Understand

What is a no-log VPN policy, explained

MCThe MiisterSoftware team Updated July 2026 8 min read
No activity logs Proven by audit Jurisdiction matters RAM-only servers
Politique no log

TL;DR, the essentials

  • A no-log VPN policy (also called “zero-logs”) means the provider keeps no record of what you do online: sites visited, files, precise timestamps or your real IP address.
  • The real dividing line is between activity logs (a deal-breaker) and connection logs (sometimes tolerated, but worth watching). A promise only counts if it is verified by an independent audit.
  • Jurisdiction (the provider’s home country) and RAM-only servers add credibility. A genuine no-log policy protects your privacy, but it does not make you anonymous.

It is every provider’s number-one selling point: “no-log policy,” “zero logs,” “we know nothing about you.” But what does a no-log VPN policy actually mean, and more importantly, how do you know it holds up? A VPN shifts trust away from your internet provider and onto the VPN company, which necessarily sees your traffic pass through its servers. The whole question is what it keeps. Here is what no-log really covers, the crucial difference between types of logs, and how to check that a provider is not spinning a story.

What exactly is a no-log VPN policy?

A no-log policy, also called a “zero-logs” policy, is a VPN provider’s commitment to not record or retain the data that could tie an online activity back to a specific user. In practice, a genuinely no-log service keeps neither the list of sites you visit, nor your originating IP address, nor detailed timestamps of your sessions. Here is how a credible absence of logs is built, technically.

1

The written commitment in the policy

It all starts with the provider’s privacy policy. It should spell out in black and white what is NOT collected (IP, sites, DNS, precise times) and the little that may be (aggregate connection counts, total volume). A vague or evasive policy is the first red flag.

2

The technical architecture that makes it possible

Keeping nothing is not just a statement, it has to be built. Servers are configured not to write persistent logs, often by running entirely in memory (RAM), so a reboot wipes everything. This is the “provable” part of the promise.

3

Independent third-party verification

Finally, an external audit firm inspects the servers, configuration and processes to confirm that reality matches the messaging. Without this step, no-log remains a marketing claim.

In other words, a credible no-log policy rests on three pillars: a clear commitment, an architecture that allows it, and independent proof. If any of the three is missing, caution is warranted.

Politique no log

Connection logs or activity logs: the difference that changes everything

Not all “logs” are equal, and this is where a lot of marketing keeps things blurry. You need to tell two broad families of logs apart.

Activity logs (usage logs) are the most sensitive: they record what you do, namely the sites and apps you open, your DNS queries, downloaded files and browsing history. A VPN that keeps this kind of data is disqualified for privacy on the spot, because this is exactly what a VPN is supposed to hide.

Connection logs cover session metadata: connect and disconnect timestamps, originating IP address, the IP of the server used, and the volume of data exchanged. Taken together and stamped to the second, they can be enough to re-identify a user. Some providers keep an aggregated and anonymized version (total connection counts, server load) to run their network, which is generally acceptable, as long as that data can never be linked back to an individual.

The right question to ask

A serious “no-log” provider keeps no activity logs, and at most aggregated metadata that cannot be tied to a person. To understand where this need for trust comes from, our article on VPN basics in our hub breaks down what your internet provider can and can no longer see.

Want something concrete?

Our comparison breaks down the logging policy, jurisdiction and audits of the best offers around right now.

See the comparison →

Why independent audits matter so much

A provider can write “no-log” in big letters on its homepage: none of it is binding until a third party has checked. That is the whole point of the independent audit, run by an external firm that inspects the servers, configuration and internal processes, then publishes a report. There are generally two levels: the security audit (hunting for flaws) and the no-log assurance audit (confirming no sensitive data is retained), the one that matters most for privacy.

The most transparent providers now publish these reports regularly. A few benchmarks verified in mid-2026:

  • NordVPN: its sixth no-log assurance audit was confirmed by Deloitte, conducted in late 2025 under the ISAE 3000 (revised) standard. One of the most-audited consumer VPNs.
  • ExpressVPN: recurring audits, including a KPMG review of its policy and TrustedServer architecture published in early 2025.
  • Proton VPN: open-source apps and an audited no-log policy, a model built on code transparency.
  • Mullvad: audited by Cure53 and known for reducing data collection to the bare minimum (it does not even require an email address).

Good habit

Look at the date and the scope of the audit. A 2020 report on a single feature is worth less than a recent, recurring assurance audit covering the whole network. A provider that repeats the exercise every year inspires more confidence.

“No-log” promise 📝Independent audit 🔍Public report ✅ = verifiable trust
A no-log promise only counts once an external firm confirms it and it is documented publicly.

Why the provider’s jurisdiction tips the scales

A no-log policy that looks perfect on paper can be undermined by the country where the provider is legally based. Some states impose mandatory data retention for connection records, or can compel a company to monitor a user, sometimes without being allowed to talk about it. That is why jurisdiction gets so much attention.

