TunnelBear built its reputation on being the friendly, beginner-approachable VPN, all cartoon bears and plain-English explanations. That branding sometimes overshadows the actual privacy question people search for: does TunnelBear keep logs? We read the current privacy policy, checked the jurisdiction, and looked at what its one and only independent audit actually covered.

What TunnelBear claims

TunnelBear’s privacy policy states it does not log:

  • Browsing activity or destination websites
  • IP addresses once your VPN session ends
  • DNS queries
  • Traffic content

What it does collect: the total amount of data used per month (relevant only for free-tier users who get a data cap), aggregate connection counts, and the app version and operating system you’re running. None of this is tied to your browsing activity.

That data-usage tracking is worth flagging on its own. TunnelBear needs to know how much data a free account has burned through to enforce its monthly cap, which is a legitimate operational reason, but it does mean TunnelBear retains more account-level metadata than a strict, connection-blind service like Mullvad.

The 2018 Cure53 audit: what it covered and what it didn’t

TunnelBear is one of the few VPNs that submitted to an independent audit early, back in 2017 and 2018, handled by Cure53, a well-regarded German security firm. The audit examined TunnelBear’s browser extensions, infrastructure, and some backend systems for security vulnerabilities.

Here’s the important caveat: that audit was a security assessment, not a no-logs verification. It looked for exploitable bugs and infrastructure weaknesses, not whether TunnelBear’s servers were configured to avoid storing connection logs the way NordVPN’s or Surfshark’s later audits specifically tested for. Cure53 found and TunnelBear fixed several issues, which is a good sign of a responsive security team, but the audit doesn’t directly prove the no-logs claim the way a dedicated no-logs assessment does.

TunnelBear has not repeated the audit since 2018. That’s eight years without an independent recheck, in an industry where infrastructure, ownership, and internal practices can shift considerably.

Jurisdiction: Canada and the Five Eyes problem

TunnelBear is based in Canada, which is a member of the Five Eyes intelligence-sharing alliance alongside the US, UK, Australia, and New Zealand. Canadian authorities can be compelled by domestic courts to request user data from companies operating there, and that data can legally be shared with the other Five Eyes members.

In practice, this matters most if TunnelBear actually held meaningful logs to hand over. Since the company’s stated policy is not to retain browsing or IP data, a Five Eyes request would have little of substance to seize, assuming the policy holds up. But without a recent audit specifically verifying that claim, users are relying on TunnelBear’s word rather than third-party confirmation, in a jurisdiction that’s more exposed than Panama or Switzerland.

Who owns TunnelBear

TunnelBear has been owned by McAfee since 2018. McAfee is a large, publicly traded US security company, which brings resources and stability, but also puts a well-known American brand’s compliance obligations in the ownership chain. McAfee has stated it operates TunnelBear independently and hasn’t required changes to its privacy practices, but the ownership structure is worth knowing if jurisdiction and corporate independence matter to your threat model.

VigilantBear and GhostBear: what they actually protect against

TunnelBear names its features after bears, which is charming but can obscure what they actually do. VigilantBear is TunnelBear’s kill switch: if the VPN connection drops unexpectedly, it blocks all internet traffic until the connection is restored, preventing your real IP address from leaking out during that gap. This is a meaningful security feature and works as advertised in our testing, no leaks detected when the connection was manually interrupted.

GhostBear is TunnelBear’s obfuscation mode, designed to disguise VPN traffic so it’s harder for networks or governments to detect and block. It’s useful in restrictive network environments, workplace filtering, school networks, or countries with VPN blocking, though it isn’t as robust as the dedicated stealth protocols NordVPN or ProtonVPN have built specifically for high-censorship regions.

Neither feature changes the logging picture directly, but both matter for the practical privacy TunnelBear delivers day to day: a kill switch that actually works closes one of the most common ways a VPN’s no-logs policy becomes irrelevant, because your real IP leaked before the policy ever mattered.

How to verify a no-logs claim yourself

You can’t independently audit a VPN’s servers, but you can do a few practical checks before trusting any provider’s claim, TunnelBear included. Check whether the privacy policy specifically lists what is and isn’t collected, rather than using vague language like “minimal data.” Look for a documented history (or lack of one) of court cases or law enforcement requests where the company either had nothing to hand over or was shown to have logs it denied keeping. And weigh how recently, and how specifically, any audit was conducted against what it actually tested.

For TunnelBear, that check leaves you with a clear, detailed privacy policy, a decent but old and narrowly scoped audit, and no known history of a logging scandal. That’s a reasonable, if unspectacular, track record. It’s meaningfully behind the handful of providers that have made no-logs verification an ongoing, repeated practice rather than a one-time event.

How TunnelBear compares to other audited VPNs

VPNAudit typeLast auditJurisdiction
TunnelBearSecurity (Cure53)2018Canada (Five Eyes)
NordVPNNo-logs (PwC, Deloitte)2025Panama
MullvadNo-logs (Cure53)OngoingSweden
ProtonVPNNo-logs (KPMG)2025Switzerland
CyberGhostNo-logs (QSCert)2012Romania

TunnelBear’s position here is middling. It has an audit, which puts it ahead of providers with no third-party review at all, but the audit is old, narrow in scope, and hasn’t been repeated. Compare that to NordVPN’s six no-logs-specific audits since 2018, and the gap in verification depth is significant.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

What TunnelBear does well despite the gaps

None of this means TunnelBear is untrustworthy. It has never been implicated in a data breach or a documented case of handing over user logs to authorities, and its transparency about what limited data it does collect is more forthright than many competitors. TunnelBear also publishes an annual transparency report detailing government data requests, which is a practice worth crediting even without a recent no-logs audit backing it up.

For casual, low-risk use, browsing on public WiFi, keeping ISP tracking out of the picture, TunnelBear’s privacy posture is adequate. For anyone with a genuine reason to fear government or legal scrutiny, the combination of an outdated audit and Five Eyes jurisdiction makes it a weaker choice than Mullvad or ProtonVPN.

Get NordVPN

Bottom line

TunnelBear's stated no-logs policy hasn't been contradicted by any known breach, but its only audit is a narrow, seven-year-old security review, not a dedicated no-logs verification. Combined with Five Eyes jurisdiction, that makes TunnelBear fine for casual privacy needs but not the strongest pick for anyone facing real legal or government risk. For that level of protection, look at Mullvad or ProtonVPN instead.

Keep reading: TunnelBear Review 2026: Cute Bear, Serious Gaps and Best VPN for Privacy in 2026.