“No logs” is not a standardized certification. One provider may mean it does not record browsing activity; another may still retain connection timestamps, bandwidth totals, device identifiers, crash data, or account information. Evaluate the exact policy and audit scope instead of treating a badge or a fixed “top five” list as proof.
What to look for in the policy
Read the provider’s current privacy policy and answer these questions:
- Does it collect source IP addresses, assigned VPN IPs, DNS requests, URLs, timestamps, session duration, or bandwidth?
- What account, payment, device, crash, and support data is retained?
- Are aggregated server-health statistics separated from user activity?
- What third parties process data, and how long is it retained?
- What happens when the provider receives a legal request?
Mullvad’s no-logging policy is a useful example because it lists both activity data it says it does not log and limited server-health statistics it does collect. That specificity is more valuable than the words “zero logs” alone.
Audits are evidence, not a lifetime guarantee
Prefer a dated, public independent audit that identifies the systems tested, evidence reviewed, limitations, and remediation status. An infrastructure audit may not cover the mobile app, website, payment system, or support platform. Recheck the date when a provider changes ownership, architecture, or product.
Technical designs such as diskless or RAM-only infrastructure can reduce persistent storage, but they do not prove that every component is ephemeral or that the provider collects no metadata elsewhere. Treat architecture claims and policy claims as separate evidence.
Jurisdiction and real-world events
The provider’s legal entity and operating locations affect what it may be required to do, but country labels alone do not determine privacy. A provider with minimal collection and a strong audit may present less data to disclose than one with a favorable jurisdiction but extensive telemetry. Read the legal-request policy and incident history, not just a “Five Eyes” marketing chart.
A repeatable comparison method
- Save the current privacy policy, audit report, and publication date.
- Record exactly what the provider says it collects and retains.
- Check whether the audit’s scope matches the app and plan you would use.
- Review account creation, payment, support, and crash-report settings separately.
- Test DNS-leak, kill-switch, and reconnect behavior on your device.
- Recheck the policy after major product or ownership changes.
Frequently asked questions
Does RAM-only mean a VPN cannot log me?
No. It may reduce persistent server storage, but logs can be generated elsewhere and metadata may be collected by apps, websites, account systems, or support tools.
Which VPN has the best no-logs policy?
There is no permanent universal winner. Choose the provider with the clearest current policy, relevant independent evidence, narrow data collection, and an architecture you understand.
Can I verify a no-logs claim myself?
You can test app behavior, DNS leaks, and published documentation, but you cannot independently prove what a remote provider stores internally. That is why audit scope and transparency matter.
The bottom line
Sources and verification notes
- Mullvad: No-logging data policy — an example of a provider specifying activity data versus limited operational data.
- NIST VPN glossary — what a VPN tunnel provides and what it does not prove about provider-side data retention.
Judge no-logs claims by specificity, scope, date, and independent evidence. Keep a copy of the policy you relied on, minimize the personal data in the account, and remember that a VPN cannot protect credentials you voluntarily give to a phishing site or insecure app.
