Guides

How to choose a VPN without falling for the marketing

Choosing a VPN comes down to a few verifiable facts: what the logging policy actually says, where the company is incorporated, which protocols it runs, whether it owns its servers, and what renewal really costs. Marketing claims like "military-grade encryption" carry no information — every serious VPN uses the same algorithms.

🛡️

Read the logs policy, not the banner

"No logs" on the homepage means nothing by itself. The privacy policy tells you what is actually recorded: connection timestamps, bandwidth, IP addresses — or genuinely nothing about your activity.

🌍

Encryption is a solved problem

AES and ChaCha20 are used by everyone, from banks to free apps. A VPN cannot differentiate itself on cipher strength, so any pitch built on "unbreakable encryption" is noise.

🔑

The renewal price is the real price

Deep first-year discounts often double or triple at renewal. The number that matters is what year two costs — and whether the service commits to renewing at the same price.

What a no-logs policy really means

A no-logs policy is meaningful only if it says what is not logged. The claim you want spelled out: no records of which sites you visit, no storage of your traffic, no mapping of your account to the IP addresses you visited. Some services that advertise "no logs" still keep connection metadata — timestamps, session length, bandwidth used, sometimes your source IP — which is enough to correlate activity.

Look for the specifics in the privacy policy, not the landing page. Useful signals: the policy names the exact data retained (account email, payment status) and the exact data never written; the service has been through an independent audit or a real-world test, such as a court order it could not satisfy because the data did not exist. Vague language — "we may collect diagnostic information" — is where activity logging hides.

Does jurisdiction matter

Yes, but less than the logging itself. The company's jurisdiction determines which governments can compel it to hand over data or to start logging. A service incorporated in a country with mandatory data-retention laws is legally required to keep records regardless of what its homepage says.

The practical rule: jurisdiction matters only for data that exists. A service that truly writes no activity logs has nothing to surrender, whatever court asks. Evaluate the pair together — strict no-logs in a neutral jurisdiction is the strong combination; a "no-logs" claim in a retention-mandate country is a contradiction and a warning.

Which protocols should be on the list

WireGuard is the baseline in 2026: a small, audited codebase, fast handshakes, quick reconnects when you switch networks, and low battery cost on mobile. If a service does not offer it or a derivative of it, ask why.

OpenVPN remains a reasonable fallback — slower and heavier, but universally supported and extremely well studied. Protocols built on the Xray platform (VLESS with REALITY, and similar) matter if you use networks that actively interfere with VPN traffic, because they are designed to look like ordinary TLS. Aurora runs WireGuard and Xray-based protocols for exactly this split: speed by default, resilience where networks are hostile.

What you can ignore: proprietary protocols with secret internals and anything still leaning on PPTP or L2TP, which are legacy at best.

Own servers or rented — and does it matter

Most VPNs rent virtual machines from the same hosting providers. That is not automatically bad, but it means a third party physically controls the hardware, and a cheap oversold VPS shows up as unstable speed at peak hours.

Services that run their own dedicated servers control the disk (no third-party snapshots of a running server), the capacity, and the network configuration. You cannot verify ownership from the outside, but you can observe its symptoms: consistent throughput at evening peak, and straight answers from support when you ask whether servers are dedicated or virtual.

Price, devices, support and the renewal trap

Compare renewal prices, not intro prices. The industry standard trick is a heavily discounted 2-year plan that renews at several times the advertised rate. Before paying, find the renewal amount in the checkout fine print — and prefer services that renew at the price you signed up at.

Then check the mechanics of everyday use: how many devices one subscription covers (Aurora allows up to 7 simultaneously), whether apps exist for every platform you own, whether there is a money-back window long enough for a real test — 14 days is a fair standard — and whether support answers with substance. Send a technical question before you pay; the reply tells you more than any review.

  • Logging policy names exactly what is and is not recorded
  • Jurisdiction without mandatory data retention
  • WireGuard available; Xray-class protocols if your network interferes
  • Renewal price equals the price you signed up at
  • Enough simultaneous devices for your household
  • Money-back guarantee long enough for real testing
  • Support that answers technical questions, not scripts
  • Independent audit or other external verification of claims

What free VPNs actually sell

Running servers and paying for traffic costs real money, so a free VPN is financed some other way. The common models: injecting or reselling data about your browsing, capping speed and volume to upsell a paid tier, or routing other customers' traffic through your device.

A limited free tier from a paid service — small quota, few locations — is a legitimate demo. A "forever free, unlimited" VPN with no visible business model is the one to distrust: you cannot audit what happens to traffic at the far end of the tunnel.

Why "military-grade encryption" means nothing

Every credible VPN uses the same public, peer-reviewed algorithms — AES-256 or ChaCha20 for traffic, standard elliptic-curve exchanges for keys. These are free, open, and identical whether the service costs nothing or twenty dollars a month. There is no secret stronger cipher available to one vendor.

So when a service leads its pitch with encryption strength, it is advertising the one property it shares with every competitor. Real differences live elsewhere: what gets logged, who owns the hardware, how the protocol behaves on hostile networks, and what renewal costs. Judge on those — the cryptography is the same everywhere.

Frequently asked questions

How do I verify a no-logs claim?
Read the privacy policy for specifics: it should name exactly what is stored (account email, payment status) and state that browsing activity and IP mappings are never written. Independent audits and court cases where no data could be produced are the strongest external evidence. A homepage badge alone verifies nothing.
Is a cheaper VPN always worse?
No. Price mostly reflects marketing budgets, not cryptography — the algorithms are identical everywhere. What cheap sometimes means is oversold rented servers and slow support. Judge by measurable things: peak-hour speed during your money-back window, the logging policy text, and the renewal price rather than the intro price.
How many devices do I actually need?
Count your household: a phone and laptop per person plus a tablet or TV fills five to seven slots quickly for a family. Check whether the limit counts simultaneous connections or installed apps — simultaneous is the number that matters. Aurora covers up to 7 devices at once on one subscription.
Do I need a VPN with servers in many countries?
Only if you need those locations. For privacy and public Wi-Fi safety, a handful of fast servers near you beats a map with a hundred flags — huge location counts are often virtual servers in a few data centers. Pick the service whose servers are fast where you actually live and travel.
What should I test during the money-back period?
The things you cannot read in a policy: download and upload speed at evening peak on a nearby server, latency for calls or gaming, reconnect behavior when switching from Wi-Fi to mobile, whether it works on your office or campus network, and how support responds to a technical question. Fourteen days is enough for all of it.
Are VPN review sites trustworthy?
Treat them as advertising. Most rankings are affiliate-funded — sites earn a commission on every signup, and placement often follows payout rather than quality. Use them to discover names, then verify claims yourself: read the privacy policy, check the renewal price, and run your own speed tests during the refund window.

Keep reading

Try Aurora

14-day money-back guarantee. Up to 7 devices on one subscription.

Protect my devices