The VPN advert on YouTube is not selling you privacy

Paid adverts promise strong encryption and no logs. They never tell you which government can lean on the company, who owns it, or what it holds when the police ask. Here is what eleven popular VPNs really expose you to, scored by one set of rules.

Facts checked 28 September 2026

The Five, Nine and Fourteen Eyes as three rings Five Eyes at the centre, inside the Nine Eyes, inside the Fourteen Eyes. Fourteen Eyes Nine Eyes Five Eyes
A VPN company inside these rings answers to a state that shares intelligence with the others.

Read this first

If you want to watch a film that is not shown in your country, any of these will do and you can stop reading. Just do not count on Netflix, which checks for VPNs now.

If your aim is privacy, and especially privacy from a government, this page matters to you. An advert is a poor guide, and trusting one can end in a knock on the door, or worse. Read it carefully and be sure you understand what is at stake.

Disclosure

I use ExpressVPN. It is the tool I use myself, and it is scored here like the other ten, with its owner's links counted against it like anyone else's. This is not a paid advert. Nobody sponsored this page. There are no affiliate links, referral codes, advertising revenue, commissions or commercial arrangements with any VPN named here.

Every VPN name linked on this page goes directly to the provider's public website. The links contain no affiliate or referral tracking. No special price, discount, free period or other deal is being offered through this page, and none should be expected. Following a link earns this site nothing.

I wrote it because I am tired of creators on YouTube and other platforms selling low quality, and sometimes dangerous, security products that are not fit for purpose. In my view many of them check nothing beyond what the sponsor pays for the slot.

This is not a VPN review site. It is a bullshit filter: a barebones comparison designed to strip away the sales pitch and put all eleven providers against the same evidence. I am not scoring app design, streaming performance, brand reputation or marketing polish. I am pulling back the curtain on what matters if privacy is the reason you are using a VPN: server design, independent audits, real-world seizure or court tests, jurisdiction, ownership and intelligence-sharing exposure. The aim is not to sell you a winner. It is to show the balance of strengths and weaknesses once the advertising is removed.

What you are actually buying

At its simplest a VPN is a relay. Websites see the VPN company's address instead of yours, and your internet provider sees an encrypted connection to the VPN instead of the sites you visit. That is relocation. It moves where you appear to be, and it moves who can see your traffic, from your internet provider to the VPN company.

For watching something from another country's catalogue, that is all you need. It is not, on its own, protection of your identity. Whether the company that now sees your traffic can be made to hand it over, or to start recording it, depends on the five things scored below. It does not depend on the price or on the advert.

Five, Nine and Fourteen Eyes

The Five Eyes is an intelligence-sharing arrangement between five countries. Four more join to make the Nine Eyes, and five more make the Fourteen Eyes. Membership does not force a VPN company to log anything. It does mean the agencies share what they collect, and a company based in a member state answers to that state's law.

Five Eyes

  • United States
  • United Kingdom
  • Canada
  • Australia
  • New Zealand

Nine Eyes

The five above, plus:

  • Denmark
  • France
  • Netherlands
  • Norway

Fourteen Eyes

The nine above, plus:

  • Germany
  • Belgium
  • Italy
  • Spain
  • Sweden

So a VPN based in one of these countries is not automatically unsafe, but it can be ordered to act by a government that has partners. That is what the jurisdiction score measures.

Two kinds of government request

Requests about the past

A subpoena, a warrant, a raid or a formal request from a foreign police force asks for what a company already holds. The defence is engineering: nothing stored, so nothing to hand over.

RAM-only servers are the strongest form of it. Memory only holds live connections, and it is wiped when the server is powered off or rebooted. ExpressVPN says its servers wipe on every reboot, and one review reports they reboot every one to two weeks. Memory freed when a session ends is reused by new connections, so on a busy server old sessions get overwritten. [20]

To get anything out of one, investigators would have to seize it while it is switched on, keep it running, capture the memory intact and preserve it as evidence. Even then it would show only the connections live at that moment, not anyone's history.

There is also time. A request from abroad has to go through a formal process in the provider's own country. For a British Virgin Islands operator, that means a written request to the islands' Attorney General. It takes time, and by the time it lands, past sessions have gone from memory. [21]

Orders about the future

A different order asks a company to record from now on. RAM does not help, because the server can write down what happens next. Only the law of the country the company sits in decides whether that can be forced.

The United States has court orders that make a communications provider install and monitor a pen register for up to 60 days. A pen register collects metadata, not content, and the order can be sealed so the provider cannot tell the user. In the Netherlands, the intelligence services can order communication providers to help with live interception, and refusing is a criminal offence. [22] [23]

This is why jurisdiction gets its own scores. Engineering covers the past. Jurisdiction covers the future.

How the scores work

Every VPN here is marked on five things. Each has a fixed rule, so the same facts always give the same score. In every column, high is good and low is bad.

RAM-only servers, 3 points

It carries the most weight because it protects you against past requests whatever the law says. All servers RAM-only scores 3. Disks with full-disk encryption scores 1. Plain disks score 0.

Independent audits, 2 points

A named firm auditing the no-logs claim or the servers earns 1. A repeat audit adds 0.5, and so does a latest audit under 24 months old. An audit is a snapshot, which is why repeats and recent dates count. None published scores 0.

