No-logs is not invisible. It is a claim about activity files the provider does not keep.

What a No-Logs VPN Does Not Mean

No-logs is not invisibility. Account email, invoices, five devices, malware, logged-in Google, phishing, and court orders for records you actually stored still exist.

KloxVPN Team
22 min readPublished 2022-06-29
What a No-Logs VPN Does Not Mean
No-logs is not invisible. It is a claim about activity files the provider does not keep.

No-logs is a sentence about files the VPN operator tries not to keep: browsing history, DNS queries, your home IP while connected, a diary of sessions. It is not a sentence about disappearing. If you wanted invisible, you wanted a different product, and consumer VPNs do not sell that product honestly.

This is not No-Logs VPN: What It Really Means. That piece is the definition and how people try to verify a claim. This is the other side: what the slogan does not erase. Your signup email. The invoice. Five device names in the portal. Malware that already lives on the laptop. Google while you are logged in. A phishing page you typed a password into. A court order for records that actually exist.

This is also not No-Logs When the Brand Isn't the Network Operator. That one is white-label: controller versus processor, who may say we. You are a consumer on Klox. Different plot.

A VPN is still a tunnel. Wikipedia's VPN page will not delete your Stripe receipt. RFC 8446 is TLS 1.3 on the web path. HTTPS was already encrypting page bodies. The no-logs claim is about the VPN operator's activity files, not about every company you already have an account with.

Klox consumer is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. The live document is /privacy. It lists account information we collect. It lists activity we say we do not. It says the no-logs stance is enforced by internal review. It does not claim a third-party no-logs audit. I will not invent one here to make the slogan feel heavier.

I have a bias. Read the policy. Keep the email you used. Assume invoices exist. Do not treat the tunnel as antivirus, as a Google logout, or as a shield against a warrant for the mailbox you already own. Then the slogan is sized correctly.

Related reading: Endbr vs a VPN: Practical Notes and Endbr32: Not a Mitigation Toggle. Endbr64: Not a Mitigation Toggle and Linux enhanced_dad: Not a VPN Setting. What is a VPN? and Download KloxVPN.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

Invisible is a movie

People hear no-logs and picture a blank universe. No name. No receipt. No device list. No way anyone could ever ask a question. That picture is a film. The product is a tunnel plus an account.

An account has an email because you need a password reset and a receipt. It has a device count because the plan is five seats, not infinity. It has a payment processor because yearly from $2.83 a month is still money. None of that is browsing history. All of that is still you, on paper, at a company that sold you software.

Mullvad's public no-logging page is a useful specimen of how another operator writes the activity claim, including numbered accounts without an email. That is their product. Klox is an email account. Do not paste their model onto ours and call it the same sentence. Read their page as a competitor specimen. Then read ours.

The rest of this article is the pile the slogan does not delete. If you already knew that, you can stop after the table. Most tickets I have seen did not know that. They wanted the slogan to reach into Gmail.

Five devices on one KloxVPN plan
One account, five devices online at the same time.

    How to read this page

  1. 1Skim the seating / order diagram.
  2. 2Do the numbered steps once on your real network.
  3. 3Use the FAQ if a sentence was too long.
  4. 4Follow one related article — not ten tabs.
What the slogan does not erase. Not a ranking of VPNs. Not an audit.
What you hopedWhat still existsWho holds it
No identity at allThe email you typed at signupThe account system; see /privacy
No money trailInvoices, processor records, bank statementStripe and your bank; Klox does not store full card numbers
No device listUp to five seats in the portalThe same account you log into
No malware riskWhatever already runs on the diskYour laptop, not the VPN node
Logged-out webCookies and sessions at Google, banks, shopsThose companies
Court-proof lifeWhatever was actually storedWhoever stored it, if a valid order lands

No-logs is not invisible. It is a claim about activity files the provider does not keep.

— KloxVPN consumer notes

Cloudflare Learning: What is a VPN?

Wikipedia: Virtual private network

IETF RFC 8446 (TLS 1.3)

Mullvad no-logging of user activity (competitor specimen)

Two drawers, one slogan

Drawer A is activity: sites, DNS names, home IP while the tunnel is up, a session diary. That is what no-logs argues is empty. Drawer B is the account: email, invoices, seats, tickets. Drawer B is how a consumer VPN bills. If marketing talks like drawer B is empty, marketing is lying.

