FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

Do VPNs Really Keep No Logs? The Signup Form Told Me More Than the Slogan

The VPN’s homepage promised strict no logs in large letters. The checkout page underneath asked for my everyday email address, card details and a password. I was in Manchester, trying to open an age-restricted site without turning a private browsing session into another permanent identity record. I entered my work email by habit, paid for one month and connected. The page loaded, but the receipt immediately appeared in the same inbox that held my real name, travel bookings and client messages. The VPN might not have been recording the page I visited. It still knew exactly who had purchased the connection.

That distinction has become harder to ignore in the UK.

After stronger age-assurance requirements took effect in July 2025, daily VPN use rose sharply. Government research found that privacy and data protection—not only access—were important reasons adults were turning to VPNs. A 2026 study of public reactions found the same concern: people were worried about how much identity data sensitive browsing could gather around them.

I had installed a VPN to reduce that trail.

Instead, I had created another named account beside it.

The short answer

For a sensitive session, that difference mattered more to me than another page explaining internal separation.

“No Logs” Did Not Mean “No Data”

I opened the provider’s privacy policy and searched for the word log.

The service said it did not retain browsing history, DNS requests or records connecting customers to destination websites.

Farther down, it described the information needed to operate the subscription: email address, payment details, account status and support communications.

Both statements could be true.

A VPN may avoid recording what I do through its servers while still keeping information about who bought the service. Major providers make that distinction openly. NordVPN, for example, says it does not keep VPN activity logs but does retain account and billing information.

The large NO LOGS badge was answering only one question.

I had three:

What does the provider record while I am connected?

What identity does it collect before I connect?

How much trust is required to keep those two things separate?

The first is about activity.

The second is about the account.

The third is the part most marketing pages leave to the privacy policy.

The Audit Proved Something Important

My established provider had a genuine strength: years of public history and independent privacy reviews.

That evidence mattered.

A serious audit can inspect whether a provider stores browsing activity or connection records that could link a user to a particular VPN session. Proton VPN’s 2026 audit found no persistent records capable of associating a specific user with activity through the reviewed servers. Its transparency reporting also showed that legal demands based on server addresses and timestamps did not produce identifying VPN records.

That is much stronger than simply printing “no logs” on a homepage.

It shows that a provider can genuinely lack the records someone may request later.

But the audit did not erase the account I had created.

The provider still had my email address. Its payment processor had handled my card. My inbox contained the subscription receipt, renewal date and customer reference.

None of that suggested the provider was secretly recording my browsing. It revealed something simpler: no activity logs and no personal information are not the same promise.

I had been treating them as though they were.

Creating a Throwaway Identity Became Another Chore

I considered starting again.

I created an email alias, opened a private browser window and looked for a payment method less connected to my ordinary card. Within ten minutes, a simple privacy tool had become a small identity-management project.

The alias needed recovery information.

The payment created its own transaction record.

The VPN still needed an account password and subscription identifier.

I could move those details away from my normal inbox, but I could not make them disappear.

A brief public discussion captured the same discomfort: users understood that “no logs” could refer to browsing activity, yet still questioned why a privacy service needed their normal email and payment identity.

That was enough to sharpen my concern.

I did not need a more elaborate disguise.

I needed the service to collect less in the first place.

The Smaller App Started Without an Account Form

I closed the checkout tabs and opened OnlydogVPN.

There was no conventional registration page asking me to create another email-and-password account for basic use. The app opened into situation-based options, so I chose the one for privacy-sensitive browsing and connected.

Then I checked the public IP address.

My home broadband address had been replaced by the VPN route.

I opened a fresh browser session, returned to the age-restricted site and completed its legitimate adult verification. The page loaded normally afterward.

The result was straightforward:

My internet provider no longer saw the destination directly.

The website received the VPN address instead of my home address.

The VPN connection did not require my work email, another password or a named customer profile.

Before relying on a promise about how carefully personal information would be separated, I had avoided supplying much of that information at all.

That was the comparison I had been missing.


Less Collection Was Easier to Trust

The larger provider’s model depended on separation.

Its account system knew who had paid.

Its VPN infrastructure was designed not to retain what that person did after connecting.

