Skip to content

No-logs VPN: what it actually means.

A no-logs VPN is one that claims not to record what you do through it — and taken literally, the claim is almost never true, because any service with accounts, billing, or a free tier has to keep something. The phrase flattens four different kinds of "logs" into one slogan, and the honest question is never logs-or-no-logs but: which categories does this provider keep, and what proof exists beyond its own marketing? This page separates the categories, walks through the three real proofs, and then applies the same standard to us — including the parts where we come up short.

Published 2026-07-20 by Phantom VPN. We sell a VPN, and this page will still tell you we keep operational records and have no audit to wave at you. That is the point of it.

"Logs" is four different things.

Every argument about VPN logging is really an argument about which of these four a provider keeps. The slogan hides the distinction; the privacy policy, read carefully, usually reveals it.

Activity logs (traffic logs)
The sites you visit, the things you download, the content of your traffic, your DNS lookups. This is what people fear, and it is the thing every "no-logs" claim is really about. A VPN that keeps these can reconstruct your browsing.
Connection logs (metadata)
When you connected, for how long, from which IP, to which server, how much data moved. Not your browsing — but enough, in combination with timestamps from elsewhere, to matter. Many "no-logs" providers keep some of this and say so in paragraph nine.
Operational and account data
Your email, your subscription state, aggregate counters that keep a free tier from being farmed. Almost no service can run without some of this. A provider claiming to keep literally nothing while running accounts and billing is describing an impossibility.
Crash and diagnostic data
App crashes, error reports, performance telemetry. Often collected by third-party SDKs the marketing page never mentions. Worth checking separately, because it lives outside the tunnel entirely.

When a provider says "no logs", it almost always means the first category, sometimes the second, and essentially never the third. That is not automatically dishonest — but a page that lets you believe "nothing at all" while its policy says otherwise is telling you how it treats precision generally.

Three ways the claim can actually be proven.

A logging policy is a sentence on a website. It becomes evidence only one of three ways, and each way has a limit its advocates tend to skip.

Proof 1: an independent audit

A firm is paid to inspect servers and configuration and attest that no activity logging was found. Genuinely valuable, and the mainstream providers who commission them deserve the credit.

Its limit: an audit is a photograph, not a promise. It describes the systems on the days the auditors looked. A policy, or a server, can change the week after the report is published, and most audits are scoped to samples of a fleet, not all of it.

Proof 2: a court test

A subpoena or seizure happens, the provider produces nothing useful, and the court record shows it. This is the strongest evidence a policy-based claim can ever get, because it was involuntary.

Its limit: it is rare, jurisdiction-specific, and always about the past. It proves what was held on one date in one legal system. You cannot order one up, and absence of a court test proves nothing either way.

Proof 3: architecture

The service is built so the data never reaches the operator at all. Not "we promise not to look" but "it does not pass through us". What you never receive, you cannot log, leak, sell, or be compelled to produce.

Its limit: architecture only covers the paths it removes. It says nothing about the account layer, and it moves trust to whoever is at the exit instead. It is the strongest proof for exactly the data it covers, and mute about everything else.

The three are not rivals; the strongest position a provider can hold is all of them at once. But they differ in kind: audits and court tests attest that a policy was honoured, while architecture removes the need for the policy. Data that never arrives does not depend on anyone's continued good behaviour.

Where Phantom VPN stands, exactly.

We do not call ourselves a no-logs VPN, because for us the phrase would not be true. Our claim is narrower and checkable: we never log your browsing, your DNS queries, or the content of your traffic — because the WireGuard tunnel runs directly between your device and an independent Sentinel node, and there is no central server of ours in the path. That is the third proof, architecture. It covers your traffic. It does not cover your account, so here is the account side too, unabridged.

What we structurally cannot see

  • The sites you visit — your traffic goes device to node and never enters our systems.
  • Your DNS queries — resolved inside the tunnel by Cloudflare, not by us.
  • The content of your traffic — encrypted with a key whose private half never leaves your device.

What we do keep, plainly

  • Connect and disconnect events — the free tier is metered per minute, so we record when sessions start and stop.
  • Which node you used, and when — this is how nodes get ranked by health and routed around when they fail.
  • Minutes used — measured against the 60-minutes-per-ad free tier and its 300-minute daily cap.
  • The email on your account, and your last login — signing in is required, so accounts are not anonymous.

