Guides

What "no logs" actually means

"No logs" almost never means a service records nothing. It usually means no activity logs: no record of the sites you visit or the data you transfer. Connection metadata, diagnostics, and payment records are separate categories, and every provider defines them differently. The privacy policy, not the slogan, tells you which ones are kept.

🛡️

Logs come in four kinds

Activity logs record what you did online. Connection logs record when and from where you connected. Diagnostics record how the app behaved. Payment records document that you paid. A "no logs" badge may cover only the first.

🌍

Some records always exist

A subscription service must know your account exists, whether it is paid, and how many devices it serves. No honest policy claims zero data. The question is whether stored data can reconstruct your behavior.

🔑

Jurisdiction outranks slogans

A provider obeys the laws of the country it operates in. If local law mandates traffic retention, a landing-page promise does not override it. Where a service is incorporated matters more than what its banner says.

What kinds of logs are there

Four categories, and they should never be discussed as one. When a provider says "no logs" without naming a category, it has told you almost nothing, because the phrase can honestly describe a service that keeps everything except a browsing history.

The categories differ in sensitivity. Activity logs can reconstruct your life. Connection logs can place you at an address at a time. Diagnostics are usually mundane crash data. Payment records identify you but say nothing about what you did online.

  • Activity logs — sites visited, DNS queries, traffic contents: the most sensitive kind
  • Connection logs — timestamps, your source IP, server used, bytes transferred
  • Diagnostic logs — crashes, app version, connection failures
  • Payment records — invoices, transaction ids, billing identity

Which logs a service technically does not need

Activity logs are never required to run a VPN. Forwarding packets does not require remembering where they went, so a provider that records visited domains or DNS queries chose to. This is the one category where "we keep nothing" is technically achievable and should be stated flatly in the policy.

Per-user connection logs are also avoidable, with a nuance. A server must know your source address while the session is open, or the return traffic has nowhere to go. The design question is what happens afterward: a privacy-focused service holds that state in memory and discards it at disconnect, while a logging one writes it to disk with timestamps. Aggregate counters, such as total load per server, need no per-user detail at all.

Short-lived diagnostics are defensible for debugging, but retention should be days, the data should not include browsing destinations, and crash reporting should be opt-in on the client.

What every paid service keeps anyway

An account record: your email or another identifier, the subscription's status and expiry, and device or connection limits. Without these the service cannot let you in or bill you. A policy claiming absolutely nothing is stored is a red flag in itself, because it cannot be true of any subscription business.

Payment records live even longer than accounts. Card processors and payment laws impose retention measured in years, and deleting your account does not erase an invoice from an accounting ledger. Paying with crypto shortens this trail on the provider's side but never removes the processor's own records. The honest framing: payment data proves you were a customer, and a well-designed system keeps it disconnected from anything describing what the connection was used for.

How an audit differs from a promise

A landing-page promise costs nothing and verifies nothing. An independent audit means an outside firm examined servers, configurations, and code at a point in time and reported whether practice matched the policy. That is a meaningfully higher bar, and providers who pass tend to publish the report, not just a badge.

Audits have honest limits. They describe the systems on the days of the examination, not forever after; scope can be narrow; and the auditor sees what it was given access to. A second, indirect form of evidence is court records: cases where a provider was ordered to produce data and had nothing useful to hand over. Neither proves the future — together they beat a slogan by a wide margin.

Why jurisdiction matters more than the policy

Because law outranks marketing. A provider incorporated in a country with mandatory data-retention rules must comply with them regardless of what its website promises, and some jurisdictions can compel a service to start logging a specific user quietly. The policy describes intent; the jurisdiction defines what can be forced.

So read the two together. Where is the company incorporated, whose courts have power over it, and where do the servers physically stand — server-side law can apply even when the company sits elsewhere. A no-logs policy in a jurisdiction without retention mandates is a coherent story. The same policy under a retention law is a contradiction the provider should explain, and usually does not.

How to check a policy yourself

Read the privacy policy, not the homepage, and search it for the four categories by name. A trustworthy policy states what is collected, how long each item lives, and what happens on account deletion. Vague documents hide behind broad verbs: "we may collect certain technical information" can mean anything up to full connection logging.

Aurora's position, briefly: we keep no activity logs — no record of the sites you visit or the traffic you send — and everything we do store, from account email to payment records, is enumerated in the privacy policy rather than summarized in a slogan.

Phrases that should make you slow down and read twice:

  • "No logs" with no definition of which log types are meant
  • "We collect anonymized data" without describing the anonymization
  • Retention periods missing, or "as long as necessary"
  • A policy that never mentions responses to legal requests
  • No named jurisdiction or company entity anywhere in the document

Frequently asked questions

Does "no logs" mean the VPN stores nothing about me?
No. It normally means no activity logs — no record of visited sites or transferred content. Your account, subscription status, and payment history still exist, because a paid service cannot operate without them. What varies between providers is connection metadata: timestamps, source addresses, and bandwidth, kept or discarded.
Can a no-logs VPN still hand data to authorities?
It can only hand over what exists. A genuine no-logs provider can produce account and payment records but not browsing history, because that history was never written down. However, a court in its jurisdiction may be able to compel logging from that day forward, which is why jurisdiction matters.
Are no-logs claims ever verified?
Sometimes. Independent audits examine servers and configurations against the written policy, and published court records occasionally show a provider had nothing to produce. Both are point-in-time evidence, not permanent guarantees, but a provider with audits and a clean legal history is far more credible than a banner.
Why does a VPN need my email if it keeps no logs?
Account identity and traffic logging are different things. An email lets you log in, recover access, and receive invoices; it says nothing about your traffic. The privacy question is whether the service links that identity to records of what you did online — a no-activity-logs design has nothing to link it to.
Do connection logs matter if my activity is not recorded?
Yes. A timestamped record that your home address connected to a given server can be correlated with events elsewhere, even with no content attached. Metadata is evidence. That is why the stronger policies discard per-session data at disconnect instead of archiving it.
Is RAM-only server infrastructure the same as no logs?
No, it is a supporting measure. Running servers from memory means data does not survive a reboot or seizure, which limits what can be taken physically. But software can still ship logs elsewhere in real time, so RAM-only hardware complements a no-logs policy rather than proving it.

Keep reading

Try Aurora

14-day money-back guarantee. Up to 7 devices on one subscription.

Protect my devices