Home › Best VPNs › VPN privacy policies compared
Original analysis · Policies read October 2026We read 5 VPN privacy policies line by line
The short answer
All five say “no logs,” and all five have audits backing it. The real difference is how much wiggle room the wording leaves. ExpressVPN's policy is the plainest — one sentence says what it will never collect, under any circumstances. PIA's has the most reassuring headline summaries, except they're explicitly not legally binding. Surfshark and Proton are clear and short. NordVPN's clause is strong but buried in the longest legal document — and its app now asks consent for undefined “limited” performance data.
The comparison table
| VPN | What they say they don't log | Clarity grade | Red flags | |
|---|---|---|---|---|
| ExpressVPN | Browsing history, traffic destination, data content, DNS queries, your IP, outgoing VPN IP, timestamps, session duration | A | Transactional emails retained for ten years. Marketing opt-out shares data with list vendors. Fraud-prevention partner Forter may obtain IPs (stored separately, per policy). | Get ExpressVPN — $3.49/mo |
| Surfshark | Visited IP addresses, browsing history, session info, timestamps, bandwidth, network traffic | A− | Keeps user ID + IP + timestamps for 15 minutes post-session. Support-chat content kept up to 6 years. Collects 'part of the credit card number' — 'part' is undefined. | Get Surfshark — $2.49/mo |
| Proton VPN | Connection logs, IP addresses, session lengths, location | A− | Proton's own blog admits it keeps the timestamp of your most recent login (never the IP). 'Metadata' in its FAQ is never defined. Will comply with valid Swiss court orders — disclosed data is limited to what it has. | Get Proton VPN — $2.99/mo |
| Private Internet Access | Browsing history, connected content, user IPs, timestamps, bandwidth logs, DNS queries | B+ | Will share data 'unless doing so is absolutely necessary' — 'absolutely necessary' is undefined. Collects state/zip at checkout for tax. Kape Technologies group sharing allowed where 'reasonably necessary.' | Get Private Internet Access — $2.03/mo |
| NordVPN | Connection timestamps, session info, bandwidth, traffic logs, IP addresses | B | A 2025 app update added a privacy consent for 'limited app performance data' — 'limited' is undefined. Nord's release notes confirm opt-in analytics exist; the privacy trade-off lives in the app, not the policy. | Get NordVPN — $3.49/mo |
ExpressVPN — clarity grade: A
“We do not collect logs of your online activity while you are connected to our Services, including no logging of browsing history, traffic destination, data content, or DNS queries.”
Source: expressvpn.com/privacy-policy, last updated Oct 2, 2026
Why A: Plainest English of the five. The 'what we do not collect under any circumstances' framing is unambiguous.
Watch for: Transactional emails retained for ten years. Marketing opt-out shares data with list vendors. Fraud-prevention partner Forter may obtain IPs (stored separately, per policy).
Surfshark — clarity grade: A−
“We do not collect any information about what you do online (i.e., we do not collect your visited IP addresses, browsing history, session information, connection time stamps, used bandwidth, network traffic or any other similar information).”
Source: surfshark.com/privacy, last updated Aug 27, 2026
Why A−: Best structure — every data item sits in a data / legal basis / retention table. Docked for vague fragments elsewhere.
Watch for: Keeps user ID + IP + timestamps for 15 minutes post-session. Support-chat content kept up to 6 years. Collects 'part of the credit card number' — 'part' is undefined.
Proton VPN — clarity grade: A−
“Proton VPN does not keep logs of your online activity. We do not store, collect, or track any information about your connection logs, IP addresses, session lengths, or location.”
Source: protonvpn.com/features/no-logs-policy + Proton's own policy explainer blog
Why A−: Shortest, clearest no-logs clause of the five. Docked because the one item it does keep isn't on this page.
Watch for: Proton's own blog admits it keeps the timestamp of your most recent login (never the IP). 'Metadata' in its FAQ is never defined. Will comply with valid Swiss court orders — disclosed data is limited to what it has.
