It’s a fair question to ask before handing a company all your internet traffic: if a VPN genuinely doesn’t log what you do, and audits back that up, how does it actually make money? The honest answer is less mysterious than people expect, and understanding it is a decent way to judge whether a specific provider’s business actually lines up with its privacy claims.
The main answer: subscriptions, at real scale
Most legitimate VPN providers make the bulk of their revenue the boring, obvious way: monthly and annual subscription fees. NordVPN charges $68.85 a year, ProtonVPN’s paid tier runs $47.88 a year, Surfshark $59.76. Individually, these look like small numbers. Multiplied across millions of subscribers, which the larger providers genuinely have, this adds up to substantial, sustainable revenue without needing to touch a single byte of user data. This is the same business model as any subscription software company, Netflix included; the product is the service itself, not the data generated by using it.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Affiliate and referral programs
A large share of VPN sign-ups come through comparison sites, YouTube sponsorships and referral links, this site included. When you click an affiliate link and subscribe, the VPN provider pays the referring site a commission, funded by the subscription revenue described above, not by your data. This is worth being transparent about: it’s how sites like this one stay funded, and it’s a standard, disclosed part of how the whole industry sells subscriptions, similar to how a retailer pays a commission to a comparison shopping site.
Free tiers: a funnel, not a data farm
ProtonVPN and Windscribe both offer genuinely free tiers, not just trials, and the business logic is straightforward: a free tier lets people try the service, builds trust and brand awareness, and converts a percentage of free users into paid subscribers once they hit a data cap or want faster servers. This is a real, common freemium model used across software broadly, not unique to VPNs, and it doesn’t require monetizing user data to work, as long as the paid conversion rate is high enough to cover the cost of running free infrastructure.
Bundling and cross-selling
A lot of the industry has consolidated around bundled security products: a VPN sold alongside antivirus, a password manager, and identity monitoring, increasing the average revenue per customer without raising the price of any single component much. This is part of why ownership consolidation matters when you’re evaluating a provider, since a VPN owned by a larger security conglomerate may be one product line among several, priced to support cross-selling into the rest of that company’s suite rather than standing alone.
Enterprise and business products
Several consumer VPN brands also sell business-focused security products, network access tools sold to companies rather than individuals, often at a much higher price point per seat. This diversifies revenue beyond individual consumer subscriptions and is a genuinely large, separate market from the one this site mostly covers, but it’s worth knowing it exists as another legitimate income source that doesn’t touch consumer browsing data. It’s one more reason a VPN’s consumer pricing doesn’t need to fully cover its own infrastructure costs on its own.
Why selling logged data would actually be bad business
Beyond the ethical problem, selling user data is a poor long-term business strategy for a VPN specifically, because the entire product’s value proposition depends on trust, and that trust is now independently checked. An audited no-logs claim that turns out to be false doesn’t just generate bad press, it destroys the credibility an audit was supposed to establish, invites regulatory scrutiny, and hands competitors a permanent talking point. For a company with millions of paying subscribers, that risk dwarfs whatever a data broker would pay for browsing logs.
When it actually did happen
This isn’t a hypothetical risk. In 2015, the free VPN extension Hola was found to be selling users’ idle bandwidth through a sister company, Luminati, effectively turning free users’ connections into a commercial proxy network without clearly informing them, a scandal that did lasting damage to the brand’s reputation. In 2018 and 2019, Facebook’s Onavo Protect app, marketed as a VPN for privacy and marketed to install on your phone, was actually built to funnel usage data back to Facebook for competitive research; Apple removed it from the App Store for violating data-collection rules, and Facebook shut it down entirely in February 2019 after the backlash. Both cases involved free products with no independent audit, not paid, audited subscriptions, which is precisely the distinction worth paying attention to.
The difference between “no logs” and “no data at all”
Even a legitimately no-logs VPN typically still collects some non-identifying operational data: aggregate server load, crash reports, app performance metrics, the kind of telemetry any software company uses to keep a product running and improving. This is a different category entirely from logging which websites you visited or when, and reputable providers document exactly what falls into this bucket in their privacy policy and audit scope. If a policy is vague about the line between “we don’t log your activity” and “we collect zero data of any kind whatsoever,” that vagueness is worth reading closely, since the second claim is rarely fully true for any functioning app, free or paid.
How to sanity-check a provider’s business model yourself
A few questions cut through most of the ambiguity quickly. Is the pricing public and does it roughly match what similar audited providers charge, or is the service suspiciously cheaper with no clear explanation? Has the no-logs claim actually been audited by a named, independent firm, or is it just a statement in the privacy policy with nothing backing it up? Is the company’s ownership public and traceable, or deliberately obscured behind shell structures with no clear parent entity? None of these questions require technical expertise to check, and our comparison table tracks all three across every provider we review specifically so you don’t have to dig through each company’s fine print yourself.
What this means for choosing a provider
The presence of a sustainable, transparent business model, subscriptions at real scale, disclosed affiliate programs, legitimate free-tier conversion, is a reasonable positive signal alongside an independent audit, not a replacement for one. A provider that’s cagey about how it actually makes money, offers a permanently free unlimited service with no visible funding source, or has a documented history like Hola’s or Onavo’s, deserves more scrutiny than one whose revenue model is straightforward and matches what it charges you directly. None of this requires taking a company’s word for it either; audit reports, ownership records and pricing history are all things you can check yourself before trusting a provider with your traffic.
Legitimate no-logs VPNs make money the same way most software companies do: subscriptions, referrals and bundling. Providers like NordVPN and ProtonVPN back this up with independent audits rather than asking you to take the business model on faith alone.
Keep reading: How to Verify a VPN’s No-Log Policy: What Actually Counts as Proof and Who Really Owns Your VPN? The Consolidation Map in 2026.