KotoVPN

Guide · Updated August 13, 2026

Red flags in a VPN privacy policy

How do I tell if a VPN privacy policy is hiding something?

Short answer

Look for the gap between the marketing page and the policy. The common pattern is a headline saying "we keep no logs" and a policy several clicks away that describes connection timestamps, bandwidth records and source addresses retained for a stated period. Both statements coexist because "logs" is undefined.

The undefined-term move

"We keep no logs" is not a technical statement. Providers who use it while retaining connection metadata mean "no activity logs" — no record of sites visited — while keeping timestamps, durations, bandwidth and sometimes source addresses.

A policy worth trusting enumerates what is kept rather than asserting a negative. If the document tells you what it does not do without telling you what it does, that is the finding.

Specific things to search the document for

Use the browser find function on these terms. Each one is a question the policy should answer explicitly.

  • "connection log", "session", "timestamp" — is connection metadata retained, and for how long?
  • "IP address" — is the source address stored at any point, even transiently?
  • "bandwidth", "data usage" — per-account totals are common and comparatively benign, but should be stated
  • "third party", "affiliate", "partner" — who else receives data, and for what
  • "analytics" — which analytics platform runs in the app, and what it sends
  • "retention", "delete" — how long anything is kept and what triggers deletion
  • "jurisdiction", "governed by" — which country’s law applies to disputes

Ownership disclosure

A number of apparently independent providers share a parent company. This is not itself wrongdoing, but a policy that does not disclose the parent is withholding something a reader would reasonably want.

It matters practically: choosing two providers from the same group for redundancy gets you one company twice, and the parent’s jurisdiction may differ from the operating company’s.

Avoid

  • Reading only the marketing page, where the claim is broadest and least binding
  • Accepting a policy that describes retention as "as required by law" without naming the law
  • Ignoring the analytics section — several clients have shipped third-party telemetry

Questions

Is keeping bandwidth totals a dealbreaker?
Not on its own. Per-account bandwidth is needed for fair-use enforcement and does not reveal browsing. The issue is when it is kept alongside timestamps and source addresses, because that combination supports correlation.
What about analytics inside the app?
It is common and it should be disclosed and optional. A privacy product shipping non-optional third-party telemetry is a contradiction worth weighing against the rest of the policy.
Does a policy change mean I should switch?
Read what changed. Policies are updated for ordinary legal reasons far more often than for sinister ones. What matters is whether retention expanded and whether the change was announced or discovered.

Terms used here

No-logs policy

A provider’s commitment not to record which sites you visit, when you connected, or what address you connected from.

Jurisdiction

The country whose law governs the company operating the VPN, which determines who can compel it and by what process.

ISP logging

The records your internet provider keeps of which addresses and domains your connection contacted.

Related