Private Internet Access — clarity grade: B+
“We DO NOT collect or store browsing history, connected content, user IPs, connection time stamps, bandwidth logs, DNS queries, or anything like that. We collect and retain zero user logs.”
Source: privateinternetaccess.com/privacy-policy
Why B+: The green 'summary of this section' boxes are genuinely readable — but the policy itself says those summaries 'are not meant to have any legal effect.'
Watch for: Will share data 'unless doing so is absolutely necessary' — 'absolutely necessary' is undefined. Collects state/zip at checkout for tax. Kape Technologies group sharing allowed where 'reasonably necessary.'
NordVPN — clarity grade: B
“We do not store connection time stamps, session information, used bandwidth, traffic logs, IP addresses or other data.”
Source: NordVPN's published policy as quoted by TechRadar/Tom's Guide; nordvpn.com blog release notes
Why B: Strong clause, but wrapped in the longest, most legalistic document. Note: we couldn't pull Nord's official policy page directly (see below) and graded it on publicly quoted text.
Watch for: A 2025 app update added a privacy consent for 'limited app performance data' — 'limited' is undefined. Nord's release notes confirm opt-in analytics exist; the privacy trade-off lives in the app, not the policy.
Our take: which policy can a non-lawyer actually understand?
ExpressVPN. It opens by telling you what it does not collect “under any circumstances,” names its eight data types in plain sections, and states its guiding principle in one sentence: it designed its systems to not have your sensitive data at all. You don't need a law degree to see the whole picture.
Surfshark is the best structured policy — every item sits in a table of what's collected, the legal basis, and how long it's kept — which makes the 15-minute session-data window and the 6-year support-chat retention easy to spot. Proton VPN's no-logs statement is the shortest and cleanest, but it's the only one where the single thing it does keep (your last-login timestamp) lives on a blog, not the policy page. PIA's green summary boxes are the friendliest to skim — and the only ones that say “these are not legally binding.”
Vague wording to distrust — anywhere, in any VPN policy
- “As necessary” / “absolutely necessary.” Necessary for what, decided by whom? PIA lets itself share data whenever sharing is “absolutely necessary” to run the service — a phrase with no definition and no boundary.
- “Limited” data. NordVPN's app now asks for consent to collect “limited app performance data.” Limited to what? The policy doesn't say. If a provider won't name the fields, treat it as unknown.
- “May collect.” “May” can mean “sometimes does” or “reserves the right to.” Either way it's a hedge, not a statement.
- “Service data” / “metadata.” These are umbrellas. Proton says it records no “metadata that can personally identify you” — but timestamps and account IDs are metadata too. Ask: which metadata, exactly?
- Summaries that aren't the policy. Readable summary boxes are great — unless, like PIA's, the policy explicitly says they have no legal effect. The legal text is what binds them.
- “Aggregated” diagnostics. Aggregate data is genuinely useful and usually safe — but “aggregated” without a stated granularity is just a claim. Audits check this; policies don't prove it.
One caveat on NordVPN
We could not pull NordVPN's official policy page directly in our research pass (the URL didn't surface through our search), so Nord's clause above is quoted from the policy text reproduced verbatim by TechRadar and Tom's Guide, and its grade rests on those plus Nord's own published release notes. If Nord updates the page, we'll re-read it ourselves. Everything else above was read directly from the provider's own pages.
Questions, answered
Do privacy policies matter if independent audits exist?
What's the difference between a privacy policy and an audit?
Which of the five policies is the most readable?
If they all say 'no logs,' are they all telling the truth?
Final verdict
For policy clarity alone, pick ExpressVPN. For structure, Surfshark. For brevity, Proton VPN. PIA's and NordVPN's no-logs claims are equally well audited — their policies are just harder to parse, and that's worth knowing before you buy. Prices drift with promos, so verify at checkout.