Seizure or court test, 1 point

A claim is worth more when it has been tested. A court case or subpoena on record where nothing usable was found earns 0.5. A seizure or raid confirmed by someone other than the company earns another 0.5. None found scores 0.

Operator's jurisdiction, 2 points

Where the company that runs the service sits. Outside the fourteen scores 2. Fourteen Eyes only scores 1. Nine Eyes scores 0.5. Five Eyes scores 0.

Intel protection, 2 points

Counts the links pulling a provider towards an intelligence-sharing state. A link is a parent or holding company in a Five, Nine or Fourteen Eyes state, or a move or pending law that pulls the company or its servers into one. It only counts if it adds a state beyond the operator's own. No links scores 2, and each link costs a point, so two or more scores 0.

Two worked examples

Mullvad. All servers RAM-only (3). Repeated qualifying infrastructure audits, but the latest was completed in June 2024 and is now over 24 months old (1.5). A raid by Swedish police that found nothing (0.5). Operator in Sweden, in the Fourteen Eyes only (1). No links beyond Sweden (2). Total 8.0. [24] [25] [8]

PIA. All servers RAM-only (3). Audited (2). Subpoenas that PIA says found nothing (0.5). Operator in the USA (0). One link, because Kape adds the UK (1). Total 6.5. [26] [27] [9] [1] [2]

Both run RAM-only servers and both have a record under pressure. The 1.5-point gap comes from the audit recency rule, where the operator sits and who else has a hand on it.

The scores

Jurisdiction cells are shaded to match the rings at the top: teal is outside the alliances, sand is the Fourteen Eyes, orange is the Nine Eyes, and red is the Five Eyes.

Scoring rules
MetricPtsHigh (good)Low (bad)
RAM-only servers3All RAM-only: 3. Disks with full-disk encryption: 1Plain disks: 0
Independent audits2Named firm 1, repeat +0.5, latest under 24 months +0.5None: 0
Seizure or court test1Court case or subpoena, nothing found +0.5. Confirmed seizure or raid +0.5None found: 0
Operator's jurisdiction2Outside the fourteen: 2. Fourteen Eyes: 1. Nine Eyes: 0.5Five Eyes: 0
Intel protection2No links: 2. Each link costs a pointTwo or more links: 0
Scores
VPN RAM /3 Audit /2 Test /1 Jurisdiction /2 Intel /2 Total /10 Verdict
ExpressVPN 3 2 0.5 2
British Virgin Islands
1 8.5 Strong
Mullvad 3 1.5 0.5 1
Sweden
2 8.0 Strong
CyberGhost 3 2 0 2
Romania
1 8.0 Strong
Surfshark 3 2 0 0.5
Netherlands
2 7.5 Acceptable
PureVPN 1 2 0 2
British Virgin Islands
2 7.0 Acceptable
IVPN 1 1.5 0 2
Gibraltar
2 6.5 Acceptable
NordVPN 3 2 0 0.5
Netherlands
(registered in Panama)
1 6.5 Acceptable
PIA 3 2 0.5 0
USA
1 6.5 Acceptable
Windscribe 3 1 0.5 0
Canada
2 6.5 Acceptable
ProtonVPN 1 2 0 2
Switzerland
1 6.0 Weak
TunnelBear 1 2 0 0
Canada
(US corporation)
1 4.0 Weak

How to read the scores: in every column, high is good and low is bad. The total is the five score columns added together. Verdicts: 8 to 10 strong, 6.5 to 7.9 acceptable, below 6.5 weak.

Jurisdiction: Gibraltar, the British Virgin Islands, Romania and Switzerland are outside the Five, Nine and Fourteen Eyes (2). Sweden is in the Fourteen Eyes only (1). The Netherlands is in the Nine Eyes (0.5). The USA and Canada are Five Eyes founders (0). TunnelBear is operated from Canada while its legal corporation and parent sit in the USA, so its jurisdiction score remains 0.

The links behind the intel scores

A link is a parent or holding company in a Five, Nine or Fourteen Eyes state, or a move or pending law that pulls the company or its servers into one. It only counts if it adds a state beyond the operator's own.

Which category do you need?

Answer three questions. Your most serious answer sets your category, so one high-stakes answer is enough to raise the bar. This points to a category, never to one brand, and it uses the same verdicts as the table above. It does not measure price, speed or streaming. Nothing you choose is sent anywhere: no script runs and no data leaves your browser.

1. What do you mainly want a VPN for?
2. If a court ordered your VPN company to hand over everything it holds about you, what would happen?
3. What will you be doing while connected?

Answer all three questions to see your category.

Shown when at least one answer points to government-level risk or legal consequences.

Your category: Strong

At least one of your answers points to real legal or government risk. Only providers scored Strong (8 to 10) are worth considering. Strong is the top category, not a guarantee: no provider scores 10.

Look towards

Strong, 8 to 10
  • ExpressVPN8.5
  • Mullvad8.0
  • CyberGhost8.0

Avoid

Acceptable, 6.5 to 7.9
  • Surfshark7.5
  • PureVPN7.0
  • IVPN6.5
  • NordVPN6.5
  • PIA6.5
  • Windscribe6.5
Weak, below 6.5
  • ProtonVPN6.0
  • TunnelBear4.0

Shown when your most serious answer is everyday privacy, with no government-level risk.

