What a No-Log VPN Policy Really Means
"No logs" is one of those VPN phrases that sounds simple until you read the privacy policy. Then it gets slippery.
A good no-log VPN policy should mean the provider is not saving the stuff that ties your internet activity back to you: browsing history, DNS requests, source IP address, destination sites, or timestamps detailed enough to reconstruct what you did later.
That does not mean the company has zero data about you. It may still need your email address, payment status, support messages, and basic account records. The real question is whether it keeps network activity logs that can identify your browsing.
Activity logs are the big red flag
There are two buckets to care about.
Activity logs are the bad ones for privacy. These can include websites visited, DNS queries, app traffic, files downloaded, or anything else that describes what you did online.
Connection logs sound harmless, but they can still matter. If a VPN saves your real IP address, the VPN IP you used, and exact connect and disconnect times, that can sometimes be enough to connect dots.
Some providers keep aggregate data, like total bandwidth used across a server, crash reports, or server load. That is different from saving "Beno connected from this home IP at 8:04 and visited these domains." The privacy policy should make that difference obvious.
Audits help, but they are not magic
Independent audits are useful because they force a VPN company to let outsiders inspect whether the server setup matches the marketing claim. Some big providers now publish repeated no-log audits, and that is better than "trust us" written in a landing page headline.
But an audit is still a snapshot. It usually checks a specific system, during a specific window, against a specific policy. It does not guarantee the company will never change its infrastructure, sell to a new owner, or quietly rewrite its terms.
That is why I look for three things together: a specific no-log policy, a simple architecture that avoids collecting sensitive data in the first place, and a public habit of transparency when things change.
What a good policy says plainly
A readable no-log VPN policy should say what it does not store in normal words. No browsing history. No DNS request logs. No source IP tied to activity. No connection timestamps that can identify a session after the fact.
It should also say what it does store. Account email. Billing status. Support tickets if you write in. Maybe temporary operational metrics that are not tied to your identity. That honesty is a good sign, not a bad one.
The shady version is a policy that says "we respect your privacy" ten times but never answers the boring questions. Boring questions are the whole point.
If you want a simple VPN that keeps the promise boring too, 99¢ VPN is $11.88/year for one WireGuard device. The goal is not to bury you in buzzwords. It is to give you an encrypted tunnel without turning privacy into a luxury subscription.
Bottom line: "no logs" is not a magic spell. It is a checklist. Read what is collected, what is not collected, how long anything is kept, and whether the company says it clearly enough that a normal person can understand it.
Written by the person who runs 99¢ VPN. Not a lawyer. Just someone who thinks privacy policies should not require a weekend.