← Blog Blog

No-Logs VPN Explained: What It Actually Means in 2026

September 1, 2026

In 2018, US federal investigators subpoenaed Private Internet Access for records tied to a criminal case. The company had nothing to hand over — not because it refused, but because the data never existed. That gap between what a VPN claims and what it can actually produce under pressure is exactly what “no-logs” is supposed to close.

What “no-logs” actually means

“No-logs” gets used as a catch-all marketing term, but a strict policy only counts if it excludes specific categories of data. A provider can call itself “no-logs” while still storing plenty — the difference is in the details.

A genuinely strict no-logs policy does not store:

  • Your IP address — neither the one you connect from nor the one assigned to you on the VPN server.
  • Connection timestamps — when you connected, when you disconnected, and for how long.
  • DNS queries — which domains your device resolved while connected.
  • Traffic content or browsing history — the sites, apps, or files behind the encrypted tunnel.
  • Bandwidth tied to your identity — aggregate, anonymized network load is fine; a log linking gigabytes to your account is not.

What most providers still keep, no-logs or not, is an email address or payment reference for the account itself — that’s billing, not activity tracking, and it’s a reasonable trade-off for running a subscription service.

How the claim actually gets tested

Anyone can write “we don’t log” on a pricing page. What separates a real policy from a slogan is whether it’s been checked by someone with no reason to be generous.

  1. Independent audit. A third-party security firm gets direct access to server infrastructure and source code, checks for any logging code path, and publishes a public report — Proton VPN, for example, passed its fifth annual external no-logs audit in 2026.
  2. Architecture review. Auditors confirm servers run RAM-only (diskless), so there’s no persistent storage layer for logs to survive a reboot on in the first place.
  3. Adversarial pressure. The strongest evidence isn’t an audit at all — it’s what happens when a government demands data. Private Internet Access was subpoenaed by the FBI in 2016 and again in 2018 for user records tied to separate investigations; in both cases it had nothing to produce. Mullvad’s Swedish offices were raided by police with a search warrant, and no customer data existed to seize. In February 2026, Windscribe reported that Dutch authorities seized one of its RAM-disk servers and recovered no user data from it.

A no-logs claim that has never faced a subpoena or a server seizure is still just a sentence on a website. The providers worth trusting are the ones with a paper trail proving the sentence held up.

RAM-only servers: architecture beats promises

A written policy is a promise about behavior. RAM-only infrastructure is a hardware guarantee — there’s no disk for logs to land on even if something went wrong.

Disk-based serverRAM-only server
Data after a rebootCan persist on diskWiped instantly
Forensic recovery if seizedPossible via disk imagingNothing to image
Depends onCorrect manual log deletionPhysical hardware design

RAM-only doesn’t replace an audited policy and a jurisdiction without mandatory data-retention laws — it removes one entire failure mode underneath them.

What a no-logs VPN can (and can’t) see

A strict no-logs policy means the provider doesn’t record your traffic — it doesn’t mean the traffic never passes through their infrastructure. Every VPN routes your connection in real time; “no-logs” is a promise about what happens to that data afterward, not about invisibility.

Without VPN Your device ISP sees & stores Website

With RunVPN Your device Encrypted, no logs Website

Without a VPN, your ISP sees and can store everything you do. With a no-logs VPN, the tunnel is encrypted and nothing is stored on the other end.

Without a VPN, your internet provider sits in the middle of every connection and, in many jurisdictions, can log it by default. With a no-logs VPN, that visibility moves to a provider whose entire technical and legal design is built around not keeping a record of it.

How RunVPN handles this

RunVPN runs on a no-logs policy and routes traffic through AmneziaWG by default, with VLESS-Reality (XTLS-Vision) on the Xray engine as the alternative protocol — both tuned for speed and resistant to deep packet inspection, which keeps the connection stable on networks that interfere with standard VPN traffic.

Getting connected doesn’t involve any manual setup:

  • Download the app and sign in with Google, email, or Telegram.
  • The app fetches its configuration automatically — no config files, no QR codes, no pasting connection strings.
  • Tap the connect button.

RunVPN currently runs on Android, with iOS and desktop coming soon. One account covers up to five devices.

FAQ

Does no-logs mean the VPN can’t see my traffic at all? No. The provider’s servers still route your connection in real time — a strict no-logs policy means that routing isn’t recorded, not that it’s invisible to the infrastructure itself.

Why have some “no-logs” VPNs been caught storing data anyway? A couple of providers that advertised no-logs policies did hand over user logs when compelled by courts — both have since changed ownership. It’s why audits, RAM-only architecture, and real legal test cases matter more than the phrase on the homepage.

Does RAM-only automatically mean no-logs? Not by itself. RAM-only removes the disk as a place logs could survive, but a provider could still log to a remote system. It has to be paired with an audited policy.

Do I need to configure anything for RunVPN to run no-logs? No — the policy applies to how RunVPN operates its servers, not to anything you set up. Sign in and connect.

Get RunVPN and connect through AmneziaWG or VLESS-Reality — learn more about AmneziaWG, VLESS-Reality, or read RunVPN’s privacy commitments.