Your category: Acceptable or better

Your answers describe everyday privacy, not government-level risk. Providers scored Acceptable (6.5 to 7.9) or Strong will do the job. If you start handling anything sensitive, answer again: your bar will rise.

Look towards

Strong, 8 to 10
  • ExpressVPN8.5
  • Mullvad8.0
  • CyberGhost8.0
Acceptable, 6.5 to 7.9
  • Surfshark7.5
  • PureVPN7.0
  • IVPN6.5
  • NordVPN6.5
  • PIA6.5
  • Windscribe6.5

Avoid

Weak, below 6.5
  • ProtonVPN6.0
  • TunnelBear4.0

Shown when none of your answers involves privacy risk.

Your category: Any

You want a different location, not protection from anyone. Any provider in the table will do that. Some streaming services block VPN addresses, and this page does not measure that.

Look towards

Any category

Strong, Acceptable or Weak all relocate your IP address. Choose on price and how well it works with the service you want.

Avoid

Free and lifetime offers

One review site's summary of the market says most free VPNs cap your data, inject adverts or sell your browsing data, and that lifetime deals often cut corners on security. [71]

Provider by provider: what the score does not show

The score above stays deliberately narrow. It measures the five core things most relevant when legal or government pressure reaches a VPN. The three points below are not extra score columns and do not change the ranking. They show the practical privacy around the VPN account: how easily the account can be tied to a person, who physically controls the server infrastructure, and what app, website or account telemetry exists outside the VPN traffic itself. Each provider gets the same three questions, including both the protection and the weakness.

ExpressVPN, 8.5, British Virgin Islands

Identity separation. The good side is that ExpressVPN says it does not retain browsing history, DNS queries, source IP addresses, assigned VPN IP addresses, connection timestamps or session duration, so the account record is not a traffic history. It also supports payment routes such as Bitcoin and gift cards that can reduce the information attached to a purchase. The bad side is that an ordinary account still uses an email address and payment information, and card or other conventional payment methods can create an identifiable financial trail. The account can therefore identify a customer even when the VPN traffic cannot. [33]

Infrastructure control. The strong part is TrustedServer: the VPN fleet runs from RAM, does not write the operating system or apps to the server hard drive, and reloads a fresh signed software image on startup. That sharply limits persistent material on a seized server. The limitation is that RAM-only design does not by itself prove ExpressVPN owns every physical machine or data-centre layer underneath it. The public material reviewed here establishes control of the software stack and server design, but not complete physical ownership of every location. [20]

App and account telemetry. ExpressVPN's policy is explicit that usage statistics and diagnostics are kept separate from browsing content, source IPs and DNS activity. It also gives users controls over some analytics and marketing sharing. Against that, it does collect limited connection-success information, app and app-version information and, with consent where required, marketing-attribution data such as device details and advertising identifiers. Its policy names AppsFlyer for attribution, and support and website functions also involve third-party processors. That is not a browsing log, but it is still data around the account and device. [33]

Mullvad, 8.0, Sweden

Identity separation. This is one of Mullvad's strongest areas. An account is a randomly generated number and does not require a name, email address or password, and cash and privacy-oriented payment methods are available. That makes it possible to create much less of an identity trail than a conventional email-and-card account. The limitation is payment choice: PayPal, bank transfer, Swish, Stripe and similar methods can still create records outside Mullvad, and Mullvad necessarily processes some payment information when those methods are used. Anonymous account design cannot make an identifiable payment anonymous. [34] [35]

Infrastructure control. All Mullvad VPN servers run from RAM with no persistent storage. Its server list identifies whether each server is owned or rented, and rented servers are dedicated rather than shared. Mullvad says hosting providers do not have direct access to the operating system or VPN software. The weakness is that not every machine is physically owned by Mullvad. On rented hardware, the data-centre provider still owns the machine and retains the physical relationship with it, even though Mullvad restricts its software access and runs the service from RAM. [24]

App and account telemetry. Mullvad says it uses no external web analytics such as Google Analytics and does not keep activity, connection, IP or bandwidth logs tied to the account. Service monitoring is largely aggregate, and simultaneous-connection checks are handled in temporary memory. There is still operational data: the app can send its version and operating-system version to Mullvad for update checking and service statistics, and payment or support contact can create personal data. The distinction is that Mullvad says those operational counters are not used to build an identifiable VPN-activity history. [34]

CyberGhost, 8.0, Romania

Identity separation. CyberGhost says it does not keep connection logs, browsing activity, IP history or DNS activity, which protects the substance of VPN use. The account side is less anonymous. Registration and payment can involve an email address and payment information, and conventional payment processors can identify the buyer. Using a cryptocurrency payment can reduce that link, but the normal customer account is not designed around the anonymous numbered-account model used by Mullvad or IVPN. [36]

Infrastructure control. CyberGhost has unusually strong control over part of its network. Its NoSpy servers are owned and operated in its Romanian premises, and its colocated servers elsewhere are self-owned, self-controlled and self-maintained even though they sit in third-party data centres. That is the good side. The qualification is that CyberGhost itself distinguishes those machines from ordinary rented servers, so the highest level of physical control does not automatically describe every server in the worldwide fleet. [37] [38]

App and account telemetry. CyberGhost's policy says VPN activity is not logged and describes the analytics it collects as anonymous or non-personal. However, its website and service ecosystem use third-party tools including Google Analytics, Mouseflow and AppsFlyer, as well as Zendesk for support. That gives it more surrounding analytics machinery than providers that self-host everything. The positive side is that CyberGhost says those analytics are not linked to the customer's VPN traffic or browsing activity. [36]

