Tips and support
How to Choose a VPN in 2026: Jurisdiction, Audits, Logs and Payment
In April 2023, officers from the Swedish police’s National Operations Department walked into Mullvad’s office in Gothenburg with a search warrant for computers holding customer data. They left with nothing. The company says the data they wanted had never been stored, and its account system, which issues a random account number instead of asking for an email address, gave it little to hand over.
Most VPN marketing promises exactly that outcome, but very few providers have had the claim tested in public. So instead of choosing from a discount banner or a ranked list, check four things in order: where the company is based, whether outsiders have audited it, what it admits to logging, and how much personal information it needs before it will take your money.
Start with jurisdiction, but don’t stop there
A VPN’s home country decides which courts and agencies can compel it to act. That matters, but it is often oversold. Switzerland has a strong reputation for data protection, yet in 2021 Swiss authorities ordered Proton to log the IP address of a user of its email service, and Proton complied because the order was lawful. A well-chosen country tells you which rules apply. It doesn’t tell you whether the company has built its systems so that there is little to disclose in the first place.
So treat jurisdiction as a filter, then move on to the evidence.
Treat audits as evidence, and check the date
An independent audit is the closest thing the VPN industry has to proof. Proton VPN, for example, went through its fourth consecutive no-logs audit in August 2025, carried out by the European security firm Securitum at Proton’s Zurich offices. When you read an audit claim, look for three details: who did the work, when it happened, and what was in scope. A review of app code is not the same as a review of server infrastructure or logging practices. If you’d rather not track down reports provider by provider, LessKYC’s VPN section marks which services have been independently audited.
The opposite case is instructive too. In July 2020, researchers at vpnMentor found that seven free VPN apps based in Hong Kong, all advertising “no logs,” had left roughly 1.2 terabytes of user data exposed online, including connection logs and passwords stored in plain text. A promise on a sales page costs nothing to write.
Read the logging section line by line
“No logs” can mean very different things. Open the provider’s privacy policy and look for specific answers on each of these:
- Connection timestamps, and how long they are kept
- Your real IP address, even temporarily
- Bandwidth totals per session or per account
- DNS queries and whether the VPN runs its own resolvers
- Account and payment records, and their retention period
Providers that run servers entirely in memory, with no hard drives, are making a stronger technical claim than those that only promise to delete logs. Look for that detail if it matters to you.
Look at what signup and payment require
This is where providers differ most, and where you can reduce the amount of personal data you leave behind. Mullvad charges a flat 5 euros a month, needs no email, and accepts cards, PayPal, bank transfer, cash sent by post and several cryptocurrencies, with a 10% discount for crypto. IVPN also skips the email requirement and accepts Bitcoin, Lightning, cash, cards and PayPal. Proton VPN accepts Bitcoin and cash too, though Bitcoin only appears as an option after you create a free account and then upgrade.
If you would rather pay in Monero, XMRList, a community-run directory of businesses that accept it, lists more than 40 VPN services, Mullvad and IVPN among them. Each listing carries a status, and “Verified” means a user has confirmed a real Monero payment, which is a better signal than a logo on a checkout page.
Paying with a card isn’t wrong. It simply means your name and billing details now sit with the VPN and its payment processor, and every extra copy of your data is one more thing that can leak. Comparing these details across providers is tedious, which is where LessKYC, an independent directory that reviews online services and scores how much personal data they collect, saves time: its listings note whether an email is required and which payment methods each provider takes.
A short checklist before you subscribe
- Find the legal entity behind the app and the country it is registered in.
- Locate the most recent audit and note its date and scope.
- Read the logging section of the policy, not just the homepage.
- Check what signup asks for and what payment options exist.
- Use the refund window to test the app on every device you own.
- Run a DNS and IP leak test while connected.
What actually earns trust
The best VPN for most people is the one whose claims have been checked by someone other than its marketing team, that keeps as little about you as possible, and that is honest about the legal limits it operates under. Free services with vague policies rarely pass that test. Spend twenty minutes on the checks above, and you will know more about your VPN than most of its customers do.
-
Resources5 years agoWhy Companies Must Adopt Digital Documents
-
Resources4 years agoA Guide to Pickleball: The Latest, Greatest Sport You Might Not Know, But Should!
-
Resources1 year ago50 Best AI Free Tools in 2025 (Tried & Tested)
-
Resources1 year agoGet Paid $5000+ a month to write : Discover 30 Spectacular Websites That Reward Your Writing Effort