Invisible would be a different stack

Cash, no email, no app store identity, discipline about logins, maybe Tor. Most people will not live that way. Most people wanted cafe Wi-Fi encrypted and a less public IP. Buy that. Do not buy a cloak and then file a ticket when Gmail still knows you.

The email you typed is a file

You created an account with an address. Password reset goes there. Receipts go there. Support replies go there. That address is personal data. It is not a browsing history. It is still a handle that points at a human who paid.

If someone phishes that inbox, they do not need a VPN activity log. They need the reset link. If you reuse that address on ten other sites, those sites already correlate you. The tunnel did not invent the address. You typed it.

Klox's live policy lists email under account information. That is the honest version. A homepage that says we know nothing about you while a login form asks for mail is a joke the reviewer will screenshot. We ask for mail. We say we do not keep the activity diary. Those sentences can both be true. They are not the same sentence.

People also forward receipts to a shared family inbox. Then five people can see the Klox invoice. That is a household choice. It is not a logging feature. It is also not invisibility.

Password reset is a trail

Every reset is a message that says this mailbox owns this VPN account. Useful. Also a record. If you wanted no mailbox, you wanted a numbered-account product. We are not that product. Download still needs a login.

Support mail is a file too

You wrote in. You pasted an error. You named a device. That ticket sits in a support tool. No-logs does not mean we pretend the ticket never happened. It means the ticket is not a packet capture of your week.

Invoices are not browsing history

Yearly from $2.83 a month still creates a charge. The processor sees a customer, an amount, a method. Your bank sees a descriptor. Klox's policy says payment is handled by third-party processors and we do not store full card numbers. That is a card-data sentence. It is not a we-have-no-financial-relationship sentence.

An invoice in the portal is proof you bought a tunnel. It is dated. It has a plan. It is exactly the document finance and tax people expect. It does not list the sites you opened. Mixing those in your head is how you get angry at a PDF.

Chargebacks and refunds are other articles. Here: the money trail survives no-logs because money trails are how subscriptions exist. Seven-day money-back on first purchase is also a record: we returned an amount, access should die. That row is not a DNS query.

If you pay through an app store, Apple or Google already know you bought a VPN. Their receipt is not our activity log. It is still a receipt. Store identity is a different kind of not-invisible.

WireGuard versus OpenVPN
Klox ships four protocols: WireGuard by default, OpenVPN when UDP fails.

Stripe is not a browsing log

A processor keeps what it needs to move money and fight fraud. That pile can include email, last4, IP at checkout, device fingerprints the processor uses. Read Stripe's policy if you care. Do not ask Klox support to unsay a bank statement.

Exporting invoices does not violate no-logs

You can download a receipt and still have an empty activity drawer. Those are different files. If a farm says a real no-logs VPN would have no invoice, that farm wants you off the legal grid. We sell a consumer SKU.

Five devices in the portal

The plan is five devices. The portal shows seats because otherwise you cannot tell which laptop is burning a slot. A device name, a last-seen style row, a revoke button: that is how a family plan is operable. It is not a list of URLs.

No-logs marketing that pretends we cannot know you have a phone and a PC is pretending the product is unusable. We have to enforce five. Mullvad's public explanation of simultaneous connections in memory is their mechanism. Ours is an account with five seats you can see. Different engineering. Same consumer fact: a device limit is visible somewhere or it is fake.

If a roommate used seat five, the portal still shows five. That is not us reading their traffic. That is a slot. Revoke it. The Family VPN on Five Devices piece is the household ops. Here: the list existing does not cancel the activity claim. It does cancel invisibility.

WireGuard, OpenVPN, OpenConnect, and Shadowsocks do not care how many humans share a login. The portal does. If you wanted nobody to know a tablet exists, do not register the tablet.

Last connected is not browsing history

A seat row that helps you find the old phone is account ops. A diary of every handshake with timestamps tied to destinations is the thing the no-logs list says we do not keep. If the live portal shows a coarse device list, that is drawer B. Read it as drawer B.

