No-Log VPN Policies: What They Really Mean
“No logs” sounds simple. A VPN says it does not keep records, so you assume there is nothing to hand over, sell, leak, or misuse.
The real answer is a little more boring, which is usually where the truth lives. A no-log VPN policy should mean the provider does not store records that connect you to what you did online. Not your browsing history. Not the websites you visited. Not your DNS lookups. Not a neat little timeline that says your home IP opened this app at 9:42 p.m.
That is the promise. The details are where you need to pay attention.
There are different kinds of logs
When people hear “logs,” they usually think of browsing history. That is the big one, but it is not the only one.
- Activity logs are the dangerous kind. These can include websites visited, apps used, DNS requests, destination IP addresses, or files accessed.
- Connection logs are more about the VPN session itself. These might include when you connected, how long you stayed connected, how much data you used, or which VPN server you picked.
- Account and billing records are normal for any paid service. Your email address, payment status, and support tickets are not the same thing as your browsing history.
A good no-log policy is clear about the difference. A vague one says “we value your privacy” six times and never tells you what is actually stored.
What a no-log policy should say plainly
Look for direct language. The strongest policies say they do not collect or store activity data that can identify a user or link a person to online activity. Recent third-party no-log audits from VPN providers often focus on exactly that: whether the service stores user IP addresses, destination IPs, browsing activity, DNS traffic, or user-attributable connection metadata.
The FTC has also warned that internet providers can collect huge amounts of personal data, including browsing data, and that users often have limited control over it. That is why the first hop matters. If your ISP can see your traffic patterns, that data can become part of a bigger profile. A VPN moves that first hop away from the ISP, but then you have to trust the VPN instead.
Audits help, but they are not magic
Independent audits are useful. They force a VPN company to let outside security or accounting firms inspect whether the no-log claim matches the actual systems. That is better than a slogan on a pricing page.
But audits are still snapshots. They cover a certain product, scope, and time period. They do not mean “trust forever.” They mean “someone checked this claim under these conditions.” That is good evidence, not a lifetime guarantee.
You should also be realistic about what a VPN can promise. A VPN cannot make you anonymous everywhere online. If you log into Gmail, Google knows it is you. If you post under your real name, the VPN does not erase that. A VPN mainly protects the network layer: your ISP, hotel WiFi, airport WiFi, and random people on the same network do not get a clean view of your browsing.
That is still useful. It is just not magic.
If you want a simple VPN without the inflated bundle pricing, 99¢ VPN gives you WireGuard for one device at $11.88/year. No complicated plans. No pretending a VPN solves every privacy problem. Just an encrypted tunnel so your network is not watching every move.
The bottom line: “no logs” should mean no records that tie you to your activity. If a VPN cannot explain that in plain English, keep looking.
Written by the person who runs 99¢ VPN. Not a lawyer. Just someone who thinks privacy policies should be readable by normal people.