Privacy basics
What does no-logs mean for a VPN, and how can you check it?
A no-logs claim usually means a VPN does not record what you do online, but it rarely means the provider stores nothing. Traffic content, DNS queries, connection metadata and account data are four different things, and a policy can treat each one differently. Read which categories a provider names, how long it keeps them, and whether its canary and transparency report are kept up to date.
Key points
- Logs come in four kinds: traffic content, DNS queries, connection metadata and account data.
- Every paid service keeps some account and billing data; the question is what and for how long.
- Privacy policies, canaries, transparency reports and open-source code each tell you part of the story.
- Read the documents yourself and check their dates, including ours.
What no-logs really means
"No-logs" is a marketing phrase, not a technical standard. There is no shared definition, and two providers can use the same words for very different practices.
In practice, a no-logs claim usually means the provider does not record what you do through the tunnel. It almost never means the provider knows nothing about you. To run a paid service, it needs to know who has an account, whether they have paid, and how much of their plan they have used. The useful question is not "does this VPN keep logs?" but "which kinds of data does it keep, for how long, and could they link me to my activity?"
The four kinds of data
It helps to split "logs" into four categories. Each one reveals something different, and a privacy policy can treat each one differently.
| Category | Examples | What it could reveal |
|---|---|---|
| Traffic content | The pages, messages and files passing through the tunnel | What you read, write and download |
| DNS queries | The domain names your device looks up | Which sites and services you use, even without the content |
| Connection metadata | Connection times, your source IP address, bytes transferred, which server you used | When you were online and, combined with other data, possibly who you are |
| Account and billing data | Email, password hash, plan, payment status, usage totals | That you are a customer, and roughly how much you use the service |
The first two are the most sensitive, because they describe your activity directly. DNS is easy to overlook: even when the content of a connection is encrypted, the list of names you look up can say a lot. RFC 9076 covers this in detail.
Connection metadata sits in between. On its own it does not show what you did, but timestamps and IP addresses can sometimes be matched with records held elsewhere. That is why it is worth reading exactly what a policy says about it, rather than relying on a headline.
How to check a VPN's claims
No single document proves a no-logs claim. Several sources together give you a reasonable picture. Here is what to look at, and what each one can and cannot tell you.
- Privacy policy. This is the most important document. Look for a named list of what is collected, why, and a retention period for each item. Vague phrases like "minimal data" or "we may collect" deserve a closer look.
- Warrant canary. A dated statement that the provider has not received certain secret orders. It only helps if it is updated on a regular schedule, so always check the date. Its legal weight differs between countries.
- Transparency report. The number of data requests received and how many were answered. Compare the period it covers with today's date.
- Open-source engines. If the software that carries your traffic is open source, anyone can check what it is able to record. It cannot show how a given server is configured.
- Jurisdiction. Where the operator is based decides which laws apply to it, including data retention rules and how authorities can request data. Look for clear operator details in the legal documents.
- Independent audits. Where they exist, check who carried them out, what was in scope and when. An audit describes a moment in time.
What DXVPN keeps
Here is what DXVPN states, in plain terms. The source documents are linked so you can check each point yourself.
Not logged: the content of your traffic, the sites you visit and your DNS queries. On plans with DNS filtering, lookups go to AdGuard Home on DXVPN's own servers, and the queries are not logged.
Kept, as account data:
- your email address and a hashed password (bcrypt);
- your plan and payment status;
- total traffic per billing period, used to enforce plan limits.
Deleted: account data is removed 30 days after your subscription ends or your account is deleted, according to the privacy policy.
Published documents: the warrant canary is last dated 3 April 2026. The transparency report published so far covers Q1 2026, with 0 requests and 0 disclosures. Check both dates when you read them.
Open-source engines: sing-box, AmneziaWG, mtg v2 for MTProto, and AdGuard Home for DNS.
For anything not listed here, including exactly what connection data is handled and for how long, go to the source documents rather than to a summary, ours included. The trust center gathers all of them in one place.
Habits that protect you anyway
A good logging policy is only one layer. A few habits reduce what any provider, website or network can learn about you, whichever VPN you use.
- Share less at sign-up. Use an email address you do not use everywhere else.
- Protect the account. Turn on two-factor sign-in; DXVPN supports an authenticator app or Telegram.
- Remember what a VPN cannot hide. Sites you sign in to still know it is you, and your browser can still be fingerprinted.
- Re-read policies now and then. Documents change. Note the edition date, and look again after major updates.
A VPN moves trust from your local network to the provider. Choosing a provider is really choosing whom to trust, so it is worth a few minutes with the actual documents.
Questions
Does any VPN keep no data at all?
A paid service needs at least some account and billing data to know who has paid and which plan they are on. What matters is which categories are kept, for how long, and whether they could link you to your online activity.
What does DXVPN log?
DXVPN does not log the content of your traffic, the sites you visit or your DNS queries. It keeps account data: your email, a hashed password, plan and payment status, and total traffic per billing period for plan limits. Account data is deleted 30 days after your subscription ends or your account is deleted.
What is a warrant canary?
It is a dated public statement that a provider has not received certain secret orders, such as gag orders. If it stops being updated or is removed, readers can treat that as a signal. Its legal weight varies by country, so treat it as one clue among several.
Does open-source software prove a VPN keeps no logs?
No. Open-source engines let anyone inspect what the software can do, but they cannot show how a particular server is configured. They make claims easier to reason about, not automatically true.
Sources
General information, not legal advice. VPN rules differ by country — check the law where you are.
See it for yourself
Run the “what the censor sees” check on the home page, or start on the free plan — no card needed.