"No logs" should mean the VPN doesn't record which sites you visit, your DNS queries, your traffic or your real IP address next to that activity. Every VPN keeps something in order to work. What matters is what, in what form, for how long, and whether anyone independent has checked it.
Almost every VPN says "no logs". It's on the homepage, in the app store listing and on the ads. But a VPN can't run on nothing: it has to know which devices may connect, and it has to route your traffic. So "no logs" can mean something solid, or almost nothing. Here's how to tell.
Activity logs versus the data a VPN needs to run
It helps to split what a VPN could keep into five kinds:
| Kind of record | Example | Does it say what you do? |
|---|---|---|
| Activity logs | The sites you visit, your DNS queries, the content of your traffic | Yes, directly |
| Connection logs | Your real IP address, the VPN address you were given, when you connected | Not on its own, but it can link you to what others logged |
| Account data | Email address, payment details | It says who you are |
| Operating data | Your devices' keys, which server you use, how much data passes | No, if it's kept briefly and apart from the rest |
| Statistics | Daily totals with no identifiers | No |
The second row is the one that trips people up. A website can log "the VPN address 203.0.113.7 posted this at 14:02". If the VPN keeps "the customer at home address X had 203.0.113.7 at 14:02", the two logs together point to a person. A "no logs" promise that keeps connection logs is a weak one.
A strong no-logs service keeps no activity logs, no connection logs that link your real address to your activity, as little account data as possible, and operating data only as long as it's needed.
Five ways to check any provider
You don't have to take anyone's word for it, ours included. These five checks work on any VPN:
- A policy with a list, not a slogan. Look for a table of what is stored, in what form and for how long. "We may collect information to improve our services" is not an answer.
- An independent audit. Who did it, when, what it covered (the servers, the apps, or only a policy), and whether the report is public. An audit is a snapshot of one moment, not a permanent seal.
- What happened when someone asked. Transparency reports that count requests from authorities, and public cases where a provider had nothing to hand over, are the closest thing to a real-world test.
- The design. Some choices make logging hard in the first place: resolvers that answer lookups in memory, identifiers stored only as hashes, email addresses encrypted and passwords kept only as one-way hashes, short retention periods by default.
- The business model. Running servers costs money. If a free VPN doesn't say who pays, the answer may be you, through ads, trackers or data. Privacy Guides, a community project, publishes criteria along these lines.
Red flags
- "No logs" with no list of what is kept.
- Vague permissions in the policy ("for analytics", "for partners").
- Advertising or analytics SDKs inside the app.
- No way to tell which company runs the service, or from where.
- Words like "untraceable" or "military-grade". Nobody can promise the first, and the second means nothing.
Our case: what PryVPN keeps, line by line
We'd be asking you to apply those checks to others and not to us, so here's our own list. It matches our privacy policy, which is the reference.
What we never record: the sites and apps you use, your DNS queries (our resolvers answer them in memory and keep only totals that point to no one), the content of your traffic, your original IP address linked to your activity, and the times you reached any site.
What we do keep:
| What | In what form | For how long |
|---|---|---|
| Your account | Your email address, encrypted, and your password only as a one-way hash (Argon2id); with Google, a keyed hash of your Google account's ID | Until you delete the account |
| Your devices | The WireGuard public key, platform, app version, and the days they were added and last used | Deleted after 90 days unused |
| Which server holds each device's key | Device, server and day | Removed after 24 hours unused |
| Your active session | Server, public key, start time rounded to the hour, bytes sent and received | Only while you're connected |
| Security events, such as failed sign-ins | Type, time and a daily-salted hash of the IP address | 24 hours |
| Service logs | Route, result and timing, with no IP address (only a short daily-salted hash) | 14 days |
| Backups | A full daily copy of the database | 14 days on the server; encrypted offline copies, up to 30 |
To stop spam and attacks without watching anyone, our servers count behavior, such as how fast a device opens new connections, in the memory of the server for up to a minute. Those counters never include where the connections go. Email is optional, and statistics from the app are off unless you turn them on.
What this means in practice: if someone asks who used a PryVPN address at a given time, we can't tell them, because that link doesn't exist. We count every such request in our transparency report.
What we don't have yet
Checks 2 and 3 are the hard ones for a new service, so here is where we stand:
- No independent audit yet. Until there is one, what you can check is what we publish: the full storage table in the privacy policy, and the transparency report.
- Our privacy policy is a beta draft. It explains our practices in plain language and will be reviewed by counsel before PryVPN launches publicly.
- Our company details are still to be published in the legal notice, before launch.
- PryVPN doesn't make you invisible. Sites you sign in to know it's you, and your device can still be recognized in other ways.
We think saying this plainly is part of what "no logs" should mean. For the product view of the same list, see our no-logs VPN page.
Sources
Spotted a mistake? Write to support@pryvpn.com and we'll fix it and update the date.