No-Log VPN Policies Are About Details, Not Vibes
"No logs" sounds simple. You use a VPN. The VPN does not save what you do. End of story.
The annoying part is that the phrase gets used for a lot of different things. One VPN might mean it does not save your browsing history. Another might mean it does not save DNS requests. Another might still keep connection timestamps, your real IP address, the VPN server you used, and how long you stayed connected.
That difference matters. A VPN no-log policy is not useful because the words sound private. It is useful when it clearly says which data is not collected, which data still exists, and how long anything is kept.
There are different kinds of VPN logs
The big one is activity logs. That means the websites you visit, searches you make, apps you use, files you download, or DNS requests your device sends. A privacy-focused VPN should not keep those. If it does, you have mostly moved trust from your internet provider to the VPN company.
Then there are connection logs. These can include when you connected, when you disconnected, your original IP address, which VPN server you used, session duration, and bandwidth. Some providers use limited connection data for abuse prevention or troubleshooting. The problem is when those details can be tied back to one person.
There is also normal account data. If you pay for a service, something has to track your plan, payment status, and maybe an email address. That is not the same thing as traffic logging, but a good privacy policy should still explain it plainly.
The word "no-log" has been tested before
This is why people get picky about the details. There have been real cases where VPN providers advertised strong privacy claims, but connection records still existed and could identify a user when matched with other data.
That does not mean every VPN is lying. It means the claim needs receipts. The stronger signs are boring but useful: a policy that names specific fields, short retention periods, independent audits, transparency reports, and server architecture that avoids persistent storage where possible.
An audit is not magic either. It is a snapshot in time. But it is better than a homepage promise. If a VPN says it has been audited, look for who did the audit, what was in scope, and when it happened. A five-year-old badge with no report is not much of a receipt.
What a good no-log policy should say
A clear no-log VPN policy should answer a few basic questions without making you decode legal fog:
- Do you store browsing history or DNS requests?
- Do you store my real IP address while I am connected?
- Do you store connection timestamps or session duration?
- How long is any account or payment data retained?
- What happens if law enforcement asks for user data?
- Has anyone outside the company checked the claim?
The best answer is not always "we store absolutely nothing," because running any paid service requires some account records. The better answer is specific: no browsing history, no DNS logs, no source IP tied to sessions, no connection timestamps tied to users, and clear retention rules for the boring account stuff.
That is the standard we try to write toward at 99¢ VPN: plain claims, simple WireGuard service, and no fake mystery around what a VPN can and cannot do. If you just want a cheap VPN for everyday privacy, you can start here: $11.88/year for the Basic plan.
A no-log policy matters because your VPN provider sits in a sensitive spot. It can protect you from the network you are on, but only if it is not quietly building its own record of your activity.
So do not judge the claim by the badge. Judge it by the details. If the policy names the data fields, explains retention, and has some outside verification, that is a stronger signal. If it just says "military-grade privacy" and "we do not sell your data," that is not enough.
Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of what to look for before you trust a VPN privacy claim.