“No logs” and “no data collected” are not the same promise, and providers rarely go out of their way to explain the gap. A VPN can be independently audited for its no-logs policy, meaning it doesn’t record what you browse or which server you connect to and when, while its app still gathers telemetry: crash reports, feature usage, device type, app version, and diagnostic data that never shows up in a no-logs audit’s scope at all.

Neither of those is necessarily dishonest. But the distinction matters if you’re choosing a VPN specifically to minimize your data footprint, and most marketing pages don’t draw the line clearly enough for you to know what you’re actually agreeing to.

What “no logs” technically covers

An audited no-logs policy, the kind NordVPN, Surfshark and ProtonVPN have all paid independent firms to verify, addresses a specific claim: the provider doesn’t record your browsing activity, connection timestamps, source IP address, or bandwidth used in a way that could be tied back to you individually. That’s the promise these audits are scoped to test, and it’s a real, meaningful thing to have verified by an outside firm rather than taken on faith.

What it typically doesn’t cover is the app itself. Crash reporting frameworks, feature-usage analytics, and diagnostic pings to help a support team troubleshoot a connection problem all live in a different bucket, and providers have historically had far more discretion over what counts as “telemetry” than what counts as a “log.”

Why telemetry exists at all

Providers have legitimate reasons to collect some of this. Aggregate server load and connection success rates help them decide where to add capacity. Anonymized crash reports help fix bugs before they hit thousands of users. None of that requires knowing who you are or what you browsed.

The problem is verification. A provider that says “we only collect anonymized, aggregate telemetry” is making a claim about its own internal engineering practices that’s much harder for an outside auditor to fully confirm than a straightforward “do you log connections” question. Metadata that’s supposedly anonymized can sometimes still be correlated back to an individual account if it’s detailed enough, and most no-logs audits aren’t scoped to test that specific risk.

What Windscribe’s own policy admits

Windscribe is a useful example precisely because it’s unusually direct about this. Its own terms of service acknowledge that it does log certain data, and it hasn’t commissioned an independent no-logs audit the way NordVPN, Surfshark, Mullvad and ProtonVPN have, a gap reflected in its 2/5 no-logs score in our comparison data. Windscribe still publishes transparency reports and open-sources its apps, which are real trust signals, but it’s not making the same “zero logs, independently verified” claim its bigger competitors are, and it doesn’t pretend otherwise.

Which providers minimize telemetry, and how they prove it

Mullvad is the clearest standard-setter here. It scores 4/5 in our no-logs data with an independent Cure53 audit, doesn’t require an account beyond a randomly generated number, and accepts cash by mail specifically so payment details never touch your identity. Its published privacy approach is to collect as little as architecturally possible rather than collect broadly and promise to protect it.

NordVPN and Surfshark both hold repeated PwC and Cure53 audits respectively, scoring 5/5 in our no-logs data, and both have moved to fully RAM-only server infrastructure, meaning data doesn’t persist to disk even temporarily. ProtonVPN, audited by KPMG and based in Switzerland, scores 5/5 as well and publishes regular transparency reports detailing exactly what legal requests it receives and how it responds.

Private Internet Access is the unusual case worth naming: its no-logs claim has actually been tested in court, where it was demonstrated in legal proceedings that it had no logs to hand over, a stronger real-world proof than most audits can offer, even though PIA itself hasn’t published as many formal third-party audits as the others.

RAM-only servers, and why they matter for this specific question

A RAM-only server wipes its contents on every reboot, since nothing is written to a persistent disk in the first place. NordVPN, Surfshark, Mullvad, ProtonVPN, CyberGhost and Private Internet Access have all fully transitioned to RAM-only infrastructure in our data, each scoring 5/5. This matters directly for the telemetry question: even if a server temporarily logs diagnostic data for troubleshooting, RAM-only infrastructure means that data can’t accumulate indefinitely or survive a server seizure the way disk-based logs could.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

A real-world example of how bad this can get

The risk isn’t hypothetical. Security researchers previously traced a group of free VPN and ad-blocker apps, including ones marketed as privacy tools, back to a single analytics company whose actual business was harvesting app usage data to sell trend estimates to other businesses, a case reported by outlets including AOL. Those apps weren’t lying about “no browsing logs” in a narrow technical sense; the harvesting happened through broader app analytics and device data that a simple no-logs claim never covered in the first place. It’s the clearest illustration of why the marketing headline and the actual data collection practice can diverge so far apart while both being, strictly speaking, true.

Apple has since tightened its App Store guidelines specifically to stop apps from collecting data about which other apps are installed on a device for analytics or advertising purposes, closing off one of the more common techniques this kind of app used. That’s a meaningful platform-level fix, but it doesn’t retroactively audit every VPN already on the market, which is why checking a specific provider’s own disclosures still matters more than trusting app store vetting alone.

How to actually check before you sign up

Read the privacy policy’s data collection section specifically, not just the marketing page’s “no logs” headline; most providers separate the two, and the data collection section is where telemetry, analytics SDKs and crash reporting tools get disclosed if they’re disclosed at all. Search for the provider’s name alongside “data collection” or “telemetry” rather than “no logs,” since that’s the phrasing more likely to surface independent reporting on what an app actually sends home.

Check whether the provider has been independently audited, and specifically what the audit’s scope covered. An audit that reviewed server logs but not app telemetry hasn’t answered the question this article is about, even though it’s genuinely reassuring on the narrower point it did check. Our guide to verifying a no-logs policy covers what actually counts as proof versus marketing language.

Look at whether the company publishes a warrant canary or regular transparency report, since providers willing to disclose how many legal requests they’ve received and how they responded tend to be more forthcoming about telemetry practices too. Our warrant canary explainer covers how to read one and what it can and can’t tell you.

The bigger picture: a VPN was never going to stop all data collection

Even a VPN with genuinely zero telemetry doesn’t stop your operating system, your browser, or the apps you use inside the tunnel from collecting their own data about you. A VPN protects your traffic in transit and hides your IP address from your network operator and the sites you visit; it was never designed to be a complete answer to every form of data collection happening on your device. Treating “telemetry-light VPN” as one part of a broader privacy setup, rather than a single fix for everything, is the more realistic way to think about it.

Our verdict

A "no-logs" audit and a genuinely low-telemetry app are related but separate claims, and most marketing blurs the two together. Mullvad, NordVPN, Surfshark and ProtonVPN back up both sides of that claim with real audits and RAM-only infrastructure. If a provider's privacy policy doesn't clearly separate connection logs from app telemetry, that vagueness is itself useful information, not a detail to skip past.

Keep reading: How to Verify a VPN’s No-Log Policy and VPN Warrant Canaries Explained.