Search for any VPN and the phrase appears within seconds: no logs. It is on nearly every landing page, so it has almost stopped meaning anything.
That is a problem, because when you use a VPN, the provider takes over the position your internet provider used to have. Whatever they record about you is the whole privacy story. So it is worth understanding what "no logs" should mean, and how to tell a real policy from a slogan.
The different kinds of logs
Not all logs are equal. When a provider says "no logs", ask which ones.
Activity logs record what you did: sites visited, DNS lookups, files downloaded. A VPN that keeps these is not a privacy service at all.
Connection logs record when you connected, from which IP address, to which server, and for how long. They sound harmless, but connection times plus your real IP address can be matched against a website's records to identify a user. Many "no-logs" providers quietly keep these.
Aggregate or diagnostic data covers things like total load on a server or crash reports with no user identifiers. Some of this is needed to run a network and is reasonable if it cannot be tied back to a person.
A meaningful no-logs policy rules out the first two completely and is specific about the third.
Why the infrastructure matters
A policy is a promise. Infrastructure is what makes the promise hard to break.
RAM-only servers run entirely from memory and keep nothing on a hard drive. When the server restarts, everything on it is gone. A provider using RAM-only infrastructure cannot hand over session records it never wrote to disk, even if asked, ordered or hacked.
Compare that with a server with ordinary disks, where "we do not keep logs" depends on someone remembering to configure every service correctly, forever.
Five questions that test the claim
- Does the policy name the specific data it does not collect? "We respect your privacy" is not a policy. "We do not record your source IP address, connection timestamps or the sites you visit" is.
- What does it collect, and why? Every service collects something, such as an email for your account or payment records. Honest policies say exactly what and why.
- Is the infrastructure designed so that logs cannot pile up? RAM-only servers are the strongest version of this.
- Where is the company based, and what can it be compelled to do there? Jurisdiction decides who can demand data and how.
- Has the claim ever been tested? Independent audits, court cases where a provider had nothing to hand over, or transparency reports all count as evidence. A claim nobody has checked is still a claim.
The red flags
- A free VPN with no clear business model. Running servers costs real money, so if you are not the customer, your data may be the product.
- A privacy policy far longer and vaguer than the marketing page.
- "No logs" on the homepage, but "we may collect connection data to improve the service" in the policy.
- Apps that ask for permissions a VPN does not need, such as contacts or location.
The bottom line
"No logs" is the most important promise a VPN makes, and the easiest to make carelessly. Read the policy, look for specifics, and prefer infrastructure that makes logging impossible over a company that simply says it does not do it.
Korp VPN runs RAM-only infrastructure with a strict no-logs policy: no session logs, no IP tracking and no persistent storage. You can read exactly what we do and do not collect in our privacy policy.