Which Words Do the Work in a VPN Logging Policy
A VPN’s logging policy is a document, and the useful skill is reading it as one. Almost every provider says something reassuring about logs; the difference between them lies in a handful of words that either commit the company to a checkable practice or leave it free to do whatever it does. This is about which words those are, and how to tell a sentence with edges from a sentence that only has a tone.
The heading promises more than the sentence underneath
Start by ignoring headings and reading only sentences. Documents in this category are frequently organised under confident section titles — “We keep no logs”, “Your privacy is absolute” — followed by text that qualifies the title into something much smaller.
The mechanical version of the check is to underline the subject and the verb of each sentence and ask what would count as a breach of it. “We do not log the websites you visit” has a discoverable failure condition. “We are committed to your privacy” has none: there is no state of the world in which the company has broken it.
The other habit worth having is reading to the end of the sentence. A promise followed by “except”, “unless”, “other than”, “save where”, or “as required” is a smaller promise, and the exception is usually the part that describes normal operation.
What “anonymised” and “aggregated” actually do
These two words appear at the moment a policy needs to say it keeps something while sounding like it does not, and they are worth understanding precisely because they are not lies.
Aggregated means combined across users. Total bandwidth per server per hour is aggregated; it genuinely says nothing about you. But aggregation is a property of the output, not of the collection. To produce an hourly total, the service handled the individual events that were summed. A policy saying it retains only aggregate figures is describing what survives, and the interesting question is what happened to the inputs and when.
Anonymised is a claim that identifiers were removed, and it depends entirely on which ones. A record stripped of your account name but still carrying a timestamp, a source address, and a duration is not anonymous in any useful sense — it is a record that requires one extra join to be about you. Where a policy uses the word, look for a definition of what was removed. A document that specifies “the final octet of the address is discarded” is telling you something; one that says “anonymised” and stops has used a word that sets its own meaning.
Related, and equally slippery: “personal data” and “personally identifiable information” are defined terms. When a policy promises not to store them, it is promising not to store whatever it has defined them as, and that definition is elsewhere in the same document.
Hedges that leave the company where it started
A few formulations recur across the whole market and are worth recognising on sight.
“As long as necessary for the purposes described” is a retention period with no number in it. So is “in accordance with applicable law”, which is true of every company whether it says so or not.
“We may collect” describes a permission the company is reserving, not a practice it is admitting. It is not evidence of collection, and it is not evidence against it either — which is exactly why it is useful drafting.
“Industry-standard” attached to encryption, security, or practice is a comparison to an unnamed baseline.
“We do not sell your data” is narrower than it sounds, because sharing, licensing, and disclosing to group companies are not selling.
And the one worth spotting most: a policy that describes what the tunnel does not log, while saying nothing about the client application on your device or the website you bought the subscription on. Those are three different systems, and a promise about one is silent on the others.
The claims that touch plumbing you can observe
A small number of statements in these documents are about mechanics you can check yourself, and they are where a policy becomes falsifiable rather than merely well-written.
If it says name resolution is handled by the provider’s own resolvers inside the tunnel, that is testable — the method is in how to check for a VPN leak, and the significance of the answer is in who runs your DNS resolver.
If it says traffic is blocked when the connection drops, you can disconnect deliberately and watch.
If it says the service enforces a device limit, then current session state must exist somewhere by definition, and a policy that acknowledges this is being straight with you while one that implies zero knowledge of live sessions is not.
Where a document’s testable claims hold up, its untestable ones deserve somewhat more credit. That is the only leverage a reader has, and it is worth using.
Silence is a finding, not a gap
The absence of a subject is often the most informative thing in the file. Things whose absence is worth noting: any retention period expressed in units of time; any mention of the source address you connect from; any mention of telemetry or crash reporting inside the client; any mention of what happens to data if the company is sold; any last-updated date at all.
A document with no date and no version history cannot be compared with its earlier self, which means nobody can tell whether a commitment was quietly narrowed. Providers that publish previous versions are rare, and the choice costs them flexibility, which is precisely why it is a signal.
Phrasings that would actually constrain a company
If you want to know what strong drafting looks like, it reads roughly like this: a named category, a named period, and a stated destination. “Session records are held in memory only and are not written to persistent storage.” “Support correspondence is deleted after a stated number of months.” “Billing records are retained because tax rules require it, for a stated period, and are separate from service records.”
Specificity is the signal, and it is uncomfortable for the company writing it, which is the point. Then compare what the document says against the floor of what any such service must hold — the argument in what a no-logs VPN claim covers — and against the scope of any outside examination, since an examination that never looked at the retention claim does not support it. That distinction is in what gets examined when a VPN says it was audited.