PC Privacy Software All Articles
VPN Reviews

No-Log VPNs Under the Microscope: Separating Verified Privacy From Empty Promises

By PC Privacy Software VPN Reviews
No-Log VPNs Under the Microscope: Separating Verified Privacy From Empty Promises

The phrase "no-log VPN" has become one of the most overused terms in digital privacy marketing. Nearly every VPN provider operating in the United States today includes some variation of it in their promotional materials. The problem is that the phrase means very different things depending on who is saying it — and for users who rely on a VPN for genuine protection, those differences are not trivial.

This investigation cuts through the promotional noise. By examining published privacy policies, the scope and credibility of third-party audits, and documented cases where law enforcement requests forced providers to produce data, we have assembled a clearer picture of which VPN services have earned their no-log reputation and which ones have not.

Why "No-Log" Claims Are So Easy to Make

There is no regulatory body in the United States that enforces VPN privacy claims. Any company can write "we never store your data" in a terms-of-service document without facing any immediate legal consequence for doing so. This creates a straightforward incentive problem: the marketing benefit of claiming a no-log policy is significant, while the cost of making that claim — absent any verification requirement — is essentially zero.

This does not mean all such claims are false. It does mean that users should require evidence before trusting them.

The evidence that actually matters falls into three categories: the specificity of the privacy policy itself, the credentials and methodology of any third-party auditor, and the provider's historical record when subpoenas or court orders have been involved.

Reading a Privacy Policy Like an Investigator

A meaningful no-log policy will specify exactly what categories of data are not retained. Connection timestamps, originating IP addresses, DNS query records, bandwidth consumption data, and session duration are all distinct data types — and a policy that vaguely promises "we don't log your activity" may still retain several of them.

ExpressVPN's privacy policy, for example, distinguishes between activity logs (which it states are never collected) and minimal connection metadata, explaining precisely which aggregated statistics are retained for network performance purposes and why individual users cannot be identified from them. That level of specificity is meaningful. A policy that simply states "we have a strict no-log policy" without elaboration is not.

Users evaluating any VPN should look for explicit enumeration of what is and is not stored. Vague language is not a privacy guarantee — it is a liability shield.

The Third-Party Audit Standard

Independent audits have become the primary credibility mechanism in the VPN industry, but the term "independent audit" covers a wide range of rigor. An audit conducted by a reputable cybersecurity firm that examines server configurations, data retention systems, and internal logging infrastructure is categorically different from a document review that simply confirms a privacy policy says what the provider claims it says.

Several providers have pursued credible audits worth examining:

Mullvad VPN has undergone infrastructure audits by Cure53, a German cybersecurity firm with an established reputation in the security research community. Cure53's methodology involves direct access to server environments, not just policy documentation.

ProtonVPN has also commissioned Cure53 audits and makes the full reports publicly available — a transparency practice that significantly increases their credibility. Providers who commission audits but decline to publish the results offer considerably weaker assurance.

NordVPN engaged PricewaterhouseCoopers to conduct a no-log audit, though critics have noted that PwC's methodology focused primarily on policy compliance rather than deep technical infrastructure review. NordVPN later contracted Deloitte for a subsequent audit with a broader technical scope.

IPVanish, by contrast, has not published a comprehensive third-party infrastructure audit as of this writing — a notable gap for a provider that markets itself aggressively to privacy-conscious American users.

When evaluating audit credibility, ask three questions: Who conducted it? Did the auditor have direct server access? Is the full report publicly available?

When the Courts Got Involved

The most unambiguous test of a no-log policy is a government subpoena. A provider that genuinely retains no identifiable user data cannot produce records it does not have. Providers that have been compelled to produce data — or that have cooperated voluntarily — reveal the gap between their marketing and their actual infrastructure.

IPVanish's 2016 incident remains one of the most cited examples in this space. Despite advertising a strict no-log policy at the time, the company provided the Department of Homeland Security with detailed connection logs — including timestamps, IP addresses, and session data — that were used in a federal investigation. The company has since changed ownership and claims to have restructured its data practices, but the incident established a baseline skepticism that its current marketing has not fully overcome through audited verification.

PureVPN faced a similar situation in 2017, when it provided the FBI with user connection data that contributed to a cyberstalking prosecution. The company's defense was that the data it provided was limited and consistent with its policy — a claim that privacy researchers disputed after reviewing the court documents.

Contrast these cases with Mullvad's response to a 2023 police raid on its servers in Sweden. Law enforcement arrived with a court order, seized hardware, and left with nothing useful — because the servers contained no logs that could identify individual users. That outcome is what a genuine no-log architecture looks like under real-world pressure.

Jurisdiction Still Matters

For American users, it is worth noting that VPN jurisdiction influences legal exposure. Providers headquartered in the United States are subject to National Security Letters, which can compel data disclosure without judicial oversight and include gag orders preventing the provider from disclosing the request. Providers in countries without intelligence-sharing agreements with the US — Switzerland, Iceland, Panama, and the British Virgin Islands are frequently cited — face a different legal environment.

Jurisdiction alone does not make a VPN trustworthy. A provider based abroad with weak technical infrastructure is not more secure than a US-based provider with a rigorous no-log architecture. But it is a relevant factor in a complete risk assessment.

A Framework for Making Your Decision

Rather than ranking providers by name, the more durable approach is to evaluate any VPN against a consistent set of criteria:

  1. Policy specificity: Does the privacy policy enumerate exactly which data types are and are not retained?
  2. Audit quality: Has a reputable cybersecurity firm conducted an infrastructure-level audit, and is the full report published?
  3. Legal track record: Has the provider ever produced user data in response to legal requests? If so, what was the nature of that data?
  4. Ownership transparency: Is the parent company publicly known, and does it have any history of data monetization in adjacent businesses?
  5. Jurisdiction: Where is the provider legally domiciled, and what does that mean for US-directed legal requests?

No VPN is perfect, and no audit covers every possible failure mode. But providers who score well across all five dimensions have earned a meaningfully higher level of trust than those who rely on marketing language alone. In the context of digital privacy, that distinction is worth taking seriously.