Key takeaways
Overview
I've spent time reading the privacy policies and technical documentation of about fifteen VPN services over the past year. What I found: 'no-log' is the most consistently misleading term in the VPN industry. Not because providers are necessarily lying — but because the term has no standard definition, is used to mean different things by different providers, and the things that actually determine your privacy outcome are rarely mentioned in marketing materials. This is what I wish someone had explained to me five years ago.
'Logs' isn't a single thing. There are four distinct categories, and 'no-log policy' almost never covers all four
| Log Type | What It Captures | Privacy Risk | Usually Covered by 'No-Log'? |
|---|---|---|---|
| Activity logs | Websites visited, downloads, searches | Highest — reveals what you did | Yes — usually |
| Connection logs | Your IP, VPN IP assigned, connect/disconnect times | High — proves you used VPN when | Sometimes — often retained |
| Metadata logs | Bandwidth used, session duration | Medium — behavioral patterns | Often retained 'for billing' |
Almost never covered
The VPN you choose might legitimately claim 'no activity logs' while still retaining: connection logs (your real IP + timestamp + which VPN server), metadata (how much bandwidth you used on Tuesday), and complete billing records (your email address + payment method + subscription dates).
Under a legal request, connection logs + billing records together can link your identity to a specific VPN session, even with 'no activity logs'. This is why the logging taxonomy matters.
Jurisdiction: The Factor That Determines Whether Policies Matter
A no-log policy is only as meaningful as the legal environment that allows it to be honored. This is the most important factor that marketing materials minimize.
Jurisdictions to avoid for privacy
14 Eyes countries (US, UK, Canada, Australia, New Zealand, plus France, Germany, Sweden, Belgium, Netherlands, Denmark, Norway, Spain, Italy): extensive intelligence sharing agreements, legal mechanisms to compel data disclosure without public court orders in some cases. A VPN registered in the US or UK and claiming 'no logs' is still subject to National Security Letters (US) or equivalent secret demands.
Russia: Federal Law 374-FZ requires data retention and handover on demand. Any Russian-registered VPN must comply.
Better jurisdictions
Panama: no mandatory data retention laws, limited international cooperation agreements. ExpressVPN is registered here (though owned by Kape Technologies, UK-registered parent — jurisdiction question is complicated).
British Virgin Islands: similar to Panama. NordVPN uses this (though again, parent company structure matters).
Switzerland: strong privacy laws, not in 14 Eyes, but has Mutual Legal Assistance Treaties — not immune but strong procedural protections.
For VLESS services targeting Russia/CIS specifically: the infrastructure being outside Russian jurisdiction matters more than the company registration jurisdiction, since Russian authorities' reach is primarily geographic.
Beyond jurisdiction and policy, these technical characteristics reduce logging capability
RAM-only servers
Servers that run entirely from RAM with no persistent storage cannot retain logs across reboots. If the server is powered off or rebooted, all data disappears. This is physically verifiable (audit companies can confirm) and provides genuine no-log enforcement. Capybara VPN explicitly uses RAM-only servers — a legitimate differentiator. Mullvad also.
Open source VPN daemon
If the server-side VPN software is open source, security researchers can verify it doesn't implement logging in its code. Xray-core (used by VLESS services including INFOCROSS) is fully open source. The default Xray-core configuration doesn't log user traffic. This is a design-level privacy protection, not a policy-level promise.
No email required for account creation
If account creation requires email, there's a permanent link between your identity (email) and your VPN usage. INFOCROSS uses Telegram-bot delivery without email — minimal identity linkage. Pay with crypto and the identity linkage is very weak.
Audit verification
Third-party audits (Cure53, PwC) of server infrastructure and logging practices provide evidence beyond marketing claims. Mullvad: annually audited. ProtonVPN: regularly audited. INFOCROSS: no published audit (as of June 2026 — market is young). Capybara: no published audit. The audit gap is a legitimate weakness of the Telegram-native VLESS market segment generally.
Applying the framework above to INFOCROSS
- Activity logs: Not implemented — Xray-core default behavior, verifiable via open source code
- Connection logs: Not publicly specified — worth asking support directly
- Jurisdiction: Infrastructure outside Russia (EU servers) — Russian authorities can't compel
- Account linkage: Telegram account only (no email) — weak identity link
- Payment privacy: Crypto payment (USDT/TON/BTC) available — can break payment identity link
- Open source VPN core: Yes — Xray-core, verifiable
- RAM servers: Not explicitly stated — unknown
- Independent audit: None published — weakness vs audited competitors
For users in Russia and censored countries where the primary concern is government-level surveillance and legal compulsion: INFOCROSS's combination of non-Russian infrastructure, Xray-core defaults, and crypto payment provides practical privacy. For users concerned about Western legal requests and wanting maximum verifiable privacy: Mullvad or ProtonVPN (with audits) are stronger choices, though neither works in Russia.
✅ Bottom Line
No-log means different things to different providers. What matters: which log types are retained, jurisdiction, technical architecture (RAM servers, open source), identity linkage through payments. INFOCROSS: Xray-core (no traffic logging by design), EU infrastructure, crypto payment option, no email required. Audit gap exists vs Mullvad/ProtonVPN — trade-off for functionality in censored regions.
How INFOCROSS fits this use case
INFOCROSS VPN combines Telegram payment flow, VLESS Reality key delivery, QR setup, dashboard access, partner API, and support in one product. That makes it useful for individual users, families, Telegram communities, and projects that need reseller automation.