Surfshark, 7.5, Netherlands

Identity separation. Surfshark's no-logs position protects browsing history, traffic and VPN IP information, but the account itself is identifiable through ordinary registration and payment records. This is not theoretical: in April 2026 Surfshark says an Amsterdam District Court warrant required it to confirm that a specified account existed and disclose payment-related information. The good part is what it could not disclose: it says it had no browsing, traffic or IP logs. The bad part is that an account and payment trail still existed even though an activity trail did not. [39] [11]

Infrastructure control. Surfshark says its entire VPN server network is RAM-only and is rebuilt from clean software rather than relying on persistent disks. That is strong protection against historic data surviving on a powered-down server. What is less clear from the public material reviewed here is physical ownership. Surfshark documents the RAM-only architecture and central management, but does not establish that it owns every physical server and rack across the fleet, so some physical and data-centre dependency remains. [40]

App and account telemetry. Surfshark's current privacy policy is unusually explicit about the surrounding services it uses. It names AppsFlyer and Firebase Analytics for app and marketing attribution, Iterable for marketing engagement, Purchasely for subscription flows and third-party payment providers including Stripe, Adyen, Checkout and Coingate. Surfshark says this technical and engagement data is limited and can be controlled or consent withdrawn where applicable, and it is separate from VPN browsing logs. Even so, it creates more account and device metadata outside the tunnel than a provider that avoids third-party analytics altogether. [39]

PureVPN, 7.0, British Virgin Islands

Identity separation. PureVPN's present no-logs policy is much stronger than the service involved in its 2017 case, and it says it does not retain source IPs, assigned VPN IPs, connection timestamps, browsing history, DNS queries or traffic content. The account side is a clear weakness: its current privacy policy says sign-up asks for a name, email address, password and payment method. PureVPN offers CoinPayments and says payment processors hold the financial data, which can reduce what PureVPN itself stores, but the service still begins with substantially more identity information than a numbered or email-optional account. [41]

Infrastructure control. PureVPN deliberately does not use RAM-only servers. It says it uses physical servers protected by full-disk encryption, strict access controls and an independently assessed no-logs design. Full-disk encryption is meaningful protection when a machine is powered off. The weakness is persistence: encrypted disks remain non-volatile storage, so the architecture does not remove stored state in the same automatic way as a RAM-only reboot. PureVPN also retains some virtual server locations, adding another infrastructure layer that users should distinguish from physical locations. [42] [43] [44]

App and account telemetry. PureVPN says its software analytics and statistics are for performance and service improvement and are not supposed to identify or track VPN activity. Against that, its privacy policy names a long list of third-party tools, including Google Analytics, Firebase, New Relic, Mixpanel, Facebook Pixel, Intercom and Sentry, and customer-support interactions can place a customer's name and email with third-party platforms. None of that is the same as a VPN traffic log, but it is a comparatively broad telemetry and service-provider footprint around a product sold for privacy. [41]

IVPN, 6.5, Gibraltar

Identity separation. IVPN does not require an email address or name to create an account, and it accepts cash, Bitcoin, Bitcoin Lightning and Monero as well as conventional payments. That gives a privacy-conscious user a genuine route to separating the VPN account from a normal online identity. The limitation is that IVPN still keeps account, subscription and transaction identifiers needed to operate the service, and PayPal or card processors can retain identifying payment information for years even when IVPN does not receive all of it. The privacy benefit therefore depends heavily on how the account is paid for. [45] [46]

Infrastructure control. Every IVPN gateway is dedicated bare-metal hardware rather than a shared VPS or virtual location, and IVPN says it uses strict access controls and full-disk LUKS encryption. That is strong isolation from other tenants. The weakness is ownership and persistence: the hardware is rented from data-centre partners rather than owned outright, and most of the network still boots from encrypted disks. Only a small pilot group is RAM-only, so a provider controls the physical premises and IVPN relies on encryption and access controls to protect the disks. [47] [48]

App and account telemetry. IVPN avoids advertising trackers and third-party analytics and uses a self-hosted Matomo installation. It truncates the last two octets of visitor IP addresses, which substantially reduces precision. The other side is that its website still processes browser user-agent, language, screen resolution, referrer and a shortened IP, while account and payment systems necessarily retain operational records. This is a small telemetry footprint rather than no telemetry at all. [45]

NordVPN, 6.5, Netherlands (registered in Panama)

Identity separation. NordVPN says it retains an email address, a username and a transaction or order ID for account and refund purposes, while keeping those records separate from VPN activity. It also recommends CoinPayments for users who want a more anonymous payment route. The positive side is the no-activity-log design. The negative side is that the ordinary account is still anchored to an email and payment record, so the customer identity layer is not anonymous by default. [49]

Infrastructure control. NordVPN's entire server design is RAM-only, and its trust centre says a large part of the fleet is colocated hardware owned, maintained and managed by its own team. That gives it direct control over a substantial portion of the network. It also openly says the remainder is partner-hosted. Those machines are meant to follow the same security requirements, but physical ownership and direct control are therefore not uniform across every NordVPN location. [50]

