July 9, 2026 · 4 min read

No-Log VPN Policies: What a Good One Actually Says

"No logs" sounds simple. A VPN either keeps logs or it does not, right?

Not quite. In VPN land, no-log policy can mean a few different things. Some providers mean they do not log the websites you visit. Some mean they do not keep your original IP address. Some still keep connection timestamps, device IDs, bandwidth totals, payment records, support emails, or abuse-prevention data.

That does not automatically make them shady. A VPN is still a business. It may need account records, billing records, and enough technical data to keep the service from being abused. The real issue is whether the policy says that clearly.

Activity logs are the big red line

The most important phrase to look for is activity logs. That means records of what you do online through the VPN: websites visited, DNS queries, search terms, app traffic, downloaded files, or content viewed.

A good no-log VPN policy should say it does not collect browsing activity, DNS history, or traffic contents. Plain language is better than fancy privacy wording. If the page says "we respect your privacy" ten times but never says what it stores, that is not very useful.

The FTC has warned consumers that a VPN shifts trust. Your coffee shop, hotel, or ISP sees less, but the VPN provider becomes the company carrying your traffic. That is why the logging policy matters so much. You are not deleting trust. You are moving it.

Quick test: Search the VPN privacy policy for "logs," "DNS," "IP address," "retention," and "share." If those words are missing or vague, keep reading before you trust the claim.

Connection logs are where the fine print lives

Connection logs are different from activity logs. They can include when you connected, how long the session lasted, how much data moved, which server you used, or what IP address you connected from.

Some VPNs keep no connection metadata at all. Some keep limited operational data for a short time. Some keep more than you would expect. The policy should answer three plain questions:

Retention is the word people skip. A provider that stores limited diagnostic data for 24 hours is very different from one that stores connection records for six months. Both may still use privacy-friendly language on the homepage.

Audits help, but they are not magic

Third-party audits are useful. They give someone outside the company a chance to check whether the infrastructure matches the promise. That is better than asking you to trust a slogan.

But audits are snapshots. Read what was audited, when it happened, and whether the report is public. An audit of one server setup from three years ago is not the same thing as regular checks of the current service.

The best policy is boring in a good way. It says what is not logged, what is logged, why it is logged, how long it stays, and what happens when legal requests arrive.

At 99¢ VPN, the goal is simple privacy without the word games. If you want a cheap WireGuard VPN for everyday browsing, travel, and public WiFi, you can get one device for $11.88/year here.

Bottom line: do not trust the phrase "no logs" by itself. Trust the details underneath it.


Written by the person who runs 99¢ VPN. Not legal advice. Just a practical way to read VPN privacy claims without getting lost.