The Parties a No-Logs Promise Cannot Speak For
A no-logs claim is a statement one company makes about its own systems, and a VPN service is assembled from several companies’ systems. Every additional party in the arrangement keeps records for its own reasons — billing, abuse handling, capacity planning, legal obligation — and none of them signed the promise you read. This is not an accusation. It is the difference between the scope of a sentence and the scope of a service, and noticing it is most of what separates reading a policy from believing one.
The useful exercise is to list the parties who must exist for the service to work, then ask what each one necessarily knows.
The parties who are always there
The hosting company. Unless a provider owns and racks its own machines everywhere it operates, someone else owns the hardware, the building, and the physical access to both. That company has its own logging defaults, its own retention, and its own legal relationship with its own jurisdiction. Owned hardware genuinely reduces this, which is why the claim gets made — see what a RAM-only server claim guarantees for how far the infrastructure story actually goes.
The network operators upstream. Traffic leaving an exit server crosses transit providers and peering arrangements. They do not know who you are, but they carry flows to and from an address that is publicly associated with a VPN, which is the raw material of traffic analysis rather than of subscriber identification. That distinction matters — see what survives a tunnel.
Whoever leased the addresses. Address space is allocated and registered. Someone is the registered holder of the ranges an exit server presents, and registration is a public fact.
The payment processor. Somebody handled the transaction, and that party usually knows more about your legal identity than the VPN does. A provider can decline to keep card details; it cannot decline to have been paid.
The support desk. Ticketing systems, shared inboxes and chat widgets are frequently third-party products. A support conversation about a connection problem routinely contains the account, the location, the timestamp, and a description of what was failing — which is a connection log written by hand and stored somewhere else.
Telemetry inside the app. Crash reporting and analytics libraries are ordinary software engineering, and they report to whoever supplies them. An application that says nothing about its own errors is harder to maintain; an application that reports them to an external service has added a party. Whether that party sees anything sensitive depends entirely on what is attached to each report.
The company’s own website and mail. Marketing analytics, content delivery, newsletter tooling and app-store distribution are separate arrangements from the tunnel, and they see your visits and your address in the ordinary way any site does. The tunnel’s privacy properties do not extend to the storefront in front of it.
Anyone reselling. Some services are operated by one company and sold under several names, and some are sold by a partner who handles the customer relationship. If you bought from a reseller, the reseller has the customer record.
What a contract can and cannot fix
Providers do address this, and the mechanism is contractual: data-processing agreements, restrictions on what a sub-processor may retain, and occasionally audit rights. This is real and worth having. It is also a promise about behaviour, not a change in capability, which puts it in a weaker class than a design that makes the data absent — the distinction in cannot versus will not.
Three limits are structural.
A contract cannot bind a legal system. A hosting company compelled under its own jurisdiction’s process will comply with that process regardless of what its customer’s marketing says.
A contract cannot be verified by you. You are not a party to it and will never see it. At best you see a summary in a policy.
A breach of contract is discovered afterwards. The remedy is commercial. It does not un-collect anything.
What this actually changes for you
For most readers, very little about traffic contents — the encryption still applies as of writing, and none of these parties is inside the tunnel. What the extra parties supply is the identity link and the timing record: the account, the payment, the support ticket, the crash report, the visit to the website from your real address before you subscribed. Those are exactly the materials that connect a subscriber to a session, which is the connection the data a VPN must hold already establishes exists in some form.
If your threat model is a network operator or an ISP, none of this changes your decision. If your threat model involves a party who can approach several companies with legal process, the number of companies is the whole point, and you are in the territory where a commercial VPN is not sufficient and specialist advice is the correct next step rather than a better subscription.
Three checks worth doing
Look for a sub-processor list. A provider that publishes one — even by category — is telling you the shape of its supply chain. Silence is not evidence of a short chain; it is evidence of no disclosure.
Read the third-party section of the policy against the parties above. If the policy names none of the categories that must exist, it is describing an architecture that does not exist. The ten-minute method is in how to read a VPN privacy policy.
Check the disclosures for consistency. The description in the app store, the privacy policy, and any transparency reporting were often written by different people at different times. Where they disagree, the disagreement is the finding — the same logic as reading warrant canaries and transparency reports.
The honest summary
Fewer independent parties means fewer independent records, and that is a real axis on which providers differ. But no service reduces the count to one, and a promise phrased as “we keep no logs” is answering a narrower question than the one most people think they asked. The question worth carrying forward is not whether the provider keeps logs. It is who else had to be involved, and what their own records look like — which is the same trust-relocation argument this site keeps returning to, applied one layer further out than what a no-logs claim is worth takes it.