App and account telemetry. NordVPN provides diagnostic tools for troubleshooting and states that VPN activity itself is not logged. Its public account material nevertheless shows that account, billing and support data exist, and diagnostics or app analytics can create technical information about a device or installation. The useful distinction is that this is support and product telemetry rather than browsing history. The limitation is that a user seeking the smallest possible metadata footprint still has more surrounding account machinery than with a provider that requires no email and avoids third-party attribution systems. [49] [51] [52]

PIA, 6.5, USA

Identity separation. PIA creates a random P-number username and says VPN activity is not linked to the customer's account. It also says it does not store full credit-card details. The weakness is that purchasing the service requires an email address and payment processing, so the customer can still be identified at the account layer even though browsing activity is not retained. That distinction matters particularly because the operator itself is directly inside US jurisdiction. [53]

Infrastructure control. This is one of PIA's strongest technical points. PIA says its NextGen servers are physical, RAM-only machines that it buys itself and places in leased racks at data centres. It says its own team manages the hardware and third parties cannot access the racks without permission. The remaining dependency is the building around the rack: the machines still sit in third-party data centres and depend on those facilities for power, connectivity and physical hosting, even though PIA owns and administers the servers. [26]

App and account telemetry. PIA says ordinary VPN operation produces only aggregate service metrics and that identifiable usage metrics are separated from customer accounts. More detailed connection events, protocol, device identifiers and debugging information are described as opt-in reports. The website also uses anonymised Google Analytics. That is better than mandatory detailed app telemetry, but it is not a telemetry-free environment, particularly if the user opts into diagnostics. [53]

Windscribe, 6.5, Canada

Identity separation. Windscribe requires only a username and password; an email address is optional. That is a substantial privacy advantage over email-mandatory accounts. It also says it does not retain source IPs, visited sites or a historical VPN-session record. The trade-off is that it stores a payment transaction ID for 30 days on paid accounts, plus the account's total transferred bytes over a 30-day period and the timestamp of its last activity. Those records are limited, but they mean the account layer is not completely blank. [54]

Infrastructure control. Windscribe says 100% of its VPN node fleet runs from RAM and that the VPN nodes are bare-metal except for a small number of virtual machines inside its own private infrastructure. It also says its machines are single-tenant systems that it either owns or leases. That is strong separation from shared public cloud hosts. The qualification is that leased machines and the small private-VM component mean physical ownership is not universal across the whole fleet. [55]

App and account telemetry. Windscribe says its website contains no third-party analytics, tracking pixels, A/B testing platforms or social widgets, and it self-hosts its analytics. That substantially limits disclosure to outside analytics companies. It still records first-party website information such as user-agent, language, screen resolution, referring site and part of the visitor IP address, and the VPN account retains the limited bandwidth and last-activity counters described above. The strength is that this data stays largely within Windscribe rather than being distributed through a large third-party advertising stack. [56] [54]

ProtonVPN, 6.0, Switzerland

Identity separation. Proton says a Proton account can be created without supplying personal information, with an external recovery email optional rather than mandatory, and it accepts anonymous cash and Bitcoin payments. That gives users a strong route to an account that is difficult to tie to a conventional identity. The qualifications are anti-abuse verification, which can temporarily involve an email address, phone number or IP information, and conventional card payments, for which Proton says it retains the payer's name and last four card digits. The privacy level therefore depends on the sign-up and payment route chosen. [57] [58]

Infrastructure control. Proton says account data is handled on servers wholly owned and operated by Proton or its subsidiaries, it physically owns all Secure Core servers, and it owns a majority of VPN servers in Switzerland and Germany. It uses dedicated hardware and full-disk encryption throughout the VPN network. That gives strong control over its most sensitive infrastructure. The weakness is that it does not own every VPN server worldwide and its general fleet remains disk-based rather than RAM-only, so encrypted persistent storage and third-party data-centre relationships still exist. [29] [58]

App and account telemetry. Proton uses a locally installed, self-developed analytics system for its websites, says IP addresses are not retained for that analytics, and says its apps do not access location information. It may still use app statistics, crash reporting and platform-level statistics from Apple or Google to diagnose problems. That is a comparatively restrained analytics model, but it is not literally zero technical telemetry, and alternative routing can send encrypted Proton traffic through third-party networks when censorship circumvention is required. [57] [58]

TunnelBear, 4.0, Canada (US corporation)

Identity separation. TunnelBear requires a valid email address to create an account. It no longer requires a full name at sign-up, which is an improvement, and it says it never stores the originating VPN IP, DNS queries or browsing activity. For card customers, however, it stores the cardholder's last name, date of card use and last four card digits, while its payment processors can see billing information and the IP address used at payment. That leaves a considerably clearer account-to-person trail than an email-optional or anonymous-numbered service. [59]

Infrastructure control. TunnelBear says it takes control of physical servers, reformats them, encrypts the entire disk and removes the vendor's ordinary access, with administrative access protected by key authentication and two-factor authentication. That is meaningful hardening and gives it more control than a generic unmanaged virtual server. The weakness is that this is still a full-disk-encrypted design rather than RAM-only, and the machines originate with hosting vendors and sit in external facilities. If a powered-down disk is seized, protection depends on the encryption and key-management model rather than the absence of persistent storage. [60]

App and account telemetry. TunnelBear is unusually open about what it collects: OS and app version, whether the account was active in the current month, current-month bandwidth, account and payment events, geolocation for performance and abuse controls, crash reports and device information. It also uses services such as Stripe, Zendesk, Mailgun, Google Analytics and app-store processors. The good side is equally important: its policy explicitly excludes originating VPN IP addresses, DNS queries and browsing destinations, monthly bandwidth is reset rather than kept as a historical series, and it says analytics are designed around service operation rather than a record of what the user did online. [59]

What they cost, and what the discounts really mean

Prices are US dollar prices taken from each provider's own site in late September 2026, and the scores are the locked ones from the table above. Where a cell names another source, that figure is not stated on the provider's own page. UK prices differ and include VAT, and offers change week to week, so check the provider's own page before you pay.