People often mention the intelligence-sharing alliances known as the “5/9/14 Eyes”, agreements to exchange information between countries (the United States, the United Kingdom, part of Europe and so on). A provider based outside these zones is seen as less exposed to data requests. This is why many VPNs pick privacy-friendly jurisdictions such as Panama (NordVPN), the British Virgin Islands (ExpressVPN), Switzerland (Proton VPN) or Sweden for Mullvad, which is known for collecting very little.

Jurisdiction is not everything

A home base in a “privacy-friendly” country helps, but it does not replace an audited no-log policy. Conversely, an excellent, genuinely audited no-log setup can offset a less-ideal jurisdiction: you logically cannot hand over data you do not hold. Look at both together, not one without the other.

Quick quiz

What best proves that a no-log policy is real?

RAM-only servers, a technical guarantee of no-log

An argument that is increasingly highlighted, and rightly so: servers running entirely in memory (RAM-only). On a traditional server, data is written to a hard drive and stays there, even after power-off. A RAM-only server, by contrast, uses no permanent storage: everything it holds is erased on the next reboot. That makes it impossible to keep durable logs or to seize a drive full of history during a physical raid.

It is a real privacy advantage. NordVPN, ExpressVPN (via TrustedServer) and Proton VPN, among others, have rolled this architecture out across their networks. It makes the no-log promise structurally more credible, because it no longer rests only on the provider’s goodwill, but on a technical constraint.

How do you check a provider’s no-log policy?

You do not need to be a security expert to sort the wheat from the chaff. A simple checklist is enough to rule out hollow promises:

  • Read the privacy policy, not just the marketing page. It should clearly state what is not collected (IP, sites, DNS, times) and what may be.
  • Look for a recent independent audit, with the name of the firm (Deloitte, KPMG, Cure53, Securitum) and the date. Be wary of the word “audited” with no readable report.
  • Check the jurisdiction: where is the company legally based, and does that country impose data retention?
  • Look at the architecture: RAM-only servers, modern protocols (WireGuard, or Lightway for ExpressVPN), open-source apps where possible.
  • Search for legal precedents: several serious providers have had servers seized without any usable data being found, the best proof of a real no-log policy.
A no-log policy is not something you take on faith: you read it, audit it and verify it.

Ready to choose with confidence?

We compared the logging policy, jurisdiction and audits of the best 2026 offers.

See the best VPNs 2026 →

What a no-log policy does NOT do

The essential honesty check. An audited no-log policy is crucial, but it works no miracles:

  • It does not make you anonymous. The provider sees your traffic pass in real time, it simply chooses to keep none of it. A VPN stays a privacy tool, not an invisibility cloak.
  • It does not protect you if you identify yourself (Google account, social media, online purchase): the service then knows who you are, logs or not.
  • It does not make up for bad habits: weak passwords, no antivirus, clicking on phishing. No-log protects the VPN’s logs, not your machine.
  • Ultimately, it rests on trust: even audited, you take the provider’s word that it applies what it declares. Audits and legal precedents reduce that risk, without removing it entirely.

The next step

Want a VPN with a genuinely audited no-log policy? Read our comparison of the best VPNs for 2026, or start from the top in our VPN hub.

Frequently asked questions

What is a no-log VPN policy?

A no-log (or “zero-logs”) policy is a VPN provider’s commitment to keep no data that could tie an online activity to a user: sites visited, DNS queries, real IP address, detailed session timestamps. A credible no-log policy rests on a clear written commitment, suitable technical architecture and verification through an independent audit.

What is the difference between connection logs and activity logs?

Activity logs record what you do (sites, DNS, files, history): they are a deal-breaker for privacy. Connection logs cover session metadata (times, originating IP, volume). In aggregated, anonymized form they are generally tolerated, but stamped to the second and tied to an IP, they can re-identify a user.

How do you check that a VPN is really no-log?

Read the privacy policy (not just the marketing page), look for a recent independent audit with the firm’s name and the date (Deloitte, KPMG, Cure53), check the provider’s jurisdiction, look at the architecture (RAM-only servers, WireGuard) and any legal precedents where seized servers yielded no usable data.

Why is a VPN’s jurisdiction important?

The country where the provider is based determines the laws it must follow. Some states impose data retention or can compel a company to monitor a user. Jurisdictions such as Panama, the British Virgin Islands or Switzerland are seen as more privacy-friendly, outside the intelligence alliances known as 5/9/14 Eyes.

Does a no-log policy make you anonymous?

No. An audited no-log policy stops the provider from keeping a record of your activity, but it necessarily sees your traffic in real time, and you are no longer protected once you identify yourself (account, social media, purchase). A VPN with no-log is a solid privacy tool, not a guarantee of total anonymity.