VPN Guide
What Is a Privacy VPN?
A **privacy VPN** is one that does not record information about your online activity — no browsing history, no connection timestamps, no IP addresses, nothing that could be used to identify what you did online. Sounds simple, but 'privacy' has been one of the most abused terms in the VPN industry. The only meaningful privacy claim is one that has been **publicly documented** by a reputable third-party firm or, even better, **proven in court**. This guide explains what privacy really means, which providers have verified their claims, and how to evaluate any VPN's privacy policy.
Editorial shortlist
Need a VPN recommendation now?
Skip the theory — compare our top-rated VPNs for US users, with pricing, privacy notes, and setup guides.
See all VPN reviewsCompare providersWhat 'Privacy' Actually Means
A true privacy VPN does not retain:
- Browsing history — Which websites you visited
- DNS queries — Which domains you looked up
- Connection timestamps — When you connected and disconnected
- Real IP addresses — Your originating IP
- VPN-assigned IP addresses — Which VPN server IP you used
- Data transferred — How much bandwidth you used
Some VPNs retain limited 'connection metadata' (like aggregate bandwidth used per day) for capacity planning, but a true zero-logs provider keeps nothing that could be tied back to an individual user.
Why Published Disclosures Matter
VPN providers can claim anything in marketing copy. The only way to verify a privacy claim is through an independent third-party reported by a reputable firm. The most respected VPN reported firms in 2026 are:
- public provider materials — Has reported NordVPN multiple times
- public provider materials — reported ExpressVPN and NordVPN
- public provider materials — Conducted security audits for ExpressVPN, Surfshark, Mullvad, and ProtonVPN
- public provider materials — reported ExpressVPN's TrustedServer infrastructure
- public provider materials — reported Surfshark and several other providers
A legitimate reported involves auditors physically visiting the VPN's data centers, reviewing server configurations, examining source code, and interviewing staff. Reports are typically published publicly, sometimes with redactions for security-sensitive details.
Court-Proven Privacy: The Gold Standard
An reported is good. A court case is better. Several VPN providers have had their privacy claims tested in real legal proceedings:
- Private Internet Access — Had its privacy policy reported in two separate US federal court cases (FBI investigation, 2016 and 2018). When Private Internet Access was subpoenaed for user data, it had nothing to provide.
- ExpressVPN — In 2017, Turkish authorities seized an ExpressVPN server investigating the assassination of the Russian ambassador. They found privacy and no useful data on the server.
- Mullvad — Had its servers raided by Swedish police in 2023. Police seized hardware but found no user data, validating Mullvad's privacy and RAM-only server architecture.
These real-world cases provide the strongest possible evidence that a provider's privacy claim is genuine, beyond what any reported can prove.
RAM-Only Servers: Hardware-Level Privacy
Some VPN providers have gone beyond software-level privacy claims by using RAM-only servers — servers with no persistent storage at all. Everything runs in volatile memory and is wiped when the server reboots.
ExpressVPN pioneered this approach with its TrustedServer technology in 2019. Surfshark, NordVPN, and Mullvad have since adopted similar architectures. The advantage is structural: even if a server were physically seized, there would be no disk to forensically analyze.
RAM-only servers also force the provider's entire stack to reload from a known-good state on every reboot, making any unauthorized configuration changes impossible to persist.
How to Evaluate Any VPN's Privacy Claim
When considering a VPN provider, check these factors in order of importance:
- Has there been a recent published disclosure? Look for a published report on the provider's website. Audits should be re-done every 1–2 years to remain meaningful.
- Is the reported firm reputable? provider materials, provider materials, public provider materials are all credible. Be skeptical of audits by unknown firms.
- What was the reported's scope? A full privacy reported should cover server configurations, source code, and operational practices — not just a privacy policy review.
- Has the privacy claim been tested in court or by a server seizure? This is the strongest possible evidence.
- Does the provider use RAM-only servers? This is becoming standard for privacy-focused providers.
- What is the jurisdiction? Providers based in countries with strong privacy laws (Switzerland, Panama, BVI) are generally better positioned to resist data demands.
For our top recommendations, we evaluate all these factors as part of the StatesVPN methodology.
Frequently Asked Questions
Continue comparing
Full reviews
Reviewed Sep 2026 · Public-source research · First-party tests appear on review pages when dated results are published · Verify details on provider sites. Editorial policy & scoring