Home › Best VPNs › VPN privacy policies compared

Original analysis · Policies read October 2026

We read 5 VPN privacy policies line by line

Affiliate disclosure: Affiliated, never sponsored. We earn commissions through links on this page, but commissions don't move rankings — picks with no affiliate program are still mentioned where they're the honest choice. See “How we test” for the protocol behind every score.
Lab status: policy text fetched from each provider's own pages · logging clauses · retention windows · weasel-word clauses — in progress: on-device speed/leak/streaming trials.

The short answer

All five say “no logs,” and all five have audits backing it. The real difference is how much wiggle room the wording leaves. ExpressVPN's policy is the plainest — one sentence says what it will never collect, under any circumstances. PIA's has the most reassuring headline summaries, except they're explicitly not legally binding. Surfshark and Proton are clear and short. NordVPN's clause is strong but buried in the longest legal document — and its app now asks consent for undefined “limited” performance data.

The comparison table

VPNWhat they say they don't logClarity gradeRed flags
ExpressVPNBrowsing history, traffic destination, data content, DNS queries, your IP, outgoing VPN IP, timestamps, session durationATransactional emails retained for ten years. Marketing opt-out shares data with list vendors. Fraud-prevention partner Forter may obtain IPs (stored separately, per policy).Get ExpressVPN — $3.49/mo
SurfsharkVisited IP addresses, browsing history, session info, timestamps, bandwidth, network trafficA−Keeps user ID + IP + timestamps for 15 minutes post-session. Support-chat content kept up to 6 years. Collects 'part of the credit card number' — 'part' is undefined.Get Surfshark — $2.49/mo
Proton VPNConnection logs, IP addresses, session lengths, locationA−Proton's own blog admits it keeps the timestamp of your most recent login (never the IP). 'Metadata' in its FAQ is never defined. Will comply with valid Swiss court orders — disclosed data is limited to what it has.Get Proton VPN — $2.99/mo
Private Internet AccessBrowsing history, connected content, user IPs, timestamps, bandwidth logs, DNS queriesB+Will share data 'unless doing so is absolutely necessary' — 'absolutely necessary' is undefined. Collects state/zip at checkout for tax. Kape Technologies group sharing allowed where 'reasonably necessary.'Get Private Internet Access — $2.03/mo
NordVPNConnection timestamps, session info, bandwidth, traffic logs, IP addressesBA 2025 app update added a privacy consent for 'limited app performance data' — 'limited' is undefined. Nord's release notes confirm opt-in analytics exist; the privacy trade-off lives in the app, not the policy.Get NordVPN — $3.49/mo

ExpressVPN — clarity grade: A

“We do not collect logs of your online activity while you are connected to our Services, including no logging of browsing history, traffic destination, data content, or DNS queries.”

Source: expressvpn.com/privacy-policy, last updated Oct 2, 2026

Why A: Plainest English of the five. The 'what we do not collect under any circumstances' framing is unambiguous.

Watch for: Transactional emails retained for ten years. Marketing opt-out shares data with list vendors. Fraud-prevention partner Forter may obtain IPs (stored separately, per policy).

Surfshark — clarity grade: A−

“We do not collect any information about what you do online (i.e., we do not collect your visited IP addresses, browsing history, session information, connection time stamps, used bandwidth, network traffic or any other similar information).”

Source: surfshark.com/privacy, last updated Aug 27, 2026

Why A−: Best structure — every data item sits in a data / legal basis / retention table. Docked for vague fragments elsewhere.

Watch for: Keeps user ID + IP + timestamps for 15 minutes post-session. Support-chat content kept up to 6 years. Collects 'part of the credit card number' — 'part' is undefined.

Proton VPN — clarity grade: A−

“Proton VPN does not keep logs of your online activity. We do not store, collect, or track any information about your connection logs, IP addresses, session lengths, or location.”

Source: protonvpn.com/features/no-logs-policy + Proton's own policy explainer blog

Why A−: Shortest, clearest no-logs clause of the five. Docked because the one item it does keep isn't on this page.

Watch for: Proton's own blog admits it keeps the timestamp of your most recent login (never the IP). 'Metadata' in its FAQ is never defined. Will comply with valid Swiss court orders — disclosed data is limited to what it has.

