The undefined-term move
"We keep no logs" is not a technical statement. Providers who use it while retaining connection metadata mean "no activity logs" — no record of sites visited — while keeping timestamps, durations, bandwidth and sometimes source addresses.
A policy worth trusting enumerates what is kept rather than asserting a negative. If the document tells you what it does not do without telling you what it does, that is the finding.
Specific things to search the document for
Use the browser find function on these terms. Each one is a question the policy should answer explicitly.
- "connection log", "session", "timestamp" — is connection metadata retained, and for how long?
- "IP address" — is the source address stored at any point, even transiently?
- "bandwidth", "data usage" — per-account totals are common and comparatively benign, but should be stated
- "third party", "affiliate", "partner" — who else receives data, and for what
- "analytics" — which analytics platform runs in the app, and what it sends
- "retention", "delete" — how long anything is kept and what triggers deletion
- "jurisdiction", "governed by" — which country’s law applies to disputes
Ownership disclosure
A number of apparently independent providers share a parent company. This is not itself wrongdoing, but a policy that does not disclose the parent is withholding something a reader would reasonably want.
It matters practically: choosing two providers from the same group for redundancy gets you one company twice, and the parent’s jurisdiction may differ from the operating company’s.
Avoid
- Reading only the marketing page, where the claim is broadest and least binding
- Accepting a policy that describes retention as "as required by law" without naming the law
- Ignoring the analytics section — several clients have shipped third-party telemetry