valuable data.

Connection metadata. Which account connected, to which server, at what time, from which address, and how much data moved. Almost every provider keeps some of this, because capacity planning and abuse handling need it. The questions are which fields, for how long, and whether the source address is among them.

Account data. Email address, payment records, support tickets. Kept by anyone with accounts, and subject to normal data protection law.

How to read a policy

Four questions, and a policy that cannot answer them is not saying much:

  1. Is the connecting IP address stored? This is the field that links a session to a person. A provider that keeps it alongside timestamps can answer "who was using this exit address at this time" whatever else it discards.
  2. Are DNS queries stored? If the policy does not mention DNS, ask.
  3. For how long? "As long as necessary" means nothing. A number means something.
  4. What does the provider do when it receives a legal request? A provider that has nothing hands over nothing; one that has records hands them over.

Why vagueness is common

Partly because specificity creates obligations. A provider that publishes "we retain the connecting IP address for 30 days" has made a commitment that can be checked and can be embarrassing. "We are a strict no-logs provider" cannot be falsified and cannot be breached.

Partly because some providers do keep more than they would like to say, and the phrase is doing work.

And partly because a genuinely specific policy is harder to write, since it requires knowing precisely what every part of the infrastructure records — which is a question a surprising number of operators have not fully answered internally.

What VPNmine records

Being concrete, since the whole point of this article is that vagueness is the problem. VPNmine records which server a session used and when it ran, because abuse handling and capacity planning need it. It does not record browsing history, DNS queries or traffic content. The privacy policy lists this as a table rather than a paragraph, which is the format that makes a claim checkable.

VPNmine has not been independently audited. That is stated plainly here because a claim about logging is only as good as the willingness to say what has not been verified.

The things a policy cannot promise

That the servers are configured as described. A policy is a statement of intent. Verifying it requires an audit, and even an audit is a snapshot.

That nothing is observed in transit. A server necessarily processes your traffic to forward it. "Not logged" means not written down, not "not seen".

That the hosting provider keeps nothing. VPN servers are usually rented, and the host has its own logs of network flows at the infrastructure level. A provider can be scrupulous and still sit on top of someone else's records.

That the law will not change. Data retention obligations vary by country and move.

A better question than "do you log"

Ask what a provider would be able to produce if compelled tomorrow. That single question cuts through the marketing, because it is about capability rather than policy. A provider that cannot produce a browsing history because it never existed is in a different position from one that promises not to look at the one it has.

The terms and the privacy policy together should answer it. If they cannot, that is the answer.

Sources

  1. GDPR Article 5 — principles relating to processing
  2. EU Court of Justice — Digital Rights Ireland (data retention)
  3. RFC 6973 — Privacy Considerations for Internet Protocols

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine