What your VPN can actually hand over
A subpoena asks for what exists, not what was advertised. Here are the four things a VPN provider can be made to produce.
July 21, 2026 · 9 min read
TL;DR — A legal request asks a provider for what it has, not what it advertised. Providers hold up to four separate categories of data, and “no logs” usually only covers two of them. The question worth asking isn’t whether your provider promises to protect you — it’s what would physically be in the envelope if it couldn’t.
Every VPN company on earth will tell you it protects your privacy. Almost none of them will tell you what they would actually put in an envelope if a court told them to. The two are very different questions, and only the second one has a factual answer.
This piece is about that second question. Not what providers promise — what they possess. If you finish it able to work out what your own provider is sitting on, it has done its job, whether or not that provider is us.
A request arrives. What happens next?
Law enforcement contacts a VPN provider roughly the way it contacts any other company: through the legal process of whatever jurisdiction the provider is incorporated in, or through a mutual assistance treaty that reaches it. What arrives is a demand for specific records about a specific account or IP address at a specific time.
At that point the provider has three honest options. Produce what it has. Say it does not have it. Or lie, which is a criminal offence in most of the jurisdictions where VPN companies choose to incorporate. Marketing copy is not an option. This is the moment where an architecture decision made years earlier turns into either a file or a shrug.
Which is why the useful question is never “would they fight for me?” A provider that wants to fight can still lose. A provider that never wrote the record down has nothing to lose with.
The four things a provider could hand over
Almost everything a VPN could be asked for falls into one of four buckets. They are technically independent of each other, which is exactly why a single phrase like “no logs” is such a poor summary.
1. Who the account is
Email address, name on the card, billing address, the app-store ID that pays the subscription. This is identity data, and most providers hold all of it — including many that advertise no logs, because the phrase almost never refers to this category.
2. When you connected
Session metadata: connection and disconnection timestamps, which server, how many bytes moved, and often the real source IP address you connected from. Correlate this with a timestamp from somewhere else and it identifies a person, no browsing history required.
3. What you did
DNS lookups, destination addresses, visited domains. Genuinely rare to retain, universally denied, occasionally discovered anyway. When a “no logs” provider is caught out, it is usually this bucket or the one above.
4. What you do next
A live interception order, targeting one account going forward rather than asking about the past. No amount of not-logging prevents this, because it does not ask for records — it asks for a tap. Honest providers say so out loud.
Why “no logs” is a claim about two of four
When a provider says it keeps no logs, it is nearly always talking about buckets two and three. That can be perfectly true and still leave bucket one intact — a full identity file, sitting in a customer database, one subpoena away.
This is the gap that catches people out. You can read a privacy policy, find a genuine, audited, technically enforced no-logs claim, and still be one email address away from being named. The tunnel was never the weak part. Signup was.
A no-logs policy protects the record of what you did. It does nothing about the record of who you are. Most providers only fixed the first one.
What we would produce, in full
Here is our own answer, stated as a list rather than an adjective. If a valid order arrived tomorrow, this is the complete set of things that exist to hand over:
- A 16-digit account number Generated at signup. It is not derived from anything about you and it is not connected to a name, an email address or a device.
- Whether that subscription is currently active A yes or a no, plus the plan length. Useful to precisely nobody.
- A payment reference If you paid by card, the processor knows who you are — we receive a reference, not an identity. If you paid in Monero, there is no such reference to receive.
There is no fourth item. No browsing history, no DNS record, no user-attributable IP log, no email address, no name. Not because we would refuse to look them up, but because the code never writes them. That claim is independently audited across 131 controls, and the report is on our transparency page rather than summarised in a badge.
The honest addition, because the four-bucket list above applies to us too: bucket four is not something an architecture can refuse. If we were ever compelled to start collecting data on a specific account going forward, we would be subject to that like anyone else. Our warrant canary exists precisely so that silence carries information.
Four questions to ask your own provider
You do not need a lawyer for this. You need a privacy policy, a search box and about ten minutes. Ask these in order — each one narrows the field:
- “What do you need to create my account?” If the answer includes an email address, bucket one is populated, whatever the homepage says about logs. See what the alternative looks like.
- “Do you retain the source IP I connect from?” Search the policy for “connection”, “session” and “diagnostic”. Timestamps plus a source IP is an identification, even with zero browsing history.
- “Who verified this, and can I read the report?” A no-logs claim with no external audit is a sentence someone wrote about themselves. The audit question deserves its own answer.
- “What would you produce if compelled?” Ask it directly, by email. A provider that cannot answer with a short list has either not thought about it or does not want to write the list down.
Nothing to hand over, by design
An account is a 16-digit number. No email, no name, no browsing history, no user-attributable IP log — audited across 131 controls, not asserted in a banner.
Get LunoVPN See pricing