VPN logging explained
Updated 21 September 2026 · How we research
"No logs" is a claim about policy, not a property of the software. Reading a privacy policy properly means separating three very different categories of record.
Three kinds of log
Activity logs
Sites visited, DNS queries, contents. A provider keeping these defeats the point of the product. Effectively nobody admits to it.
Connection logs
Timestamps, source IP, server used, bytes transferred. These are the ones that matter, because they can link a session back to a person.
Diagnostic logs
Crash reports and aggregate load data. Often benign, but the detail and retention period are what decide that.
Questions a policy should answer
- Is the source IP address stored at all, and for how long?
- Are connection timestamps retained, and can they be correlated with a server?
- What is the retention period in days, stated as a number rather than "minimal"?
- Which jurisdiction governs the company, and what can compel disclosure there?
- Has an independent audit examined the infrastructure, who performed it, and when?
- Does the service run diskless or RAM-only servers, so that seizure yields nothing?
Wording to be sceptical of
Why we do not score this
A logging policy can only be assessed from published documents, corporate structure and any third-party audit. VPN Sherlock does not operate infrastructure inside any provider, so we cannot verify what is written to disk. We summarise what each provider publishes and say plainly when a claim is unverified. See our methodology for what that means in practice.
A practical approach
- Read the privacy policy, not the landing page.
- Check the retention period for connection metadata specifically.
- Note the jurisdiction and who ultimately owns the company.
- If an audit is cited, find the report and check its date and scope.
- Assume that anything not written down is not a commitment.