Revoke is the control you actually have

Lost laptop: revoke the seat. That is the move. Hoping no-logs will make the stolen disk forget your cookies is not a move. The disk still has the cookies.

Malware on the laptop

A tunnel encrypts a path. It does not scan the disk. If a stealer is already in the browser profile, it will steal the session. The VPN node never sees that job. The stealer does not read /privacy first.

People buy a VPN after a scare and treat it as a cleanup. It is not cleanup. Cleanup is a different product: backups, a reinstall, a password change on every important site, 2FA. The What a VPN Cannot Do list covers malware in the broad sense. This paragraph is narrower: no-logs does not mean we magically deleted the infection by refusing to keep your DNS queries.

If malware opens its own path around the tunnel, you have a leak of a different kind. That is an infected machine. Reinstall. Do not ask the privacy policy to be an antivirus engine.

Crash reports, if the policy lists them, are about the app dying, not about the sites you visited. Still a file. Still not a cloak for a keylogger.

Cafe Wi-Fi is not the same threat

The tunnel is good at the cafe sniffer. The sniffer is not the trojan you installed last month from a fake codec. Different rooms. No-logs does not merge them.

We will not pretend to inspect your disk

We cannot. We should not. A VPN that offered to scan your files would be a worse privacy story, not a better one. Keep the jobs separate.

Logged-in Google is still you

You connected Klox. You opened Gmail. Google sees a VPN egress IP and a logged-in account. The account wins. Cookies win. The no-logs claim at the VPN shop does not un-login you at the identity shop.

This is the ticket that makes people feel cheated. They wanted the slogan to reach into the other company. It cannot. Google, Microsoft, Apple, your bank, your shop: they have their own files. RFC 8446 still encrypts the path to them. They still know the account.

Search history in a logged-in browser is Google's problem, or yours, depending on settings. It is not a Klox activity log. Turning on a VPN and leaving Sync on is a common setup. It is also the opposite of invisible.

If you need a less identified browser session, that is a browser profile job, cookie job, account job. The tunnel only changed the IP the other company saw. Useful. Incomplete.

Ads and fingerprints still exist

IP is one signal. Fonts, screen, logins, pixels. Masking IP is worth doing. It does not retire the rest. The tracking-limits article is a sibling. Here: no-logs at the VPN is not a fingerprint cleaner.

Incognito is not a Klox feature

Private windows drop some local state. They do not drop a Google login you typed again. They do not empty our invoice drawer. Separate tools.

Phishing does not read the privacy policy

A fake bank page will take the password whether the tunnel is up or not. The resolver will even answer the name if the name exists. DNS through the tunnel hides that name from the ISP. It does not make the fake page honest.

No-logs means we are not storing a diary of the sites you opened. It does not mean the phish failed. The phish succeeded on your screen. Change the bank password. Call the bank. Do not email us asking for the log of what you typed. We are saying we do not have that log. That is the point of the slogan, and it is also why we cannot undo the phish.

People hear no-logs as we will protect you from bad pages. That is antivirus and judgment. Different SKUs. I would rather lose the signup than inherit the user who clicks because VPN.

HTTPS can still be a valid cert on a lookalike domain. RFC 8446 does not check whether you meant klox.app or a cousin. The padlock is not a brain.

We cannot replay your session

If the activity drawer is empty, we cannot tell you which URL you opened at 14:03. That is the privacy you asked for. It is also why support cannot rewind a phish. Live with both halves.

Support will ask what you typed

We may ask whether you entered a password on a page that was not the real bank. That question is not us admitting we logged the page. It is us trying to get you to the bank's fraud desk faster.

Court orders for what was actually stored

A valid legal process can ask for records a company has. It cannot invent records a company does not have. That is the whole honest version of no-logs under pressure. The live policy says we cannot provide online-activity data we do not have. It also says we may disclose information we do have if required by law, to the extent necessary: account identity, billing, the kind of drawer B files this article keeps naming.

I will not write a courtroom drama. I will not invent a jurisdiction tour. I will not invent a Klox independent audit that proves an empty disk to a stranger. Internal review is what the policy claims. Read that sentence on /privacy. If you need a third-party audit as a buying rule, that is your rule. Do not let a blog post fake the PDF.

