What a Provider Still Holds After You Cancel

Cancelling a subscription stops payments. Deleting an account is a different action, and even a completed deletion leaves categories of data behind by design. Some of what survives is required by law, some is required for the service to keep functioning for everyone else, and some survives because deletion from live systems propagates through backups on a schedule rather than instantly. None of that is sinister, and all of it is worth knowing before you assume that walking away closes the file.

The question is not whether anything remains. Something always remains. The question is which categories, for how long, and whether the provider’s own documents say so.

Three different actions people conflate

Turning off auto-renewal. The account keeps existing and keeps whatever it held; you have only declined the next charge.

Cancelling the subscription. Access ends at the term boundary. The account record, the billing history, and any support history normally persist, because the relationship might resume.

Requesting deletion. A separate request, often through a separate channel, that triggers whatever the provider’s retention policy actually says. This is the only one of the three that is about data at all.

If you want the third, do the third explicitly. A cancelled subscription is not a deletion request, and no provider treats it as one.

What survives a genuine deletion, and why

Transaction and tax records. Companies are required to retain evidence of what they charged and to whom, for a statutory period that varies by jurisdiction and by the kind of company. A deletion clause cannot override a bookkeeping obligation, and any that claimed to would be describing something the company is not permitted to do.

The payment processor’s own record. A separate company with its own retention, its own obligations, and no relationship with you. Deleting your VPN account does nothing there — one instance of the general problem in the parties a no-logs promise cannot speak for.

Abuse and fraud controls. If an account was terminated for abuse and the provider forgets it entirely, the control does not work. Every consumer service keeps some durable record for this purpose, usually a minimal one: an identifier, a reason, a date.

Support conversations. Frequently in a third-party ticketing system, frequently retained on its own schedule, and frequently containing more operational detail about your connections than anything else the provider holds.

Backups, until they rotate. Deletion from production systems is not deletion from a backup taken last week. A responsible policy says how long the rotation takes; the data is gone when the last copy expires, not when the confirmation email arrives.

Aggregate and derived figures. Counts, capacity statistics, and totals. Most policies treat these as no longer personal, which is usually reasonable and is worth reading closely when the aggregation is coarse.

Anything a third party already received. Which is why the whole subject is downstream of what turning on a VPN today does not undo: deletion is as forward-looking as the tunnel was.

There is also a category that does not survive, for a structural reason worth naming: data that was never created. A provider whose exit servers genuinely do not record connection timestamps has nothing to delete when you ask, and no ability to produce it later. That is the practical value of the design distinction in cannot versus will not — it is the difference between a deletion promise and a deletion capability.

How to read the deletion clause

Find it before you subscribe rather than after you leave. It sits near the retention section, and the method for the surrounding document is in how to read a VPN privacy policy.

Who has to act. Automatic on termination, or only on request? If on request, where is the request made, and is there a form or an address that actually works?

What triggers the clock. End of the paid term, the deletion request, or the last login? These can be years apart.

The exceptions list. This is the real policy. “We delete your data on request, except where retention is required by law or necessary for legitimate business purposes” is a sentence whose second half swallows the first unless the legitimate purposes are enumerated. Enumerated exceptions are a good sign; an open-ended category is not a lie, but it is not a commitment either.

The timeline, including backups. A stated number of days, with backup rotation mentioned separately, indicates someone who has actually implemented this.

Whether it reaches sub-processors. The clause should say whether deletion is passed on to processors, and processors are where the support history and the telemetry live.

Whether you get confirmation. A written confirmation is not proof, but its absence means you cannot even establish that the request was received.

Doing it in a sensible order

  1. Read the retention and deletion clauses, so you know what you are asking for.
  2. Cancel or disable renewal, and note the term end date.
  3. Make the deletion request in writing through the documented channel, and keep a copy with the date.
  4. If your jurisdiction provides a statutory erasure or access right, that route is usually more reliably staffed than the support queue, because it carries deadlines.
  5. Remove the payment authorisation at your end as well as theirs.
  6. On the device, uninstall properly: remove any system profile or virtual adapter the client installed, and check that a leftover always-on or kill-switch setting is not silently blocking traffic afterwards — a stale one behaves exactly like a broken internet connection, which is the same failure surface as leaks and kill switches.

What this means for your threat model

For most readers the residue is billing records at a company that has billing records for everyone, and the consequence is close to nil. The category that matters is the identity link: the association between a person who paid and an account that connected at particular times, which is the floor established in what data a VPN must hold. Cancelling does not dissolve that link, and deletion dissolves only the parts a company is both willing and permitted to drop.

If your concern is that someone may one day ask a provider what it holds about you, the useful move was choosing an architecture that holds little in the first place. Cancellation is not a privacy measure. It is the end of a commercial relationship, and the data question is a separate one you have to ask on purpose.