August 10, 2026 · 4 min read

No-Log VPN Policies Are About Details, Not Vibes

"No logs" sounds simple. You use a VPN. The VPN does not save what you do. End of story.

The annoying part is that the phrase gets used for a lot of different things. One VPN might mean it does not save your browsing history. Another might mean it does not save DNS requests. Another might still keep connection timestamps, your real IP address, the VPN server you used, and how long you stayed connected.

That difference matters. A VPN no-log policy is not useful because the words sound private. It is useful when it clearly says which data is not collected, which data still exists, and how long anything is kept.

There are different kinds of VPN logs

The big one is activity logs. That means the websites you visit, searches you make, apps you use, files you download, or DNS requests your device sends. A privacy-focused VPN should not keep those. If it does, you have mostly moved trust from your internet provider to the VPN company.

Then there are connection logs. These can include when you connected, when you disconnected, your original IP address, which VPN server you used, session duration, and bandwidth. Some providers use limited connection data for abuse prevention or troubleshooting. The problem is when those details can be tied back to one person.

There is also normal account data. If you pay for a service, something has to track your plan, payment status, and maybe an email address. That is not the same thing as traffic logging, but a good privacy policy should still explain it plainly.

Quick check: Search the privacy policy for "IP address," "DNS," "timestamp," "connection logs," "retention," and "share." If the policy only says "we do not sell your data," keep reading. That sentence does not tell you what is collected.

The word "no-log" has been tested before

This is why people get picky about the details. There have been real cases where VPN providers advertised strong privacy claims, but connection records still existed and could identify a user when matched with other data.

That does not mean every VPN is lying. It means the claim needs receipts. The stronger signs are boring but useful: a policy that names specific fields, short retention periods, independent audits, transparency reports, and server architecture that avoids persistent storage where possible.

An audit is not magic either. It is a snapshot in time. But it is better than a homepage promise. If a VPN says it has been audited, look for who did the audit, what was in scope, and when it happened. A five-year-old badge with no report is not much of a receipt.

What a good no-log policy should say

A clear no-log VPN policy should answer a few basic questions without making you decode legal fog:

The best answer is not always "we store absolutely nothing," because running any paid service requires some account records. The better answer is specific: no browsing history, no DNS logs, no source IP tied to sessions, no connection timestamps tied to users, and clear retention rules for the boring account stuff.

That is the standard we try to write toward at 99¢ VPN: plain claims, simple WireGuard service, and no fake mystery around what a VPN can and cannot do. If you just want a cheap VPN for everyday privacy, you can start here: $11.88/year for the Basic plan.

A no-log policy matters because your VPN provider sits in a sensitive spot. It can protect you from the network you are on, but only if it is not quietly building its own record of your activity.

So do not judge the claim by the badge. Judge it by the details. If the policy names the data fields, explains retention, and has some outside verification, that is a stronger signal. If it just says "military-grade privacy" and "we do not sell your data," that is not enough.


Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of what to look for before you trust a VPN privacy claim.