A VPN logging policy describes what user data to collect, such as bandwidth use, connection details, device information, DNS requests, IP address info, bug reports, and crash reports. Some policies improve the service, while others compromise your privacy. This is why many people specifically look for a VPN with a strict privacy policy.
But what exactly counts as a “log” on a VPN?
What are logs on a VPN or network?
VPN logs can include your original IP address, the servers you connected to, how long you stayed connected, how much bandwidth you used, your browser type, and the websites you visited. Every VPN handles this differently, depending on its logging policy.
Some providers keep a limited set of logs to help monitor performance and fix problems. Take a look at the breakdown below.
Research from Privacy Canada found that VPN providers often collect a wide range of user information:
- 29% collect personal details
- 24% log IP addresses
- 57% log connection timestamps and bandwidth
- 51% log device types
- 92% log payment information
- 9% log browsing history
A separate study by VPN Overview found:
- 47% of VPN providers are based in Five Eyes, Nine Eyes, or Fourteen Eyes countries
- 15% of VPNs don’t clearly disclose what information they store in their privacy policies
So what kind of data can these alliance countries request?
- Communications data (your digital activity)
- Internet activity (apps and websites you use)
- Location data (places you visit or save)
- Financial data (banking and purchase history)
- Biometric data (such as fingerprints)
The same research found that 14.4% of VPNs log network traffic activity, 27% log your original IP address before connecting, 50% log connection timestamps, and 42% log the server location you connect to. Data source: VPN Alert
What are the reasons for data logging?
VPN providers collect this data for several reasons:
- Improving their product
- Fixing bugs
- Running analytics
- Gathering user feedback
- Handling maintenance.
The concern is that some of this data includes personal or sensitive details that may be sold to advertisers.
What type of log collection is acceptable?
Not all logging is a red flag. Some data collection doesn’t include sensitive personal details, and most users are comfortable with it. Here’s what generally falls into that category.
| Log type | What it involves |
| Bandwidth logs | Track how much data you send and receive through your VPN connection. Providers use this to monitor server usage and manage bandwidth limits. |
| Connection logs | Record incoming and outgoing connections to a VPN server, including your IP address, the server’s IP address, and connection times/dates. Sometimes includes bandwidth use. Providers use these for troubleshooting, service improvements, and detecting unusual activity like torrenting through deep packet inspection. A genuine no-logs provider doesn’t retain any of this. |
| Bug reports | Collected to spot and fix technical issues. Typically include device type and specifications rather than personal information. Help developers troubleshoot problems and improve the app. |
| Crash logs | Similar function: if the app crashes, this data helps developers understand why and prevent it from happening again. |
What type of log collection is unacceptable?
Some types of data collection raise real privacy concerns, including your browsing habits, the apps you use, your DNS requests, the websites you visit, and your original IP address. Here’s a closer look.
| Log type | What it involves |
| Browsing history | Tracks which websites you visit, how long you stay, and your overall browsing patterns. Some providers sell this data to advertisers for targeted marketing. |
| DNS requests | Reveals what you’re doing while connected to a VPN, which is why logging them raises privacy concerns. Some providers log DNS requests only to troubleshoot issues or improve network performance. |
| URLs visited | Lets a provider build a profile of your interests for advertising. For example, searching for sunglasses on a shopping site can lead to sunglass ads showing up on Facebook, Instagram, or YouTube. This is exactly the kind of tracking a strict no-logs VPN is meant to prevent. |
| IP address logs | Some providers keep a record of your original IP address while you’re connected. If a government or legal authority requests this, it could expose your identity. A true no-log VPN doesn’t store this data, so it has nothing to hand over, even if asked. |
3 popular VPNs that used to keep user logs
Major popular VPN services that have faced documented controversies, data leaks, or legal cases contradicting past “no-logs” or zero-logging pledges include: [1]
- UFO VPN: Marketed itself with a strict zero-log policy, but suffered a massive data leak exposing over 20 million user logs daily—including real IP addresses, connection timestamps, and plaintext passwords.
- PureVPN: Adhered to a no-log marketing policy, but handed over specific connection and real IP logs to the FBI in 2017 that successfully helped law enforcement identify and arrest a cyberstalker.
- IPVanish: Famously advertised a zero-logs policy, but court documents from a 2018 criminal case revealed the service had turned over connection and traffic logs to US Department of Homeland Security investigators.
Data source: Gadget Match, Life Hacker, Reddit.
FAQs
The most reliable way to avoid VPN logging is to choose a provider with a genuine privacy policy, ideally one backed by an independent audit or open-source code you can review yourself.
Most VPN providers hold onto logs for somewhere between 30 and 90 days, though this varies widely. Some keep data for as long as they consider necessary, which is where privacy concerns start to creep in.
Only if it’s backed by proof, such as an independent security audit or open-source code that anyone can inspect.
Final words
VPN logging policies matter because they determine how much data your provider collects, stores, and may share. Technical logs, like connection and bandwidth data, are generally acceptable and help providers maintain their service.
Sensitive information, such as your browsing history, DNS requests, original IP address, or device details, is different. If privacy is a priority, choosing a VPN with a strict privacy policy is the safest way to protect that data.