What to Ask Before You Trust a VPN Provider's Claims
This is not a review of any provider, and it contains no verdict, no ranking, and no feature list. We have not run the testing that would make a review honest, and restating a company’s own marketing under a review heading is the thing this site exists to avoid — the longer version of that position is in why this site does not publish VPN reviews.
What is durable, and what this page gives you, is a way to sort any provider’s claims into three piles: the ones you can check for yourself, the ones you can only take on trust, and the ones nobody can establish at all. That sorting survives every price change, rebrand, and acquisition.
Pile one: claims you can check yourself
These require no special access. Reading them takes an evening and tells you more than any listicle.
The policy text, in the provider’s own words. Not a marketing page summarising it — the actual document. Read what it says is collected, for how long, and for what purpose. Note whether it separates connection records from activity records, and whether it distinguishes the service from the website, the apps, and the payment system, which frequently have different practices.
Where the company is established, and which entity you are contracting with. This is normally in the terms or a corporate registry, and it is often a different name and a different country from the brand.
Whether an independent examination exists, and its scope. If one does, the question is not whether it happened but what it covered, who commissioned it, when, and whether the report itself is readable rather than merely announced.
Whether the client software’s source is published, and if so which components. Publication does not by itself prove anything about server-side conduct, but it makes one part of the system inspectable.
How they respond to legal demands, if they publish anything about it at all. Some do; the absence of any statement is itself information.
What happens when you leave. What is deleted, when, and whether you can request it.
How the software behaves on your own networks. Install it, take it to the kinds of connection you actually use, and see whether it holds up. This is the one genuinely empirical thing you can do without a lab.
Pile two: claims you can only take on trust
Here the provider is telling you about its own internal conduct, and you have no independent view.
That it does not retain what it says it does not retain. Absence cannot be observed from outside. This is the central limitation of the entire category, and it is why the policy text and the jurisdiction matter more than any feature.
What happens on the servers. Whether the fleet is configured as described, whether logging is genuinely disabled, whether operational data is separated as claimed.
What is done with account, billing, and support records, which are ordinary business data and often governed by different rules from the tunnel itself.
How incidents are handled. Whether a problem is disclosed, and how quickly, is a matter of institutional character rather than technology.
An independent examination narrows this pile — it does not empty it. An examination reports on what an assessor observed, within a defined scope, at a point in time. It is meaningful evidence and it is not a guarantee about tomorrow.
Pile three: claims nobody can establish
Be wary when any of these appear, from any provider or reviewer.
- Complete anonymity, or being untraceable. No consumer service can promise this, and the reasons are in can a VPN be traced.
- Guaranteed access to any particular restricted service or network. The other side keeps moving; nobody controls both ends of that.
- Protection against threats a tunnel does not touch, such as your own accounts, your device, or what you have already disclosed.
- Permanence. Ownership, management, jurisdiction, and policy can all change after you subscribe, and frequently do.
Why jurisdiction shapes a promise
A privacy policy is a commitment made inside a legal system. That system determines what records a company may be required to create, what it can be compelled to hand over, whether it can tell you that happened, and what recourse you have if the promise is broken.
Two providers with identical policy text can therefore be in materially different positions, because the enforceability and the compulsion sit outside the document. The practical questions are: which country’s law governs the entity you are contracting with, what obligations exist there for services of this kind, and whether the provider addresses that anywhere in its own materials.
What this site will not do is tell you what any named country’s law currently requires. That changes, it varies by service category, and getting it wrong matters — the shape such rules take, in categories, is in why VPN rules differ from country to country, and the source worth using for a real decision is an official one or a qualified adviser.
Where the authoritative answer actually lives
For any specific provider question, the ranked sources are:
- The provider’s own current documents — policy, terms, and any transparency material. Dated, in their words, and what they can be held to.
- The independent report itself, if one exists, read for scope and date rather than for the headline.
- Corporate and regulatory records for who owns and operates the entity.
- Court and regulatory filings, where a claim has actually been tested.
- Your own hands-on trial on your own networks.
Notably absent: any ranked list, including one that agrees with you.
The questions worth asking, in order
- What exactly is collected, by which part of the service, and for how long?
- Which legal entity am I contracting with, and where is it established?
- Has anything been independently examined — what scope, whose commission, what date?
- What is published about responses to legal demands?
- What happens to my data when I stop paying?
- Does the client survive the networks I will actually be on?
- What does the provider decline to say? The gaps are usually the answer.
Bottom line
Sort every claim before you weigh it: read the policy and the jurisdiction yourself, treat conduct claims as trust rather than fact, and dismiss the promises nobody could keep. Then test the software on your own connections. That is a decision you can defend, and it is the closest thing to a review this site will offer.