Prices, in score order
VPN Score /10 One month Advertised long-term deal Renewal
ExpressVPN 8.5 Not shown. Its crossed-out list price works out at $14.99 Basic $2.99 a month: $83.72 for 2 years plus 4 months. Advanced $4.49, Express Pro $7.49. Basic $99.95 a year, about $8.33 a month. Advanced $119.95, Express Pro $199.95 a year
Mullvad 8.0 €5 None. A flat €5 a month, with no discounts. Same, €5 a month
CyberGhost 8.0 $12.99 $2.19 a month: $56.94 for 2 years plus 2 months. Six months $6.99 a month. $56.94 a year, about $4.75 a month
Surfshark 7.5 $16.45 (Starter) Starter $2.49 a month on the 24-month plan. One $2.79, One+ $4.49. Not stated on the plans page. Reviews report $79 a year for Starter
PureVPN 7.0 $12.95 (Standard) Standard $2.15 a month: $58.20 for 2 years plus 3 months. Standard renews at $47.95 a year after the 2-year offer
IVPN 6.5 $6 Standard $60 a year, about $5 a month. Plus $80 and Pro Suite $100 a year. No free months. Not stated on the pricing page
NordVPN 6.5 $14.99 (Basic) Basic $3.49 a month: $94.23 for 2 years plus 3 months. Complete $4.49, Prime $7.49. Basic $139.08 a year, about $11.59 a month
PIA 6.5 $11.95 $2.03 a month for 3 years plus 3 months. One year $3.99 a month. $79 every 3 years, about $2.19 a month. The one-year plan renews at $47.88
Windscribe 6.5 $9 Pro $69 a year, about $5.75 a month. Build-a-Plan from $3 a month. Free plan with 2 to 10GB a month. Same, per Windscribe
ProtonVPN 6.0 $9.99 (Plus) Plus $2.99 a month: $71.76 for 24 months. One year $3.99 a month. Free plan on one device. $83.88 a year, about $6.99 a month, per a review site quoting Proton's terms
TunnelBear 4.0 $10.99 $3.33 a month: $120 for 3 years. One year $69.99. Annual subscriptions renew at $69.99 a year; the 3-year checkout states annual renewal

How a free month works

Free months come on top of the paid term, and the advertised monthly price is the total bill divided by every month, free ones included. NordVPN's Basic bill of $94.23 is $3.49 a month over 27 months. CyberGhost's $56.94 is $2.19 a month over 26 months. ExpressVPN's Basic bill of $83.72 is $2.99 a month over 28 months. The multi-year prepayment is the sale, and the renewal is the price. [61] [62] [63]

ExpressVPN's Basic renews at about $8.33 a month. NordVPN's Basic renews at about $11.59, and CyberGhost's at about $4.75. PIA is the exception among the big discounters: its 3-year plan renews at $79 every 3 years, about $2.19 a month. PureVPN's Standard 2-year offer renews at $47.95 a year, and TunnelBear's annual renewal is $69.99. Mullvad does not discount at all, and Windscribe says its price stays the same on renewal. [61] [35] [64] [65] [62] [66] [63] [67] [68] [69]

Cheap is not the tell

It would be neat to say the cheapest are the weakest. The scores say otherwise. PIA has the lowest advertised price in the table and scores Acceptable. CyberGhost is next and scores Strong. ExpressVPN advertises the most free months, four, and also scores Strong. Windscribe has one of the higher advertised monthly prices and scores Acceptable. Across these eleven, the advertised price and the score are barely related, so a big discount is not a warning sign and a high price is not a guarantee.

What the price can tell you is different. Mullvad and IVPN sell at one flat rate with no free months and no multi-year promotion. And one review site's price index says it plainly: price reflects marketing and promotions as much as quality. [70]

Where cheap does get dangerous

Free and lifetime offers. One review site's summary of the market says most free VPNs cap your data, inject adverts or collect and sell your browsing data to pay for themselves, and that lifetime deals often compromise on security. When the product is free, the company is paid somewhere else. [71]

What the low price is paying for

On a good provider, a low price pays for scale and a long lock-in. On a bad one it pays for nothing you can see. The advert cannot tell you which, because the five things that matter are not on the price page. The headline is the number that sells, and the renewal sits in the terms. Ask what year three costs, then ask the five questions.

