A "no logs VPN" is a provider that promises not to record what you do through its servers: which sites you visit, what you download, when you connect from which address. The phrase has no legal definition, so on its own it means nothing. What matters is the specific list of what is and is not stored, and whether that list is believable given how the service is built. This article explains what a VPN server can see, what a real no-logs policy has to say, and how to check a provider's claim without taking its word for it.

What a VPN provider can see

Once you connect, the VPN server is where your traffic is decrypted and forwarded. Technically, the provider can see everything your ISP could see before: the domains you visit (via DNS and TLS server names), timestamps, data volume, your real IP address, and the server you connected to. It cannot see the content of HTTPS pages, which is nearly everything today. The details of what is visible at each hop are in what can my ISP see.

So "no logs" is a promise not to write down what the server can see. Whether it is kept is a question of policy, architecture and incentives.

The kinds of logs

  • Activity logs: sites, DNS queries, connections, content metadata. A no-logs provider must not keep these, full stop.
  • Connection logs: your real IP, connection timestamps, server used. Some providers keep these briefly for abuse handling; a strict no-logs provider does not keep them tied to your identity.
  • Aggregate statistics: total data volume per period, number of active sessions, server load. These do not identify what you did, and almost every provider keeps some of them because billing and capacity planning need them.
  • Account data: email, subscription status, payment records. Unavoidable if you pay.

A provider that says it keeps nothing at all is either not running a business or not being precise. The honest version says which of these four it keeps and for how long.

What a serious policy looks like

Look for specifics rather than slogans. Here is the shape a credible policy takes, using 404 VPN's privacy policy as an example. It states that the service does not store browsing history, DNS queries, traffic content or metadata, or the source IP address after the VPN connection is established. It also states what it does store: the account email, subscription status and plan, and aggregated technical statistics such as data volume per period and the date of last connection, kept while the account is active and deleted within 30 days of a deletion request.

That last paragraph is the tell. A policy that lists the stored items is one you can hold the provider to. A policy that only repeats "zero logs" gives you nothing to check.

Questions to ask any provider

  1. What exactly is stored, and for how long? If the answer is a list, good. If it is an adjective, no.
  2. Is DNS handled inside the tunnel, on the provider's own resolvers? Otherwise a third party gets the domain list.
  3. What happens on a legal request? A provider that keeps no activity or connection logs can only hand over what it has: account email and aggregate usage. A provider that keeps connection logs can hand over your IP history.
  4. Which jurisdiction, and has the policy been tested? Court cases and independent audits where the provider could produce nothing are the strongest evidence that exists.
  5. How are servers run? Disk-less servers that hold everything in memory, and configurations that assign session addresses dynamically and wipe them on disconnect, make retention technically hard rather than just promised.
  6. How does the business make money? A paid subscription is a clear answer. Anything else deserves a closer look.

Why "free no-logs VPN" is a contradiction

Servers, bandwidth and staff cost money. A free service has to recover that somewhere: advertising built on your browsing, selling aggregated or not-so-aggregated data, injecting content, or using your device as an exit point for other customers. Each of those requires exactly the data a no-logs policy says is not collected. There are a few honest free tiers funded by paid plans, with limits on data or servers; the rest should be assumed to log by design. A free tier that states its limits and is attached to a paid product is a different thing from a free app with no visible business.

What no-logs does not cover

  • The websites you use. They see the VPN's address but still see your account, cookies and browser fingerprint. The Privacy Checker shows how much a site learns without your IP.
  • Your device. Apps and the operating system keep their own histories.
  • Leaks. If DNS or IPv6 escape the tunnel, the ISP gets the domain list regardless of the provider's policy. Test with is my DNS leaking.

The practical summary

"No logs" is worth exactly as much as the list behind it. Read for specifics, prefer providers that state what they do keep, check that DNS stays inside the tunnel, and be suspicious of anything free that cannot explain its income. Then test your own connection, because a policy cannot fix a leak.

404 VPN keeps DNS inside the VLESS or WireGuard tunnel on its own resolvers, has a kill switch, and publishes a privacy policy that lists what is stored and what is not. You can read the security page for how the tunnel is built, or get started here.