Judging a VPN on Privacy: Sorting Claims by What Can Be Checked

Every privacy claim a VPN provider makes belongs to one of three groups: things you can verify yourself in an evening, things an outside party can test on your behalf, and things nobody can verify at all. Almost all of the marketing lives in the third group, and almost all of the useful evaluation lives in the first two.

Nobody can tell you which provider is most private, including a provider’s own auditor. What can be done is sorting the claims, so that you know which parts of a decision rest on evidence and which parts rest on trust.

Group one: what you can establish yourself

These require no expertise and no tools beyond the software itself, and they are the most neglected part of any evaluation.

What the signup demands. A service that requires more identifying information than it needs to bill you has told you something about its priorities. Note what is mandatory versus optional, and what it says it does with it.

What the application asks of your device. Permissions, background behaviour, and anything bundled that is not the tunnel. An application that wants more access to the device than its function requires is a privacy question in itself.

Whether it tells you the truth about its own state. Connect, then deliberately break the connection and watch what the software does. Does it say clearly that you are exposed, or does it show a reassuring interface while traffic goes out normally? This is the single most informative test in the list, and providers are not graded on it anywhere.

What the privacy policy says, as distinct from what the marketing says. They are frequently written by different people for different purposes, and where they disagree the policy is the operative document. Look for what is collected, how long it is kept, who it is shared with, and which of those sentences are hedged.

Whether the documentation is current and specific. Documentation that is vague where it should be precise is a signal, and it is a free one.

Group two: what an outside party can test

Here you are relying on someone else’s work, which is legitimate as long as you understand exactly what their work covered.

An independent audit establishes that specified things were examined at a specified time and found to match a specified description. That is genuinely valuable and much narrower than the announcement implies. Before treating one as reassurance, find out what was in scope, who commissioned it, whether the report itself is published rather than summarised, and how long ago the examination happened. An audit is a snapshot of a configuration, and configurations change the day after.

Published source code lets people establish what the software on your device does. It says nothing about what runs on the servers, which is where the interesting questions are.

Court and regulatory records are the strongest available evidence class, because they show what actually happened when a provider was compelled rather than what it promised. They are rare, and they are also specific — one case tells you about one demand at one time in one jurisdiction.

Documented incidents are worth more attention than they usually get. How a provider behaved during a failure, and how completely it disclosed it, is informative in a way no marketing claim can be.

Group three: what nobody can verify

This is where the strongest-sounding claims sit.

Whether a promise is being kept right now, at scale, across a fleet of machines you cannot inspect, is not observable by any customer. Neither is whether a company would resist a demand, whether an employee has access they should not have, or whether the corporate structure will look the same next year.

That does not make the claims worthless. It makes them promises. A promise from an accountable organisation with a documented history is worth something, and the correct way to hold it is as trust rather than as knowledge. The failure mode is not believing a provider; it is believing you have evidence when what you have is a sentence.

Why the no-logs claim sits almost entirely in group three

The retention promise is the centre of privacy marketing in this category, and it is a policy statement. A provider is describing what it has chosen to configure. Choices can change, quietly, and the change is invisible from outside.

There is one thing that lifts part of it into group two: the difference between a provider that promises not to keep something and one that designed the system so that the something is not produced in the first place. The second is an architectural claim, it can be described in detail, and the description can be examined. Ask which one you are being offered. Most marketing does not distinguish them, and the distinction is the whole substance of the question, as what a no-logs VPN policy means sets out.

What a checkable claim looks like

Whatever the subject, a claim you can do something with has four qualities. It is specific about what is and is not covered. It is scoped to a mechanism rather than an outcome. It is dated, so you know what period it describes. And it is falsifiable — you can say what observation would prove it wrong.

Hold a marketing page against those and most of it disappears. What survives is the small set of statements you can act on.

Wording that should slow you down

  • Anonymity, stated flatly. No provider can deliver it, because most of what identifies you online is your accounts and your behaviour, not your address. This is the ground covered by can a VPN be traced.
  • Impossible-to-comply framing. Any company can be compelled by the jurisdiction it operates in. A provider claiming otherwise is either misdescribing its own position or misunderstanding it.
  • Grades of encryption as a selling point. The cryptography is not where providers differ meaningfully, and emphasising it usually means avoiding the parts where they do.
  • Absolute quantifiers. Never, nothing, nobody, always. Real systems have exceptions and honest documentation names them.
  • Trust language substituting for structure. Awards, longevity, and popularity are not evidence about data handling.

What no provider can fix for you

A tunnel changes which network sees your traffic and which address a service records. It does not touch the accounts you are signed into, the identifiers your browser hands out, the permissions you have granted, or anything you type. Where the address is the smaller part of the problem — and for most people it is — the provider choice is the smaller part of the answer, which is the argument in what a VPN does not change about your location.

Bottom line

Sort every claim before weighing it: verify signup demands, application behaviour and disconnection handling yourself; treat audits, published code, and court records as narrow but real outside evidence; and file the rest as promises rather than facts. Prefer a provider that distinguishes what it has designed from what it has merely undertaken, and be most suspicious of the claims that are most reassuring, because those are the ones nobody can check.