EU GDPR: what it does and what it does not

GDPR is the EU's data protection law and has applied since 25 May 2018. It covers how companies handle the personal data of people in the EU. It reaches beyond the EU: a company anywhere that offers services to people in the EU, or monitors their behaviour, has to follow it and must appoint a representative in the EU. Fines can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher. [72]

For a VPN user that means rights over your own data, such as access and erasure, and a duty on the company to collect no more than it needs. Sweden, the Netherlands and Romania are EU states, so it applies directly to Mullvad, Surfshark and CyberGhost. It also reaches providers outside the EU that sell to people in it. [72]

What it does not do is stop a government. Processing for national security sits outside EU law, and police use of personal data is covered by a separate law, the Law Enforcement Directive. GDPR governs how a company treats you. It does not switch off an intelligence agency's own powers, and it does not stop the Dutch interception orders described above. [73] [23]

The UK left the EU and now has its own version, the UK GDPR, built on the same rules. [72]

What Switzerland is doing

Switzerland is outside the EU and all the eyes, and for years that made it the default answer for privacy. Its current law does not force VPN providers to log. That is now under threat. [30]

The Swiss government has proposed rewriting the ordinance on surveillance of post and telecoms traffic, known by its German initials VÜPF. The draft would apply to VPN, email and messaging providers with as few as 5,000 users. They would have to identify customers with a government document, keep IP addresses and connection data for six months, and be able to decrypt what they have encrypted. It is an ordinance issued by the government, not a law passed by parliament. [30]

The first consultation closed on 6 May 2025 with a near-uniformly hostile response. In February 2026 the justice department said it had commissioned an external risk impact assessment and would prepare a second consultation. As of June 2026 there was no binding timetable, and the Federal Council had not said the project was dead. A paused law is not a buried one. [30] [31]

Proton, the best known Swiss provider, froze new Swiss data-centre spending and put the servers for its new AI assistant in Germany, with facilities also being built in Norway. It says its headquarters, legal entity and core Mail and VPN infrastructure stay in Geneva. Its chief executive has said the company would leave if the amendment passes. [31] [29] [58]

That leaves ProtonVPN exposed either way. If the rule passes and Proton stays, it has to log. If it leaves, the places it is already building servers, Germany and Norway, are inside the alliances, and the company and its data would still sit under alliance-state law. That is why it scores 1 point on intel protection, and why having no RAM-only servers matters. [30] [31] [29]

What to do with this

Read the advert as what it is: a paid script. Then ask the same five questions of any VPN, the ones in the table. Does it run RAM-only servers? Has a named firm audited it, recently and more than once? Has its no-logs claim been tested by a seizure or a court? Which country is the operator in? Who else, in which country, owns it or can pull it?

Then look at what it costs in year three, not year one. The deal in the advert is the introductory price.

No provider scores 10, and every one loses points somewhere. Nobody here is out of reach of every possible order, so pick on evidence, not on the advert.

About these ratings: the method is this site's own. It is based on public sources and company statements, checked on 28 September 2026. Companies change owners, servers and laws, so check current details before you rely on any of this. This page is information, not legal advice.

References

References are numbered in order of first use. Each numbered citation in the article jumps to its reference here. The source title in that reference then opens the original page at the exact supporting words using a browser text-fragment link, so compatible browsers such as Chrome and Edge highlight the cited passage rather than merely opening the top of the page. PDFs and pages that do not support text fragments open at the closest available location. Provider material is identified as company-published material rather than independent evidence.