The proofs we do not have: no independent third-party audit yet, and no court test. We are not going to imply either. What you can verify today is the architecture — the node registry is public on sentinelhub-2, and the app shows you the node you are connected to.

The trust that remains: node operators are independent strangers, and your account is tied to an email because sign-in is required. Architectural no-traffic-logs is not anonymity, and we would rather you leave this page knowing that than believing a slogan.

The full data inventory, item by item

How to read any "no-logs" claim in two minutes.

Find the inventory, not the slogan

Skip the homepage and open the privacy policy. Look for a concrete list of what is collected. A precise provider enumerates; a vague one repeats the slogan in longer sentences.

Check the metadata clause

Search the policy for "timestamp", "bandwidth", "session" and "IP address". This is where connection metadata lives, and where "no logs" quietly becomes "some logs" in most policies.

Ask what proof exists

An audit: read its date and scope, not just its existence. A court test: read the actual record. Architecture: ask what data physically reaches the operator. No proof at all is an answer too — it means you are trusting a sentence.

Distrust perfection

"Zero logs, complete anonymity, untraceable" is a sentence written by marketing, not engineering. Services that run accounts keep something. The trustworthy ones tell you what.

No-logs questions, answered straight

What does "no-logs VPN" actually mean?

In marketing, it means the provider claims not to record your browsing activity. The phrase is slippery because "logs" covers four different things: activity logs (the sites you visit), connection metadata (when and from where you connected), operational account data (email, billing, usage counters), and diagnostics. Almost every service with accounts keeps something from the last two categories, so a literal reading of "no logs" is almost never true. The meaningful question is never "logs or no logs" — it is which categories are kept, and what proof exists.

Is any VPN truly no-logs?

Truly zero-data services are close to nonexistent, because accounts, billing, and abuse prevention all require keeping something. What does exist: providers whose activity-logging claims have survived independent audits or court tests, and architectures where traffic never reaches the operator at all, so there is nothing to log. Treat "100% no logs, total anonymity" on a marketing page as a red flag rather than a reassurance — precise services publish an inventory instead of a slogan.

How can a VPN prove it does not log?

Three ways, in ascending strength. An independent audit: a firm inspects the systems and attests no activity logging was found — valuable, but a snapshot of the days it covered. A court test: a legal demand produced nothing useful and the record shows it — the strongest evidence for a policy claim, but rare and always retrospective. Architecture: the service is built so the data never reaches the operator, which removes the need to trust the policy at all — but only for the data paths it actually removes.

Is Phantom VPN a no-logs VPN?

We do not use that phrase, because for us it would not be literally true, and it is rarely true for anyone who says it. What is true: we never log your browsing, your DNS queries, or the content of your traffic, because the encrypted tunnel runs directly between your device and an independent node and never passes through our systems. We do keep operational data: connect and disconnect events, which node and when, minutes used, and the email on your account. Both lists are published in full on our privacy page.

Has Phantom VPN been independently audited?

No. Phantom VPN has not undergone an independent third-party audit, and it has no court test to point to either. We say that plainly rather than borrowing the credibility of proofs we do not have. Our claim rests on the third proof, architecture: your traffic never transits our infrastructure, so browsing data is not something we could produce. For the operational data we do hold, you have our published inventory and our word — which is exactly why we keep the inventory short and public.

What could Phantom VPN hand over if legally compelled?

The operational list and nothing beyond it: the email on the account, last login, connect and disconnect events, which node and when, minutes used, and subscription state. We could not hand over browsing history or DNS queries, because we are not in the traffic path and never receive them. We could not hand over your keys, because the private key never leaves your device. And there is no server fleet of ours to seize, because we do not own any nodes.

Do the node operators log?

We cannot promise they do not, and honesty requires saying so. Sentinel nodes are run by independent operators we do not own or vet — the network is permissionless. A node is an exit point, so like every VPN server it can see where the traffic it carries goes, though HTTPS keeps the contents unreadable. The structural difference from a central provider is scope: an operator sees only the sessions it carried, and no party — us included — has a view across the whole network.

Fewer promises. More architecture.

Phantom VPN keeps its claims small enough to check: a direct tunnel, a public node registry, and a data inventory with nothing under it. Free to start.