July 14, 2026 · 4 min read

No-Log VPN Policies: The Trust Test Most People Skip

“No logs” sounds simple. A VPN says it does not keep logs, you believe it, and that is the end of the story.

But the useful question is not “does this VPN say no logs?” Every VPN says some version of that now. The useful question is: what does the policy actually promise not to collect, and what does it still keep because the service needs to run?

A no-log VPN policy matters because a VPN sits in a sensitive spot. Your internet provider sees less when your VPN is on, but the VPN becomes the first hop instead. That means you are moving trust from one company to another. The privacy policy is where that trust gets tested.

Activity logs are the big one

The most important phrase to look for is activity logs. A good no-log policy should clearly say the VPN does not record the websites you visit, the pages you open, your DNS lookups, or the contents of your traffic.

If a provider only says “we protect your privacy” or “we do not monitor users,” slow down. That may be true, but it is vague. You want plain words about browsing activity.

There is also a difference between activity logs and basic account records. A paid service may keep your email address, payment status, support messages, or the date your subscription renews. That is normal. It is not the same as keeping a list of every site you visited last Tuesday.

Connection logs are where it gets blurry

Connection logs are the middle ground. These can include when you connected, how long you stayed connected, how much data you used, what server you picked, or the IP address you connected from.

Some VPNs keep none of this. Some keep a small amount temporarily to prevent abuse, fix bugs, or enforce device limits. The key is whether the policy tells you exactly what is collected and how long it is kept.

“Temporary diagnostic data deleted after 24 hours” is very different from “we may collect usage data to improve services.” One gives you a clock. The other gives the company room to stretch.

Quick check: search the VPN privacy policy for “logs,” “DNS,” “IP address,” “retention,” “diagnostic,” and “third parties.” If the answer is hard to find, that is part of the answer.

Audits help, but they are not magic

Independent audits have become common in the VPN world. That is a good thing. An outside security firm checking a no-log claim is better than a company grading its own homework.

Still, read audits with basic common sense. When was it done? What did it actually test? Did it review server configuration, apps, privacy policy language, or all of the above? A fresh audit focused on logging practices is more useful than an old badge on a pricing page.

Regulators care about this too. The FTC can go after companies for unfair or deceptive privacy claims, which includes saying one thing about data and doing another. That does not mean every VPN claim is verified by the government. It means sloppy privacy promises can become a legal problem.

The plain-English version: a good no-log VPN policy should be specific, boring, and easy to verify. It should say what is not logged, what is collected for account management, what temporary data exists, how long it is kept, and who can access it.

If a VPN hides behind broad language, that does not automatically mean it is bad. But it does mean you are being asked to trust a slogan instead of a policy.

At 99¢ VPN, the goal is simpler: keep the service lean, use WireGuard, and avoid turning privacy into a giant bundle you have to decode. If you want a basic VPN without the $10/month routine, you can start with the 99¢ VPN basic plan here.

No-log policies are not about sounding tough. They are about limiting what exists in the first place. Data that is never collected cannot be sold, leaked, subpoenaed, or quietly repurposed later.


Written by the person who runs 99¢ VPN. Not a lawyer. Just someone who thinks privacy policies should be readable before your coffee gets cold.