Skip to content
  1. Home
  2. Blog
  3. What "no logs" really means in a VPN, and how to check it

What "no logs" really means in a VPN, and how to check it

Every VPN stores something to work. "No logs" should mean no record of what you do online. How to tell the difference, and what PryVPN keeps, line by line.

PryVPN TeamPublished Updated 5 min read
Short answer

"No logs" should mean the VPN doesn't record which sites you visit, your DNS queries, your traffic or your real IP address next to that activity. Every VPN keeps something in order to work. What matters is what, in what form, for how long, and whether anyone independent has checked it.

Almost every VPN says "no logs". It's on the homepage, in the app store listing and on the ads. But a VPN can't run on nothing: it has to know which devices may connect, and it has to route your traffic. So "no logs" can mean something solid, or almost nothing. Here's how to tell.

Activity logs versus the data a VPN needs to run

It helps to split what a VPN could keep into five kinds:

Kind of record Example Does it say what you do?
Activity logs The sites you visit, your DNS queries, the content of your traffic Yes, directly
Connection logs Your real IP address, the VPN address you were given, when you connected Not on its own, but it can link you to what others logged
Account data Email address, payment details It says who you are
Operating data Your devices' keys, which server you use, how much data passes No, if it's kept briefly and apart from the rest
Statistics Daily totals with no identifiers No

The second row is the one that trips people up. A website can log "the VPN address 203.0.113.7 posted this at 14:02". If the VPN keeps "the customer at home address X had 203.0.113.7 at 14:02", the two logs together point to a person. A "no logs" promise that keeps connection logs is a weak one.

A strong no-logs service keeps no activity logs, no connection logs that link your real address to your activity, as little account data as possible, and operating data only as long as it's needed.

Five ways to check any provider

You don't have to take anyone's word for it, ours included. These five checks work on any VPN:

  1. A policy with a list, not a slogan. Look for a table of what is stored, in what form and for how long. "We may collect information to improve our services" is not an answer.
  2. An independent audit. Who did it, when, what it covered (the servers, the apps, or only a policy), and whether the report is public. An audit is a snapshot of one moment, not a permanent seal.
  3. What happened when someone asked. Transparency reports that count requests from authorities, and public cases where a provider had nothing to hand over, are the closest thing to a real-world test.
  4. The design. Some choices make logging hard in the first place: resolvers that answer lookups in memory, identifiers stored only as hashes, email addresses encrypted and passwords kept only as one-way hashes, short retention periods by default.
  5. The business model. Running servers costs money. If a free VPN doesn't say who pays, the answer may be you, through ads, trackers or data. Privacy Guides, a community project, publishes criteria along these lines.

Red flags

  • "No logs" with no list of what is kept.
  • Vague permissions in the policy ("for analytics", "for partners").
  • Advertising or analytics SDKs inside the app.
  • No way to tell which company runs the service, or from where.
  • Words like "untraceable" or "military-grade". Nobody can promise the first, and the second means nothing.

Our case: what PryVPN keeps, line by line

We'd be asking you to apply those checks to others and not to us, so here's our own list. It matches our privacy policy, which is the reference.

What we never record: the sites and apps you use, your DNS queries (our resolvers answer them in memory and keep only totals that point to no one), the content of your traffic, your original IP address linked to your activity, and the times you reached any site.

What we do keep:

What In what form For how long
Your account Your email address, encrypted, and your password only as a one-way hash (Argon2id); with Google, a keyed hash of your Google account's ID Until you delete the account
Your devices The WireGuard public key, platform, app version, and the days they were added and last used Deleted after 90 days unused
Which server holds each device's key Device, server and day Removed after 24 hours unused
Your active session Server, public key, start time rounded to the hour, bytes sent and received Only while you're connected
Security events, such as failed sign-ins Type, time and a daily-salted hash of the IP address 24 hours
Service logs Route, result and timing, with no IP address (only a short daily-salted hash) 14 days
Backups A full daily copy of the database 14 days on the server; encrypted offline copies, up to 30

To stop spam and attacks without watching anyone, our servers count behavior, such as how fast a device opens new connections, in the memory of the server for up to a minute. Those counters never include where the connections go. Email is optional, and statistics from the app are off unless you turn them on.

What this means in practice: if someone asks who used a PryVPN address at a given time, we can't tell them, because that link doesn't exist. We count every such request in our transparency report.

What we don't have yet

Checks 2 and 3 are the hard ones for a new service, so here is where we stand:

  • No independent audit yet. Until there is one, what you can check is what we publish: the full storage table in the privacy policy, and the transparency report.
  • Our privacy policy is a beta draft. It explains our practices in plain language and will be reviewed by counsel before PryVPN launches publicly.
  • Our company details are still to be published in the legal notice, before launch.
  • PryVPN doesn't make you invisible. Sites you sign in to know it's you, and your device can still be recognized in other ways.

We think saying this plainly is part of what "no logs" should mean. For the product view of the same list, see our no-logs VPN page.

Sources

  1. Privacy Guides: VPN recommendations and criteria
  2. General Data Protection Regulation (EU) 2016/679, article 5: data minimisation and storage limitation

Spotted a mistake? Write to support@pryvpn.com and we'll fix it and update the date.

About the author

PryVPN Team

The people who build PryVPN's Android app, servers and network. We check every claim about PryVPN against our privacy policy before publishing.

How we write
Join the beta

Try PryVPN during the beta

Free, no card, no activity logs. Join the beta and we'll email you when there's room; PryVPN installs from Google Play.

Join the beta