If you don't run the boxes, don't write like you do.

No-Logs When the Brand Isn't the Network Operator

How a white-label VPN brand can talk about no-logs without lying: controller vs processor, privacy policy traps, and what you can honestly say when you don't run the nodes.

KloxVPN Team
19 min readPublished 2024-05-13Updated 2026-04-27
No-Logs When the Brand Isn't the Network Operator
If you don't run the boxes, don't write like you do.

No-logs is the easiest sentence to steal and the hardest one to defend. A white-label VPN brand wants the sentence because every competitor has it. The brand does not run the packet path. The platform does, or the brand's own servers do if they bought source and actually deployed it. Those are different worlds. Most launches live in the first one and write copy for the second.

I am not interested in scaring you off the words. I am interested in you surviving a customer, a journalist, an app store reviewer, or a regulator who asks 'who stores what.' If your privacy policy says 'we never log' and your contract says the provider processes connection metadata for abuse, you do not have a policy. You have a future screenshot.

Controller versus processor is the boring legal split that marketing keeps skipping. Skip it and you will publish a homepage that talks like a network operator. You are a brand. Sometimes you are a controller for billing email. Sometimes you are a joint mess. Write the mess down before you publish the slogan.

This is not a KloxVPN claim that we are Mullvad, or that a white-label partner inherits someone else's court history. Mullvad's no-logging policy is a useful example of how a network operator writes logs language in public. I will point at it as a specimen. I will not paste it onto your brand. Your brand did not earn that page.

If you need the consumer version of no-logs, we already have a primer and a policy-reading guide. This piece is for people putting their logo on a client they did not compile from scratch, or putting a domain in front of a hosted network. The failure mode is not 'forgot a cookie banner.' The failure mode is a first-person promise about servers you cannot ssh into.

Related reading: Linux ad_blockers: Not a VPN Setting and White-Label VPN and App Store Age Rating. White-Label VPN and Export Compliance and No-Logs VPN: What It Really Means. What is a VPN? and Download KloxVPN.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

The split: brand vs network operator

The user sees one logo. The packet sees a server. Those identities only match if you run the nodes under your own ops. On a hosted white-label model, they do not match. Your app, your Stripe, your support mailbox. Someone else's rack, someone else's daemon, someone else's ability to pull a log that you swore did not exist.

You can still sell privacy. You cannot sell omniscience. The honest product is: a branded client, a billed account, and a tunnel that terminates on infrastructure described in a contract. The dishonest product is: 'we keep no logs' with no 'we,' no 'what,' and no 'who.'

White-label branding versus the VPN tunnel
Your logo is packaging. The tunnel is still WireGuard, OpenVPN, OpenConnect, and Shadowsocks.

    How to read this page

  1. 1Skim the seating / order diagram.
  2. 2Do the numbered steps once on your real network.
  3. 3Use the FAQ if a sentence was too long.
  4. 4Follow one related article — not ten tabs.

What the user thinks 'we' means

When a privacy page says we, users hear the brand they paid. They do not hear a processor annex. If you are not ready for that, do not use we for node operations. Use named roles. 'Your account data is held by [brand]. The VPN network is operated by [provider] under a processing agreement.' It is uglier than a slogan. It is also the sentence that keeps you out of a trap.

I would rather lose a few conversions than win them with a we that collapses in email one.

Hosted vs source changes the 'we'

Hosted: the platform operates servers. You operate a brand, billing, and usually the controller role for customer accounts. Source: you can operate servers. You still might use a cloud host, which is another processor. Source is not automatic moral purity. It is more ssh and more homework.

Do not write hosted copy that sounds like source. Do not write source copy that ignores the cloud provider you actually used. The user does not care about your invoice layout. They care who could have seen a source IP.

Controller vs processor, in sentences a founder can repeat

A controller decides why personal data is processed and how. A processor processes it on the controller's instructions. VPN businesses love to reverse these words because 'processor' sounds weaker and 'controller' sounds like blame. Blame is the point. Someone has to be accountable for the privacy notice.

For a typical hosted white-label consumer brand: you decide to collect email and payment status so you can sell a subscription. That is controller territory for account data. The network operator may process technical data to run the service. Whether they are a processor, a separate controller, or a mess of both depends on the contract and on what they decide autonomously (abuse, legal process). Get a lawyer to map it. I will not fake a jurisdiction-by-jurisdiction chart here.

What Klox ships versus what this page is not
FactKloxVPNNot on this page
ProtocolsWireGuard, OpenVPN, OpenConnect, and ShadowsocksA third invented protocol
DevicesFive simultaneousUnlimited seats
YearlyFrom $2.83/monthA fake city count
Refund7-day, first purchaseAn On Demand toggle

Account data is not tunnel data

Email, password hashes, device count, invoices, refunds, support tickets. That pile exists even if the nodes forget every handshake. No-logs marketing that pretends you have no personal data is how you get a reviewer who opens your password-reset form and laughs.

KloxVPN consumer plans include 5 devices and billing from $2.83/month on the yearly plan. That billing relationship is personal data. White-label brands have their own processors (often Stripe). Name them. 'We don't log' next to a Stripe checkout without a payment section is a policy hole, not a flex.

What you must not pretend to decide

If you cannot set retention on the operator's nodes, do not publish a retention number you invented. If you cannot attest to disk wiping, do not write 'RAM-only servers' because it sounded good in a competitor FAQ. If you cannot see a warrant, do not promise how you would fight one.

