← Blog Blog

What Is a No-Logs VPN, Really? A Plain-English Breakdown

July 2, 2026

In 2018, a VPN provider marketing a “strict zero-logs policy” handed the U.S. Department of Homeland Security a user’s name, email address, home IP, and connection timestamps — the exact records it had told customers it never kept. The provider was IPVanish. The case is now the standard warning cited whenever someone asks what a no-logs policy is actually worth.

That gap between the marketing page and what a company can produce under a subpoena is the whole story of “no logs.” The phrase gets printed on every VPN homepage, but it has no single legal definition, and providers use it to mean very different things.

What “no logs” actually means

A genuine no-logs policy means the provider retains nothing that could tie a specific person to specific online activity at a specific moment in time. In practice, that claim covers several distinct categories of data, and a policy can be strict about some while staying vague about others.

  • Connection logs — timestamps of when you connected and disconnected, and for how long.
  • Source IP address — the IP your device actually used to reach the VPN server.
  • Destination data — which sites, servers, or services your traffic went to.
  • DNS queries — the domain lookups that reveal browsing activity even when the content itself is encrypted.
  • Bandwidth and session metadata — how much data moved, sometimes kept in aggregate for capacity planning without being tied to an individual account.

A strict no-logs policy excludes the first four entirely. Some providers still retain aggregate, anonymized bandwidth figures to manage server load — that’s a reasonable operational exception, not a privacy failure, as long as it can’t be traced back to one user’s activity.

The logs that matter most — and the ones that don’t

Not every category of data carries the same risk. This is roughly how they stack up:

Data typeWhat it revealsKept by a strict no-logs VPN?
Connection timestampsWhen you were online and for how longNo
Source/destination IPYour real location + sites/services you reachedNo
DNS queriesEvery domain you looked upNo
Aggregate bandwidth (anonymized)Server load, capacity trendsSometimes, without user linkage
Account email / payment methodWho’s paying, for support and billingYes — this isn’t a privacy leak by itself

The last row matters: even a genuinely no-logs VPN has to know who’s paying for the subscription. The privacy promise is about activity data, not about whether an account exists at all.

How real policies get tested — audits and court cases

Independent audits have become common among established VPN providers, with firms like Cure53, Deloitte, PwC, and KPMG publishing reviews of provider infrastructure and app source code. These audits generally fall into two types: operational attestations, where auditors sample live servers and configuration to confirm no logging code is running, and deep technical audits that also review the app codebase for hidden telemetry.

An audit is a snapshot, not a guarantee. It confirms the systems examined on that date weren’t logging — a code change, new SDK, or added feature the following month isn’t automatically covered by last year’s report.

The more convincing evidence tends to come from real-world tests, not marketing claims:

  1. Private Internet Access, 2016 and 2018 — subpoenaed twice by U.S. investigators in separate cases. Both times, the company could only hand over a general geographic cluster of IP addresses, because no per-user connection logs existed to produce.
  2. IPVanish, 2018 — the counterexample above: a “zero-logs” claim that collapsed the moment a subpoena arrived, because the provider was in fact logging connection data.
  3. Mullvad, Sweden — police were allowed to physically inspect the company’s offices and servers as part of a cross-border investigation and found no customer activity data to seize, consistent with Sweden’s lack of mandatory data-retention rules for VPN operators.

The pattern is consistent: a no-logs policy is only as strong as what happens when someone with legal authority actually asks for the data.

How to verify a no-logs claim yourself

You don’t need a law degree to sanity-check a provider’s promise. A few checks go a long way:

  1. Read the actual privacy policy, not the homepage summary — look for specific exclusions (IP, timestamps, DNS) rather than the vague phrase “we don’t log.”
  2. Look for an independent audit and check its scope and date — a three-year-old audit of a different app version tells you less than it sounds like.
  3. Check the provider’s jurisdiction — some countries require data retention by law, which overrides any policy on paper.
  4. Search for a real-world test — a court case, a police seizure, a hack — where the no-logs claim was actually put under pressure.
  5. Separate account data from activity data — billing information isn’t a privacy failure; connection and browsing logs are.

How RunVPN handles logging

RunVPN does not store websites, DNS queries, traffic destinations, or traffic content. It retains limited connection records for 30 days.

  1. Download the app — Android is available now, with iOS and desktop coming soon.
  2. Sign in with Google, email, or Telegram — the app then pulls its connection configuration automatically. There’s no manual config file to import and no QR code to scan.
  3. Tap connect. Traffic runs over AmneziaWG or VLESS-Reality (XTLS-Vision) on the Xray engine, tuned for a fast, stable connection.
Logging VPN Device VPN server Activity logs stored Subpoena / leak No-logs VPN Device VPN server No logs to hand over
With no activity logs stored, there's nothing to hand over when a request comes in.

RunVPN can respond to valid legal requests with the limited connection records available within the 30-day retention window. It does not have browsing destinations, DNS queries, or traffic content to disclose.

RunVPN accounts support up to 5 devices, and the app is free to try before you commit to a plan. For the full technical breakdown, see the trust and privacy page.

FAQ

Does a no-logs VPN mean the company knows nothing about me? No. Billing information (email, payment method) still exists for account management — a no-logs policy is about not recording your connection times, IP addresses, and browsing activity, not erasing the fact that an account exists.

Can a VPN provider really guarantee it will never log, even under legal pressure? No provider can guarantee future behavior. What matters is whether its current architecture makes activity logging technically unnecessary, and whether that’s been checked by an independent audit or tested by a real legal request.

Is a no-logs policy the same as strong encryption? No — they solve different problems. Encryption protects what’s inside your traffic from being read in transit; a no-logs policy determines whether a record of that you sent traffic at all exists afterward.

Does RunVPN log which sites I visit? RunVPN does not track browsing destinations. Account sign-in (Google, email, or Telegram) is linked to limited connection records retained for 30 days and is also used to manage subscriptions and devices.

Ready to try it? Download RunVPN or read more about the VLESS-Reality protocol powering the connection underneath.