What a No-Logs Policy Is, and What It Can Promise

A no-logs policy is a company’s stated commitment about which records it creates and keeps. It is a promise, not a mechanism — you cannot verify absence from outside, and no setting in an app makes it true. That means the interesting questions are not technical at all: they are about what the company is obliged to do where it is established, who can require it to do something different, and what an independent examination actually establishes.

For a reader who crosses networks and borders, this matters in a particular way. When you travel, the networks you use change constantly and your provider becomes the one fixed observer of your traffic in every country you visit. Its obligations, not the local Wi-Fi’s, are what stay with you.

Why it cannot be a technical claim

Every other privacy property of a tunnel is observable in principle. You can check that traffic is encrypted, that name lookups go where you expect, that the connection does not leak when it drops.

Retention is different in kind. A record that was never created leaves nothing to find, and a record that was created leaves nothing visible to you either. There is no test you can run from your own device that distinguishes a provider keeping nothing from a provider keeping everything, because the difference exists entirely on machines you cannot inspect.

That asymmetry is the whole reason the category runs on trust, and why marketing leans on the phrase so heavily — it is unfalsifiable from the customer’s side.

Not all records are the same records

“No logs” is doing a lot of work in three words. The distinctions that matter:

Activity records — which sites or services a user reached. This is what people mean when they worry, and what serious commitments centre on.

Connection records — that an account connected, from which address, to which location, for how long, and how much data moved. These can be operationally necessary for enforcing simultaneous-connection limits and diagnosing faults, and a policy may permit them while still using the phrase.

Aggregate operational data — capacity and fault statistics not attributable to an individual.

Account and billing records — your name, email, payment relationship, and support history. These are ordinary business data, usually governed by separate rules, and generally retained because they must be.

Website and app telemetry — the provider’s own site and client software, which may behave quite differently from the tunnel.

A policy can be entirely accurate and still involve more retained data than a reader assumed, purely because those five categories were collapsed into one phrase. Reading the actual document rather than a summary is the fix, and the sorting method is in what to ask before you trust a VPN provider’s claims.

Jurisdiction is the part that binds

A commitment lives inside a legal system, and that system determines things the document itself cannot.

Whether records must be created in the first place. Some regulatory regimes require services of particular kinds to retain identifying information, in which case a promise not to is not available to a company operating there.

Whether the company can be compelled to hand over what it holds, and under what process.

Whether it can tell you that happened, or is prohibited from doing so.

What happens if the promise is broken — whether there is a regulator, a remedy, or anything enforceable at all.

Two providers with identical policy text can therefore be in materially different positions. What this site will not do is tell you what any named country currently requires; that changes, it varies by service category, and getting it wrong matters. The shapes such regulation takes, in categories, are in why VPN rules differ from country to country, and the source for a real decision is an official one.

Note also that the relevant jurisdiction may not be the one on the marketing. The contracting entity, the operating company, the parent, and the physical servers can sit in different places, and it is worth knowing which is which.

What an independent examination settles

An examination is real evidence and it is routinely oversold. What it can establish is that an assessor, given access, found the described practices in place — within a defined scope, at a point in time.

Read four things about any examination before weighting it:

Scope. Which systems, which claims, which parts of the service. An examination of the client software says nothing about server retention. One covering some servers says nothing about the rest.

Date. It reports a past state. Infrastructure, ownership, and policy all change afterwards.

Who commissioned it, and whether the report is readable. Nearly all are commissioned by the provider, which is normal and not disqualifying, but it shapes the scope. An announcement without an obtainable report is a press release.

Methodology. Whether the assessor inspected configuration and procedure or reviewed documents describing them. Both are legitimate; they establish very different things.

What no examination can establish is future conduct, or behaviour under legal compulsion it was never asked about.

Why the traveller cares more than most

Three reasons this is sharper on the road.

Your provider is the constant. The hotel network changes weekly; the provider sees every one of those sessions. Whatever it retains is a record spanning your whole trip rather than one evening.

Your traffic pattern is unusually revealing while travelling. Where you connected from and when, taken together, describes an itinerary. Connection records that seem innocuous at home describe your movements abroad.

Local conditions can change what a provider does. A service operating in many countries may be subject to obligations in some of them, and may make different arrangements accordingly. That is a reason to read what the provider says about the specific markets you care about.

What to do with all this

  • Read the actual policy, and note which of the five record categories each sentence refers to.
  • Identify the contracting entity and where it is established, rather than the brand’s stated home.
  • Look for an examination and read its scope and date, not its headline.
  • Assume connection records may exist unless the policy is explicit that they do not.
  • Assume account and billing data exist, because they almost certainly must.
  • Calibrate the rest accordingly. A tunnel narrows who observes your traffic; it does not remove observation, and what the provider itself sees is set out hop by hop in can a VPN be traced.

Bottom line

A no-logs policy is a commitment made inside a legal system, unverifiable from your side, covering categories of record that the phrase itself does not distinguish. Judge it on the actual document, the jurisdiction of the entity you are contracting with, and the scope and date of any independent examination — and treat “audited” as evidence about a past state rather than a guarantee about the next one.