August 6, 2026 · 4 min read

No-Log VPN Policies: Ask What Still Gets Stored

"No logs" is one of those VPN phrases that sounds cleaner than it really is.

Most people hear it and think: good, nothing about me exists anywhere. But a VPN still has to run a service. It may need billing records, support emails, abuse prevention, server health data, or bandwidth totals. The real question is not whether the provider uses the words "no logs." The real question is what data is still stored, for how long, and whether it can be tied back to you.

That is the part worth checking before you trust any VPN with your traffic.

Activity logs are the scary ones

An activity log is a record of what you did online. Websites visited. DNS requests. Apps used. Files downloaded. Search queries. Anything that turns a VPN from a privacy tool into a browsing-history warehouse.

A good no-log VPN policy should clearly say it does not store activity logs. Not in vague language. Not "we respect your privacy." It should say no browsing history, no DNS query history, and no records of the sites or services you access through the VPN.

This matters because your VPN sits in a sensitive spot. Without a VPN, your ISP can see parts of your network activity, especially domains and metadata. With a VPN, you move that trust from the ISP to the VPN provider. If the VPN logs your activity, you did not remove the privacy problem. You just changed who has the notebook.

Connection logs are where the fine print hides

Connection logs sound less dramatic, but they can still matter. These are things like your real IP address, the VPN server you connected to, timestamps, session duration, and sometimes bandwidth used.

Some connection data is harmless when it is aggregated. For example, a provider may need to know that a server is overloaded. But if a provider stores your real IP address plus exact connection times, that can become identifying information. Match those timestamps with a website's logs and suddenly the "no activity logs" promise is less comforting.

Fast privacy-policy check: search the page for "IP address," "DNS," "timestamp," "connection," "retain," and "share." If the policy only says "no logs" but never explains those words, slow down.

The best policies are specific. They separate activity logs from connection logs. They explain what account data exists. They say how long anything is kept. They do not make you decode five pages of legal fog to understand the basic deal.

Audits help, but they are not magic

Independent audits are useful because anyone can write a privacy promise. A third-party review can check whether the technical setup matches the marketing. Some providers also use RAM-only servers, which means server data is not written to a hard drive and disappears when the machine restarts.

Those are good signs. They are not a free pass. An audit from five years ago is less useful than a recent one. A policy review is not the same as a live infrastructure review. And RAM-only servers do not answer every question about billing records, support tickets, or company-level data sharing.

So read no-log claims like you would read a nutrition label. Ignore the giant promise on the front. Look at the details on the back.

The bottom line

A no-log policy matters because it tells you whether your VPN can become a record of your private life. But the phrase only earns trust when it is specific.

Look for no activity logs, no DNS logs, no source IP tied to sessions, short retention, clear account-data rules, and recent independent verification. If the policy says all that in plain English, that is a good sign. If it hides behind slogans, keep looking.

If you want a simple WireGuard VPN without the usual inflated pricing, 99¢ VPN Basic is $11.88/year. It is built for normal people who want encrypted traffic without another expensive subscription.


Written by the person who runs 99¢ VPN. Not a lawyer. Not a compliance auditor. Just someone who thinks privacy promises should be readable.