Private Internet Access — clarity grade: B+

“We DO NOT collect or store browsing history, connected content, user IPs, connection time stamps, bandwidth logs, DNS queries, or anything like that. We collect and retain zero user logs.”

Source: privateinternetaccess.com/privacy-policy

Why B+: The green 'summary of this section' boxes are genuinely readable — but the policy itself says those summaries 'are not meant to have any legal effect.'

Watch for: Will share data 'unless doing so is absolutely necessary' — 'absolutely necessary' is undefined. Collects state/zip at checkout for tax. Kape Technologies group sharing allowed where 'reasonably necessary.'

NordVPN — clarity grade: B

“We do not store connection time stamps, session information, used bandwidth, traffic logs, IP addresses or other data.”

Source: NordVPN's published policy as quoted by TechRadar/Tom's Guide; nordvpn.com blog release notes

Why B: Strong clause, but wrapped in the longest, most legalistic document. Note: we couldn't pull Nord's official policy page directly (see below) and graded it on publicly quoted text.

Watch for: A 2025 app update added a privacy consent for 'limited app performance data' — 'limited' is undefined. Nord's release notes confirm opt-in analytics exist; the privacy trade-off lives in the app, not the policy.

Our take: which policy can a non-lawyer actually understand?

ExpressVPN. It opens by telling you what it does not collect “under any circumstances,” names its eight data types in plain sections, and states its guiding principle in one sentence: it designed its systems to not have your sensitive data at all. You don't need a law degree to see the whole picture.

Surfshark is the best structured policy — every item sits in a table of what's collected, the legal basis, and how long it's kept — which makes the 15-minute session-data window and the 6-year support-chat retention easy to spot. Proton VPN's no-logs statement is the shortest and cleanest, but it's the only one where the single thing it does keep (your last-login timestamp) lives on a blog, not the policy page. PIA's green summary boxes are the friendliest to skim — and the only ones that say “these are not legally binding.”

Vague wording to distrust — anywhere, in any VPN policy

One caveat on NordVPN

We could not pull NordVPN's official policy page directly in our research pass (the URL didn't surface through our search), so Nord's clause above is quoted from the policy text reproduced verbatim by TechRadar and Tom's Guide, and its grade rests on those plus Nord's own published release notes. If Nord updates the page, we'll re-read it ourselves. Everything else above was read directly from the provider's own pages.

Questions, answered

Do privacy policies matter if independent audits exist?

Yes — they do different jobs. The privacy policy is the provider's own legally binding promise about what it collects. The audit is an independent firm's check that the systems match the promise at a point in time. An audit without a strong policy means they verified a weak promise. A strong policy without audits means you're taking their word for it. You want both.

What's the difference between a privacy policy and an audit?

A privacy policy is a legal document written by the VPN company itself: what it collects, why, how long it keeps it, and what it won't collect. An audit is a third party (Deloitte, KPMG, PwC, Securitum) examining the provider's systems and reporting whether the no-logs claims hold up — usually ISAE 3000 engagements testing controls on a given date. Transparency reports are a third thing: published counts of how many legal data requests a provider received and what it handed over.

Which of the five policies is the most readable?

ExpressVPN's. It's the only one that states the no-logs clause in one plain sentence up front ('we do not collect under any circumstances'), lists its eight data types by name, and was last updated October 2, 2026. Surfshark is a close second with its data-basis-retention tables. Proton VPN's no-logs statement is the shortest but hides its one retained item — the last-login timestamp — in a blog post rather than the policy itself.

If they all say 'no logs,' are they all telling the truth?

Every provider here has independent audits backing the no-logs claim, plus two have been tested the hard way: PIA was twice subpoenaed by the FBI (2016, 2018) with nothing to hand over, and a Turkish-seized ExpressVPN server in 2017 yielded no logs. What differs isn't the claim — it's how much wiggle room the wording leaves: 'as necessary' sharing, undefined 'limited' data, and optional analytics opt-ins are where policies get slippery.

Final verdict

For policy clarity alone, pick ExpressVPN. For structure, Surfshark. For brevity, Proton VPN. PIA's and NordVPN's no-logs claims are equally well audited — their policies are just harder to parse, and that's worth knowing before you buy. Prices drift with promos, so verify at checkout.