What a No-Log Policy Actually Means
A VPN no-log policy means the provider does not retain records that could identify what you did online, when you were connected, or where you connected from. The key word is retain: virtually all VPNs process your traffic in real time (that is how routing works), but a true no-log provider does not write that information to disk or keep it after your session ends.
What Should and Should Not Be Logged
There are different categories of data a VPN might store. Usage logs (browsing history, IP addresses, connection timestamps, bandwidth per session) are the most privacy-sensitive and should not be kept by any privacy-focused provider. Connection logs (timestamps of when you connected, which server you used) are less sensitive but can still be used to correlate activity with your account. Aggregate diagnostics (total bandwidth across all users, uptime statistics) are acceptable because they cannot be tied to an individual.
How Providers Are Verified
Independent audits are the only meaningful verification. Providers like ExpressVPN, NordVPN, Mullvad, and ProtonVPN have paid independent security firms (including Cure53, PwC, and KPMG) to audit their infrastructure and confirm no logs exist. The audit reports are published, though often at a summary level. Court cases are another real-world test: NordVPN's servers were seized in a 2018 Finnish case; investigators found no useful data because the provider held none.
Jurisdiction Matters
Even with no logs, a provider operating in a country with mandatory data retention laws faces legal pressure. Providers in Switzerland (Mullvad), the British Virgin Islands (ExpressVPN), and Panama (NordVPN) operate outside the 14-Eyes intelligence sharing framework and face weaker retention mandates. This does not guarantee privacy but reduces the legal surface for compelled disclosure.
Red Flags to Watch For
Vague policies using language like 'we do not log your browsing activity' without specifying what else they do log. Policies that mention 'connection logs for troubleshooting.' No mention of audits or audit results. Free VPNs with no clear business model (they are monetizing your data, not your subscription). These are warning signs that the no-log claim is marketing rather than policy.