  1. Kape Technologies. Our Brands [Internet]. [cited 2026 Sep 28].
  2. Kape Technologies. About Us [Internet]. [cited 2026 Sep 28].
  3. International Association of Privacy Professionals. Your VPN could be a privacy trap. Here’s how to protect yourself [Internet]. [cited 2026 Sep 28].
  4. PCWorld. VPNs and the law: How often does law enforcement actually request VPN logs? [Internet]. [cited 2026 Sep 28].
  5. Operation Saffron. Operation Saffron [Internet]. [cited 2026 Sep 28].
  6. Bitdefender Business Insights. Operation Saffron: Bitdefender joins First VPN takedown [Internet]. [cited 2026 Sep 28].
  7. ExpressVPN. ExpressVPN statement on the Andrey Karlov investigation [Internet]. [cited 2026 Sep 28].
  8. TechRadar. Mullvad’s no-log policy proven after police raid [Internet]. [cited 2026 Sep 28].
  9. Private Internet Access. Transparency Report [Internet]. [cited 2026 Sep 28].
  10. Windscribe. No Identifying Logs [Internet]. [cited 2026 Sep 28].
  11. Surfshark. Transparency Report [Internet]. [cited 2026 Sep 28].
  12. IVPN. Ethical Guidelines [Internet]. [cited 2026 Sep 28].
  13. Mullvad VPN. Policy regarding reviews, advertising and affiliates [Internet]. [cited 2026 Sep 28].
  14. ExpressVPN. Affiliate Program [Internet]. [cited 2026 Sep 28].
  15. NordVPN. Influencer Program [Internet]. [cited 2026 Sep 28].
  16. Surfshark. Affiliate Program [Internet]. [cited 2026 Sep 28].
  17. CyberGhost VPN. Affiliate Program [Internet]. [cited 2026 Sep 28].
  18. PureVPN. Affiliate Program Terms [Internet]. [cited 2026 Sep 28].
  19. TunnelBear. Affiliate Program [Internet]. [cited 2026 Sep 28].
  20. ExpressVPN. TrustedServer technology [Internet]. [cited 2026 Sep 28].
  21. Government of the Virgin Islands. Request Mutual Legal Assistance [Internet]. [cited 2026 Sep 28].
  22. Cornell Legal Information Institute. 18 U.S. Code § 3123 - Issuance of an order for a pen register or a trap and trace device [Internet]. [cited 2026 Sep 28].
  23. General Intelligence and Security Service of the Netherlands (AIVD). Must I always cooperate as a communications provider with an order to intercept or tap? [Internet]. [cited 2026 Sep 28].
  24. Mullvad VPN. Servers [Internet]. [cited 2026 Sep 28].
  25. Mullvad VPN. Audits [Internet]. [cited 2026 Sep 28].
  26. Private Internet Access. PIA Colocated Servers [Internet]. [cited 2026 Sep 28].
  27. Private Internet Access. 2025 Security Audit [Internet]. [cited 2026 Sep 28].
  28. Companies House. NORDSEC LTD company information [Internet]. [cited 2026 Sep 28].
  29. Proton VPN. Why Proton VPN does not use RAM-only servers [Internet]. [cited 2026 Sep 28].
  30. Tuta. Switzerland surveillance plan [Internet]. [cited 2026 Sep 28].
  31. heise online. Surveillance: Proton relocates parts of its infrastructure from Switzerland [Internet]. [cited 2026 Sep 28].
  32. TunnelBear. Trust [Internet]. [cited 2026 Sep 28].
  33. ExpressVPN. Privacy Policy [Internet]. [cited 2026 Sep 28].
  34. Mullvad VPN. No-logging of user activity policy [Internet]. [cited 2026 Sep 28].
  35. Mullvad VPN. Terms of Service [Internet]. [cited 2026 Sep 28].
  36. CyberGhost VPN. Privacy Policy [Internet]. [cited 2026 Sep 28].
  37. CyberGhost VPN. NoSpy Servers [Internet]. [cited 2026 Sep 28].
  38. CyberGhost VPN. Server Fleet [Internet]. [cited 2026 Sep 28].
  39. Surfshark. Privacy Policy [Internet]. [cited 2026 Sep 28].
  40. Surfshark. VPN Servers [Internet]. [cited 2026 Sep 28].
  41. PureVPN. Privacy Policy [Internet]. [cited 2026 Sep 28].
  42. PureVPN. RAM-only VPN servers: How they compare with encrypted disk servers [Internet]. [cited 2026 Sep 28].
  43. PureVPN. No-log assessment [Internet]. [cited 2026 Sep 28].
  44. KPMG. PureVPN Technical Privacy Assessment letter [Internet]. [cited 2026 Sep 28].
  45. IVPN. Privacy Policy [Internet]. [cited 2026 Sep 28].
  46. IVPN. How can I pay with cash? [Internet]. [cited 2026 Sep 28].
  47. IVPN. Service Status and Infrastructure [Internet]. [cited 2026 Sep 28].
  48. IVPN. IVPN infrastructure audit concluded [Internet]. [cited 2026 Sep 28].
  49. NordVPN. What information does NordVPN store? [Internet]. [cited 2026 Sep 28].
  50. NordVPN. Trust Center [Internet]. [cited 2026 Sep 28].
  51. NordVPN. How to get connection logs on Android [Internet]. [cited 2026 Sep 28].
  52. NordVPN. How to get NordVPN connection logs for Windows [Internet]. [cited 2026 Sep 28].
  53. Private Internet Access. Privacy Policy [Internet]. [cited 2026 Sep 28].
  54. Windscribe. Privacy Policy [Internet]. [cited 2026 Sep 28].
  55. Windscribe. NodeOS: Booting from RAM [Internet]. [cited 2026 Sep 28].
  56. Windscribe. Ethics [Internet]. [cited 2026 Sep 28].
  57. Proton. Privacy Policy [Internet]. [cited 2026 Sep 28].
  58. Proton VPN. Privacy Policy [Internet]. [cited 2026 Sep 28].
  59. TunnelBear. Privacy Policy [Internet]. [cited 2026 Sep 28].
  60. TunnelBear. TunnelBear removes Hong Kong servers to safeguard VPN network infrastructure [Internet]. [cited 2026 Sep 28].
  61. ExpressVPN. Pricing [Internet]. [cited 2026 Sep 28].
  62. NordVPN. Pricing [Internet]. [cited 2026 Sep 28].
  63. CyberGhost VPN. Pricing [Internet]. [cited 2026 Sep 28].
  64. Private Internet Access. Download and pricing [Internet]. [cited 2026 Sep 28].
  65. Windscribe. How much does it cost to use Windscribe? [Internet]. [cited 2026 Sep 28].
  66. NordVPN. How much does NordVPN cost? [Internet]. [cited 2026 Sep 28].
  67. PureVPN. Order [Internet]. [cited 2026 Sep 28].
  68. PureVPN. 1-year VPN deal and renewal information [Internet]. [cited 2026 Sep 28].
  69. TunnelBear. Checkout and pricing [Internet]. [cited 2026 Sep 28].
  70. Coppers. VPN Pricing Index [Internet]. [cited 2026 Sep 28].
  71. TheBestVPN. How much does a VPN cost? [Internet]. [cited 2026 Sep 28].
  72. International Association of Privacy Professionals. Territorial scope of the GDPR from a US perspective [Internet]. [cited 2026 Sep 28].
  73. CNIL. Law Enforcement Directive: what are we talking about? [Internet]. [cited 2026 Sep 28].