Guides › No-logs, actually
What a "no-logs" VPN actually stores
"No logs" is a slogan, not a description. A VPN that stored nothing at all could not enforce a device limit, show you your own sessions, or bill you. So the honest question is not whether a VPN keeps records, but which ones, for how long, and whether any of them describe what you did online.
Updated
The one question that matters
Does the provider keep anything that describes what you did: the sites you visited, the addresses you connected to, your DNS lookups? If the answer is no, then whatever else it holds cannot be turned into a history of you, because the history was never written. That is the test. Everything else is bookkeeping.
Our answer is no. We do not record traffic contents, destinations or DNS queries, on the servers or anywhere else. No order can compel us to produce a record that does not exist.
What we do keep, and why
This is the complete list. It is the same list as clause 3 of the Privacy Policy, in plainer words.
| Record | What is in it | Why it exists | Kept for |
|---|---|---|---|
| Account | Email, a hash of your password, plan and status, optional 2FA secret (encrypted), the time and address of your last website sign-in | Recovery, expiry notices, spotting a hijacked account | Life of the account |
| Devices | A name you choose, the certificate or WireGuard public key issued to it, a device-derived identifier | Enforcing the device limit on your plan | Until you remove the device |
| Connections | Which server, which device, the tunnel-internal address, start and end time, bytes in and out; a salted hash of the address you connected from, which also appears in the session identifier | Plan limits, your own "active sessions" view, running the network | 7 days after the session ends, by default; then deleted automatically |
| Payments | Method, amount, currency, status, a processor reference. Never a card number | Billing, and tax law | As long as accounting law requires |
| Diagnostics | The app log, your email, device name, platform and versions, plus your note. Sent only when you press "send to developers" | Fixing the bug you reported | Until resolved |
| Server logs | The VPN daemon's connect and disconnect events, including the connecting address | Operating the node | Rotated on the server; a few rotations kept |
The source address, honestly
Most "no logs" pages go quiet here, so we will not. When your device connects, the server sees the address it connected from; that is how the internet works. What we do with it is the question. The connection record holds a salted hash of that address, and the address itself appears inside the session identifier the node uses to match a disconnection to its connection. Both go when the record is deleted under the retention schedule. We do not store the address anywhere else, and we never associate it with any destination, because we hold no destinations.
If even that is more than you want, connect through Tor mode: the server then sees a Tor exit, and the record holds the hash of a Tor exit.
What "we could not produce it" means in practice
We disclose data only under legal process that is valid and binding on us, and we assess every request rather than answering reflexively. But the more important protection is structural: what we can disclose is bounded by the table above. A demand for "everything you have on this user" is answered with an email address, a plan, some device names and up to a week of connection records that say a device connected to a server and moved n bytes. Not where the bytes went.
How to keep your account as thin as possible
- Use an email address that is not tied to your name. It is the only identifier we require.
- Pay with Monero or Bitcoin. BTCPay attaches no name, card or address; see paying with Monero.
- Name devices blandly. "Laptop" says less than "Jeff's ThinkPad".
- Don't send diagnostics unless you need help. Nothing is transmitted unless you press the button.
- Use Tor mode when the source address matters.
Why we did not go further
A service that kept nothing at all could not stop one paid account from being shared with a thousand people, could not show you which of your devices is currently connected, and could not refund a payment it had no record of. Every row in the table above exists to run the service you are paying for, is kept for the shortest time that job allows, and describes the service, not you. That is what "no logs" ought to mean, and it is what we mean by it.
Questions
Do you log the websites I visit?
No. We do not record traffic contents, destinations, or DNS queries, so no record of them exists to be produced, sold, or subpoenaed.
Do you log my IP address?
When a device connects, the connection record holds a salted hash of the address it connected from, and the address appears inside the session identifier that matches a disconnect to its connect. Both are deleted with the record, 7 days after the session ends by default. Your sign-in address for the website is kept for the life of the account, to detect account compromise.
What happens if the police ask for my data?
We disclose data only under legal process that is valid and binding on us, and we assess every request. What we could disclose is bounded by what we hold: the records described on this page, and nothing about destinations or traffic.
Can I use the service without giving you personal data?
Close to it. An email address is required, for account recovery. Paying with Bitcoin or Monero through BTCPay attaches no name, card or address to the account.
Try it
Every new account starts with a free trial, every plan includes every location, and you can pay by card, Bitcoin, Lightning or Monero.