Skip to content Skip to content
LunoVPN
Privacy

What your VPN can actually hand over

A subpoena asks for what exists, not what was advertised. Here are the four things a VPN provider can be made to produce.

By the LunoVPN team
July 21, 2026 · 9 min read

TL;DR — A legal request asks a provider for what it has, not what it advertised. Providers hold up to four separate categories of data, and “no logs” usually only covers two of them. The question worth asking isn’t whether your provider promises to protect you — it’s what would physically be in the envelope if it couldn’t.

Every VPN company on earth will tell you it protects your privacy. Almost none of them will tell you what they would actually put in an envelope if a court told them to. The two are very different questions, and only the second one has a factual answer.

This piece is about that second question. Not what providers promise — what they possess. If you finish it able to work out what your own provider is sitting on, it has done its job, whether or not that provider is us.

A request arrives. What happens next?

Law enforcement contacts a VPN provider roughly the way it contacts any other company: through the legal process of whatever jurisdiction the provider is incorporated in, or through a mutual assistance treaty that reaches it. What arrives is a demand for specific records about a specific account or IP address at a specific time.

At that point the provider has three honest options. Produce what it has. Say it does not have it. Or lie, which is a criminal offence in most of the jurisdictions where VPN companies choose to incorporate. Marketing copy is not an option. This is the moment where an architecture decision made years earlier turns into either a file or a shrug.

Which is why the useful question is never “would they fight for me?” A provider that wants to fight can still lose. A provider that never wrote the record down has nothing to lose with.

The four things a provider could hand over

Almost everything a VPN could be asked for falls into one of four buckets. They are technically independent of each other, which is exactly why a single phrase like “no logs” is such a poor summary.

1. Who the account is

Email address, name on the card, billing address, the app-store ID that pays the subscription. This is identity data, and most providers hold all of it — including many that advertise no logs, because the phrase almost never refers to this category.

2. When you connected

Session metadata: connection and disconnection timestamps, which server, how many bytes moved, and often the real source IP address you connected from. Correlate this with a timestamp from somewhere else and it identifies a person, no browsing history required.

3. What you did

DNS lookups, destination addresses, visited domains. Genuinely rare to retain, universally denied, occasionally discovered anyway. When a “no logs” provider is caught out, it is usually this bucket or the one above.

4. What you do next

A live interception order, targeting one account going forward rather than asking about the past. No amount of not-logging prevents this, because it does not ask for records — it asks for a tap. Honest providers say so out loud.

Why “no logs” is a claim about two of four

When a provider says it keeps no logs, it is nearly always talking about buckets two and three. That can be perfectly true and still leave bucket one intact — a full identity file, sitting in a customer database, one subpoena away.

This is the gap that catches people out. You can read a privacy policy, find a genuine, audited, technically enforced no-logs claim, and still be one email address away from being named. The tunnel was never the weak part. Signup was.

A no-logs policy protects the record of what you did. It does nothing about the record of who you are. Most providers only fixed the first one.

What we would produce, in full

Here is our own answer, stated as a list rather than an adjective. If a valid order arrived tomorrow, this is the complete set of things that exist to hand over:

  • A 16-digit account number Generated at signup. It is not derived from anything about you and it is not connected to a name, an email address or a device.
  • Whether that subscription is currently active A yes or a no, plus the plan length. Useful to precisely nobody.
  • A payment reference If you paid by card, the processor knows who you are — we receive a reference, not an identity. If you paid in Monero, there is no such reference to receive.

There is no fourth item. No browsing history, no DNS record, no user-attributable IP log, no email address, no name. Not because we would refuse to look them up, but because the code never writes them. That claim is independently audited across 131 controls, and the report is on our transparency page rather than summarised in a badge.

The honest addition, because the four-bucket list above applies to us too: bucket four is not something an architecture can refuse. If we were ever compelled to start collecting data on a specific account going forward, we would be subject to that like anyone else. Our warrant canary exists precisely so that silence carries information.

Four questions to ask your own provider

You do not need a lawyer for this. You need a privacy policy, a search box and about ten minutes. Ask these in order — each one narrows the field:

  • “What do you need to create my account?” If the answer includes an email address, bucket one is populated, whatever the homepage says about logs. See what the alternative looks like.
  • “Do you retain the source IP I connect from?” Search the policy for “connection”, “session” and “diagnostic”. Timestamps plus a source IP is an identification, even with zero browsing history.
  • “Who verified this, and can I read the report?” A no-logs claim with no external audit is a sentence someone wrote about themselves. The audit question deserves its own answer.
  • “What would you produce if compelled?” Ask it directly, by email. A provider that cannot answer with a short list has either not thought about it or does not want to write the list down.
LunoVPN

Nothing to hand over, by design

An account is a 16-digit number. No email, no name, no browsing history, no user-attributable IP log — audited across 131 controls, not asserted in a banner.

Get LunoVPN See pricing
FAQ

Common questions

Can a VPN be forced to hand over my data?
A provider can be compelled to produce records it holds. It cannot produce records that were never created. That is the entire difference between a policy promise and an architecture decision, and it is why the useful question is what a provider has rather than what it intends.
Does “no logs” mean they have nothing on me?
Usually not. The phrase almost always refers to browsing activity and connection metadata. It rarely covers account identity — the email address, name and payment details collected at signup. A provider can hold a complete identity file and still describe itself accurately as no-logs.
What can LunoVPN produce about a subscriber?
Three things: a 16-digit account number, whether that subscription is active, and a payment reference where a payment processor was involved. There is no browsing history, no DNS record, no user-attributable IP log, no email address and no name, because the system never records them.
Does paying with Monero change what can be handed over?
It removes the payment reference. Card and app-store payments necessarily involve a processor that knows who you are; we only ever receive a reference to that transaction. Monero carries no identity at all, so that last thread does not exist.
Is a warrant canary actually useful?
It is a narrow but real signal. A provider can be barred from telling you a demand arrived; it is much harder to compel it to keep publishing a statement that is no longer true. A canary that stops being updated tells you something a press release never would.
© 2026 LunoVPN — We don’t know who you are, and that’s by design.