Windscribe markets itself as a privacy-first VPN with a generous free tier, but its logging policy is more nuanced than the “no logs” tagline VPNs like to lean on. Unlike NordVPN, Surfshark, or ProtonVPN, Windscribe has not commissioned a single independent audit of its no-logs claims, and its own terms of service admit to collecting more than a strict no-logs provider would. Here’s what that means in practice.

What Windscribe actually says it collects

Windscribe’s privacy policy is more candid than most. It states plainly that it does not log traffic content, but it does log a limited set of technical data tied to your account: total bandwidth used (reset every 30 days, relevant to its free-tier data cap), and, for a short window, the timestamp of your last connection, used for troubleshooting and abuse prevention. Windscribe also runs Firewall/R.O.B.E.R.T., its DNS-based content and ad blocker, which by its nature has visibility into the domains you attempt to reach while it’s active.

None of this rises to the level of “keeping browsing logs” in the way a genuinely bad-faith VPN would, but it is meaningfully more data retention than Mullvad’s account-free model or ExpressVPN’s audited zero-log architecture.

The scorecard

In our test spreadsheet, Windscribe scores 2 out of 5 on audited no-logs policy, the lowest of the eight VPNs we track closely, against a 5/5 for NordVPN, Surfshark, ExpressVPN, and ProtonVPN, all of which have completed independent third-party audits (PwC, Cure53, PwC, and KPMG respectively). Windscribe’s own notes in our spreadsheet are direct: “they have a transparency report but no independent audit yet.”

ProviderAuditedAudit companyLogs claim in ToS
WindscribeNoNonePartial (bandwidth, last connection timestamp)
NordVPNYesPwCStrict no-logs
SurfsharkYesCure53Strict no-logs
ProtonVPNYesKPMGStrict no-logs
ExpressVPNYesPwCStrict no-logs

Jurisdiction matters here too

Windscribe is based in Canada, a Five Eyes intelligence-sharing member. That’s not disqualifying on its own (Private Internet Access is a US company and has proven in court it keeps no meaningful logs), but combined with the lack of an audit, it means you’re relying on Windscribe’s word rather than independently verified proof, in a jurisdiction that can legally compel data disclosure.

Does this actually matter for you?

For most everyday uses, streaming, general privacy from your ISP, public Wi-Fi protection, Windscribe’s data retention is unlikely to be the deciding factor. Bandwidth counters and connection timestamps are not the same as logging which sites you visited or what you did there. Windscribe has never been implicated in handing over meaningful user activity data to authorities.

But if your threat model specifically requires provable, audited no-logs behavior, journalism in hostile jurisdictions, activism, or anything where “trust us” isn’t good enough, Windscribe is not the strongest choice on the market right now. Mullvad (account-free, cash accepted, Cure53-audited) or ProtonVPN (KPMG-audited, Swiss jurisdiction) are better fits for that use case.

What Windscribe does not collect

To be precise about the boundaries: Windscribe states it does not log your IP address once connected, your browsing history, DNS queries outside of R.O.B.E.R.T.’s active blocking function, or connection timestamps beyond the short troubleshooting window mentioned above. It also supports port forwarding and static IPs as paid add-ons, features some stricter no-logs VPNs deliberately avoid because they can make individual users easier to fingerprint across sessions. That’s a real trade-off worth knowing about if anonymity, not just privacy, is the goal.

How to minimize your footprint on Windscribe

If you use Windscribe and want to reduce the data trail as much as the platform allows: pay with cryptocurrency instead of a card, since Windscribe accepts it and it breaks the billing-to-identity link most of these logging questions are really about. Turn off R.O.B.E.R.T. if you don’t need the DNS blocking, since it’s the one feature that necessarily inspects domain requests locally on Windscribe’s resolver. And avoid the static IP add-on if session-to-session anonymity matters more than convenience, a static IP is by definition a stable identifier tied to your account.

Comparing this to other providers we’ve audited

We’ve run this same check against every VPN in our top eight. NordVPN, Surfshark, ExpressVPN, ProtonVPN, and Mullvad all come back clean with independent audits behind their no-logs claims. Private Internet Access has no formal third-party audit either, but has the unusual distinction of having its no-logs claim tested and confirmed in actual court proceedings, twice, when authorities sought data PIA didn’t have to hand over. Windscribe sits in a middle tier: transparent about what little it does collect, but without either an audit or a court test to back it up.

How Windscribe compares on everything else

It’s worth being fair to Windscribe here: a 2/5 privacy audit score sits inside an otherwise competitive 3.82/5 overall rating. Speed scores a full 5/5, its free tier (10GB/month, unlimited devices) remains one of the best in the industry, and its R.O.B.E.R.T. blocker is a genuinely useful extra most competitors don’t offer. The gap is specifically in third-party verification of its logging claims, not in the product as a whole.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Should this change which VPN you buy?

Not automatically. Windscribe remains a genuinely good value pick, particularly its free tier, and its logging practices are meaningfully more limited than the ad-supported free VPNs that actually do sell browsing data. The honest framing is that Windscribe asks you to trust its word, while five of the eight providers we track ask you to trust an independent auditor’s word instead. For general privacy and streaming use, that distinction rarely matters day to day. For high-stakes use cases, it’s the whole ballgame, and it’s worth paying the few extra dollars a month for a provider that’s already done the work of proving its claims.

What an audit would actually prove

An independent no-logs audit means a security firm gets access to Windscribe’s server infrastructure, source code, and internal processes, and verifies that what the company claims about data retention matches what its systems actually do. Windscribe has not commissioned one. That doesn’t mean the company is lying about its practices; several long-standing VPNs went years without an audit before eventually completing one. It means that, as of today, there’s no independent confirmation, only Windscribe’s own transparency report and terms of service.

Our verdict

Windscribe logs less than most free VPNs and is upfront about what it does collect, but it remains the only major provider in our top eight without an independent no-logs audit. Fine for everyday privacy and streaming. Not the pick if your threat model demands audited, provable no-logs behavior, go with Mullvad or ProtonVPN instead.

Curious how other providers stack up? Read our full Windscribe review, our head-to-head on Windscribe vs ProtonVPN, or our guide on how to verify a VPN’s no-logs claims yourself.