Warrants for Gmail, for Apple, for the bank, for the laptop in your house: those land on other parties. The VPN slogan does not quash them. People collapse every company into we. Stop collapsing.

If a farm says no-logs means police-proof, the farm is selling a feeling. Police-proof is not a consumer SKU. Empty activity files plus a real invoice is the adult picture.

Empty activity is not empty billing

An order that asks who paid for account X may get an answer if that answer exists. An order that asks for a week of URLs should get we do not have that, if the activity claim is true. Those are different asks. Keep them different in your head.

Do not coach a crime in a comment

This article is limits of a slogan. It is not a guide to hiding from lawful process. If you need a lawyer, get a lawyer. If you needed a tunnel for cafe Wi-Fi, you already have the right-sized product.

Two other posts, different jobs

The No-Logs VPN: What It Really Means is what the words should cover and how people try to verify claims. I am not repeating the audit-shopping guide. I am not repeating red-flag phrasing as a scavenger hunt. You already have that article.

The No-Logs When the Brand Isn't the Network Operator is for a brand that does not run the nodes. You, here, are buying Klox consumer. First person we is the operator you paid. If you are launching a logo on someone else's network, go read that one and do not steal this consumer essay as partner copy.

What a VPN Cannot Do is the broad limit list: anonymity, backups, 2FA, phishing, malware. Overlap exists because phishing showed up here too. The plot here is narrower: the slogan's leftover files. If you only wanted the encyclopedia of limits, you are in the wrong tab.

Account deletion is another drawer. Account Deletion for a White-Label VPN (GDPR and Store Rules) is ops for brands. Consumers still need a way to close an account. That is a policy and a button, not a magic vanish of Stripe's past invoices.

Why I split the consumer slogan

Definition posts attract people who want to believe. Limits posts attract people who already got surprised. Both are useful. Mixing them into one 8,000-word blob is how nobody finishes.

Download is still a client

None of this replaces installing the app. /download is the client. WireGuard until UDP is rude, then OpenVPN. Five seats. The slogan lives on /privacy, not in the protocol picker.

Read /privacy, then size the slogan

The live page wins. Blog posts rot. If account fields change, the policy changes. I described the shape: email, processor payments, tickets, device seats, a listed activity pile we say we do not keep, internal review, no third-party no-logs audit claimed. Confirm on the page, not in my paragraph.

Size the slogan to drawer A. Keep drawer B in view. You will be less angry at invoices. You will be less shocked that Google still knows you. You will phish less often if you remember the tunnel is not a tutor. You will not ask us for a URL history we said we do not have.

Klox consumer remains WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. Those facts do not require a fake audit. They require a client and a policy you can read.

If the leftover files are too many for you, you want a different life than a consumer VPN. That is allowed. It is not what we sell. What we sell is a tunnel, an account, and an activity claim. Hold all three.

Print the page on purchase day

Policies get dated. If you care, save a copy. The first argument about what we stored will ask what the page said then. I cannot save it for you in this JSON.

Then go use the internet

You do not need a weekly seminar on slogans. Read it once. Connect. Leave Google logged in if that is your life. Just stop calling that invisible.

Key Takeaways

No-logs does not mean invisible. It means the operator claims not to keep an activity diary: sites, DNS, home IP while connected, a session novel. It does not delete the email you typed, the invoice, five device seats, malware on the disk, a logged-in Google, a phishing form, or a lawful ask for files that actually exist.

The definition post is how to read the claim. The white-label post is who may say we when the brand is not the network. This post is the leftover pile for a consumer. Live text: /privacy.

Klox consumer is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. Internal review, not an invented third-party no-logs audit. If that is too plain, you were shopping for a movie. The tunnel is still a tunnel. Keep the password manager, keep 2FA on the mail that owns the account, and treat the portal device list as a seating chart, not as proof nobody can name you. If a pitch treats the tunnel as a new identity, that is theater. Buy the path. Keep the rest of the stack boring.

Read the live policy, not the slogan on a farm

KloxVPN's privacy page lists account data we collect and activity we say we do not. WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. No invented audit in this box.

Read KloxVPN privacy policy

Frequently Asked Questions

No. You have an email account, invoices via the payment processor, and up to five devices in the portal. No-logs is about activity files such as browsing history, not about the account disappearing.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.