The Broken Promise at the Heart of “No-Logs” Marketing
Almost every VPN homepage carries some version of the same pledge: “we keep zero logs.” It’s the single most repeated claim in the industry — and one of the least verified. Below are three documented cases where a provider’s real-world behavior didn’t match its marketing, plus how to tell the difference between a provider that’s actually been tested and one that’s just saying the right words.
Case File #1: PureVPN and the Ryan Lin Cyberstalking Investigation (2017)
In 2017, the FBI investigated Ryan Lin, a Massachusetts man accused of a months-long cyberstalking and harassment campaign against a former roommate. Lin had routed his activity through PureVPN, whose privacy policy at the time claimed the service didn’t keep logs that could identify a user’s activity. Court documents showed otherwise: PureVPN handed federal investigators connection timestamps and session data that, combined with other evidence, tied Lin’s home IP address to the VPN sessions used in the harassment. PureVPN hadn’t handed over browsing history — but the connection metadata alone was enough to unmask him, directly contradicting the plain-language “no logs” promise on its own marketing pages at the time.
Case File #2: IPVanish and the Vincent Gevertz Case (2016)
The same year, IPVanish’s then-parent company (Highwinds Network Group) provided connection logs to Homeland Security investigators in a child-exploitation case involving a user named Vincent Gevertz, despite IPVanish’s public claim of a strict “we don’t keep logs. Period.” policy. It’s worth noting IPVanish changed ownership in 2019 (now under StackPath/Ziff Davis) and has since published third-party audit claims — but the 2016 incident remains the textbook example of why a marketing page is not proof, and why “who owned the company when the promise was tested” matters.
Case File #3: UFO VPN’s 894GB Leak (2020)
UFO VPN advertised a “strict no-logs policy” with anonymized data. In July 2020, security researchers found an unsecured Elasticsearch database exposing roughly 894GB of records — over 20 million log entries per day, including plaintext account passwords, VPN session tokens, connection timestamps, and device/IP information. The data was anything but anonymous. The exposed database resurfaced a second time later that month before being wiped by an automated “Meow” bot attack. It took UFO VPN roughly two weeks to close the leak.
What “No Logs” Actually Means — Three Kinds of Logs
- Usage logs — websites visited, DNS queries, files downloaded. This is what most “no-logs” claims technically refer to.
- Connection logs — timestamps, source IP, bandwidth used, session duration. This is the category that unmasked both PureVPN’s and IPVanish’s users, and it’s frequently retained even by providers with a “no-logs” badge.
- Account/billing logs — email, payment method. Necessary for the business to function, but a weak link if it can be correlated with connection timestamps.
How to Vet a No-Logs Claim Before You Trust It
- Independent audit. Has a named firm (PwC, Deloitte, KPMG, Cure53) actually reviewed the server infrastructure, not just read the privacy policy?
- Court-tested. Has the provider ever been subpoenaed and had nothing to hand over? That’s a far stronger signal than an audit.
- Jurisdiction. Is the company based outside the 5/9/14-Eyes intelligence-sharing alliances?
- RAM-only servers. Diskless infrastructure that wipes on reboot makes long-term log retention structurally harder, not just a policy choice.
Verdict
“No logs” is a marketing sentence until it’s been tested by a subpoena or a breach. Providers with a genuine track record of surviving both — audited by an independent firm and confirmed to have nothing to produce when legally compelled — deserve more trust than ones simply repeating the phrase. Read the actual audit report, not just the press release summarizing it, and check the date: a 2019 audit tells you nothing about a provider’s infrastructure today.
FAQ
Does a “no-logs” claim mean a VPN can’t identify me at all?
No. Even providers with a genuine no-usage-logs policy can often still see your account’s payment method and, if they retain connection timestamps, correlate that with an ISP subpoena for your home IP’s activity at that timestamp.
Are PureVPN and IPVanish still bad choices today?
Not necessarily — both have since published audit claims and, in IPVanish’s case, changed ownership. But past behavior under legal pressure is a data point worth weighing against current marketing.
What’s the single best signal a VPN’s no-logs claim is real?
A documented case where the provider was legally compelled to produce logs and had nothing to hand over. That’s rarer and more valuable than any audit.
Sources: TorrentFreak — PureVPN Logs Helped FBI Net Alleged Cyberstalker, Comparitech — UFO VPN Data Exposure, BetaNews — UFO VPN Data Leak.