Independent audits gave that separation credibility.

The smaller app removed part of the problem before separation became necessary. Without a conventional email-and-password registration for basic use, there was less ordinary account identity sitting behind the connection.

I could not observe either provider’s live production logging systems, so I relied on published audits, privacy disclosures and the information each service requested during setup.

Of those signals, the signup screen was the easiest to verify personally.

The established provider told me it would keep my account identity apart from my VPN activity.

The smaller app did not ask for the same account identity in the first place.

For a sensitive session, that difference mattered more to me than another page explaining internal separation.

“No Logs” Needed a More Precise Meaning

The phrase became easier to understand once I stopped expecting it to mean “no data of any kind.”

There were three practical categories.

Browsing activity includes destination sites, DNS requests and traffic content. A no-logs VPN should not retain a history of them.

Connection records may include the original IP address, assigned VPN address, connection time and session duration. When stored together, those details can connect a person to a particular server at a particular moment.

Account information includes email addresses, payment records, subscription status and support messages. A provider may retain this information while truthfully saying it does not log VPN activity.

My established provider had strong evidence concerning the first two categories.

My discomfort came from the third.

That did not make its audits meaningless. It made my original question too broad.

I was no longer asking only whether a VPN remembered the websites I opened.

I was asking how much identity had to exist before I could use it.

The smaller app gave me the cleaner answer.

The Next Privacy Problem Appeared After the Page Loaded

Once the site was open, I noticed the app’s blocked-request counter increasing.

Advertising and tracking requests were being filtered as I browsed.

That did not prove anything about VPN server logs. The main problem had already been solved by the account-light connection.

The counter revealed a smaller problem around it.

A VPN can hide the destination from the local network and replace the public IP visible to a website. It does not automatically stop the website’s own trackers, cookies and advertising partners from gathering information inside the browser.

The rising counter showed that unnecessary requests were being stopped before they completed.

I had begun by trying to reduce what the VPN provider knew.

The counter reminded me that the VPN provider was not the only company trying to learn something from the session.

It was a useful secondary reason to leave the app installed.

The Shorter Public History Was the Trade-Off

The smaller service has a shorter public history, fewer independent reviews and less published audit evidence than the most established providers.

That limitation matters in an article about trust.

A mature provider with repeated audits and detailed transparency reports offers evidence that a newer service cannot reproduce overnight. I would not dismiss that record merely because its signup process requested an email address.

But audits are not the only form of evidence.

Collection choices matter too.

An audit can show that retained account information is not being connected to VPN activity.

An account-light design reduces the amount of retained identity that needs to be separated and protected.

The established provider offered stronger historical proof about its infrastructure.

The smaller app gave me a more private starting point for the session in front of me.

Those were different advantages. For this task, the second one was more valuable.

No Logs Can Be Real Without Meaning No Identity

By the time I closed the browser, I no longer thought every no-logs claim was dishonest.

Independent audits and transparency reports show that some providers genuinely avoid storing the records needed to reconstruct user activity. When someone arrives with a server address and timestamp, those providers may truly have nothing useful to connect to an individual session.

But no logs does not automatically mean:

No email address.

No payment record.

No subscription account.

No support history.

No personal data at all.

My established provider offered a mature, audited promise that my account would not become a browsing history.

The smaller app reduced the amount of identity I had to place behind that promise.

For sensitive browsing, that changed the decision.

The strongest no-logs policy may prove that a provider forgets what I do after I connect. The more useful privacy design begins by needing less information about me before I connect at all.

Questions this experience may leave you with

What was actually causing the problem?

For a sensitive session, that difference mattered more to me than another page explaining internal separation.

Why did the obvious fixes fail?

None of that suggested the provider was secretly recording my browsing. It revealed something simpler: no activity logs and no personal information are not the same promise.

What should you check first?

The strongest no-logs policy may prove that a provider forgets what I do after I connect. The more useful privacy design begins by needing less information about me before I connect at all.

What finally changed the result?

That did not prove anything about VPN server logs. The main problem had already been solved by the account-light connection.

What is worth remembering?

The smaller service has a shorter public history, fewer independent reviews and less published audit evidence than the most established providers.