You can promise how you handle account deletion in your portal. You can promise you will not build a dashboard that shows user browsing. You cannot promise a packet log you have never inspected does not exist. Inspect the contract. Ask for the operator's privacy notice. Link it. Dual notices are allowed. Dual fantasies are not.

What no-logs can honestly mean when you don't run the boxes

Honest version A: 'We do not keep browsing history in our brand systems. The network is operated by [name]. Their policy is [link]. We do not receive traffic logs from them as part of normal support.' That is a paragraph. It can be true.

Honest version B, if the contract actually says it: 'The operator's policy is no connection or usage logs as described here [link]. We are not given those records to debug tickets.' Still a paragraph. Still not 'we are invisible.'

Dishonest version: 'We never log anything' on a site that has Google Analytics, a chat widget, and a password-reset audit trail. Anything is a word that will hang you.

WireGuard versus OpenVPN
Klox ships four protocols: WireGuard by default, OpenVPN when UDP fails.

If the brand cannot name the operator and cannot link a policy that describes node logging, the homepage should not say no-logs in the first person.

— Operator rule of thumb, not legal advice

Support practice has to match the sentence

If agents ask for destination URLs 'to debug streaming,' you are requesting usage data even if nodes do not store it. If agents can see last-connected timestamps in admin, that is a log, even if you call it telemetry. Align the admin panel, the ticket macros, and the privacy page. The mismatch is how a Reddit user proves you wrong with a screenshot of your own dashboard.

Ask the platform what the admin actually shows. User online now? Last handshake? Bytes? Source IP? If you do not know, you cannot write a policy.

Abuse and legal process

Someone will use the network badly. Someone will send a legal request. The request will go to whichever entity looks like the operator, or to both. Your policy should say where requests should go, what you can actually produce (usually account and billing, not browsing), and that you will not invent records.

If the operator produces technical data you never saw, your public 'we had nothing' needs a footnote. 'The brand did not have traffic logs' is not the same as 'nobody did.' Precision is not optional once lawyers are in the thread.

Privacy policy traps white-label brands walk into

Trap one: copying a consumer VPN policy from a company that runs its own network, including RAM-disk poetry and audit names. Trap two: copying a SaaS policy that never mentions tunnels. Trap three: a generator that lists 'we collect IP addresses' in the website section and 'we never collect IP addresses' in the VPN section. I have read all three in the wild. They were published.

Trap four: putting the platform's company name nowhere. Trap five: putting it everywhere except the store listing, so Apple sees a different data-safety form than the site. Trap six: promising deletion in 24 hours when Stripe and your mailbox retain invoices for years. Pick a true deletion story for each pile of data.

What an operator-written logs page looks like

Read Mullvad's no-logging policy as a specimen of tone and structure: they describe what they do not store, they write as the operator of the service, and they do not hide behind a slogan with no nouns. That is the bar for a network operator. It is not a template for a brand that does not operate the network, and it is not a claim about KloxVPN.

If you are the operator (source deployment, your nodes), you still should not clone another company's page. Your disk layout is not theirs. Your payment stack is not theirs. Steal the honesty, not the sentences.

Analytics, pixels, and the silent contradiction

A no-logs VPN landing page with a full advertising pixel package is a joke people will tell without you. If you need ads, isolate them, disclose them, and do not run them inside the authenticated portal if you can help it. If you cannot help it, say so.

I would rather a quieter homepage than a privacy theater that loads six third parties before the first paragraph. Users who care will look. Reviewers who care will look. Your competitor's affiliate will look with a recorder on.

What you can say on the homepage

You can say the client encrypts traffic in transit to the VPN server. You can name WireGuard, OpenVPN, OpenConnect, and Shadowsocks if the apps include them. You can say you do not sell browsing history. You can say account data is used to bill and support. You can link /privacy and actually keep it in date.

You should not say 'anonymous' as if payment never happened. You should not say 'warrant proof.' You should not name audits you do not have. KloxVPN does not ask you to invent SOC 2. Do not invent it for yourself either. If you have no independent audit, do not imply one with a badge-shaped PNG.

Store listings are privacy policies with a character limit

Data-safety forms that say no data collected while you require an email login will get you in trouble. Match the form to the portal. If you collect crash reports, say so. If you collect none, make sure the SDK list is empty, not just the prose.

White-label means the binary might include libraries you did not personally choose. Ask for the list. Your privacy nutrition label is yours even if the module was inherited.

Support macros are public writing

Agents should not say 'we can look up your sessions' if you claim you cannot. They should not say 'we never keep emails' when the ticket system is the email. Train them on the same nouns as the policy: account data vs traffic data. If they cannot keep those nouns straight, they should not work tickets yet.

What you must not copy from consumer VPN ads

Do not copy 'independently audited' with a year and a firm you cannot produce. Do not copy a jurisdiction story that belongs to another company. Do not copy a 'we were raided and had nothing' anecdote. That anecdote is someone else's history. Wearing it is a lie.

Do not copy device counts and prices from KloxVPN consumer pages onto a white-label store listing unless those are actually your plan rules. Consumer KloxVPN is from $2.83/month, 5 devices, 7-day money-back. Your brand might be none of those. Your privacy story is not a SKU, but SKU copying often travels with policy copying. Stop both.

Affiliate landing pages are still your words

If an affiliate writes 'this brand never logs and is based in [fantasy country],' and you pay them, you will own the screenshot. Give affiliates a claims sheet. Ban the rest. VPN affiliate culture will invent audits for you if you do not police it.

I would claw back commission for banned claims. Soft feelings about partners are how false no-logs copy spreads faster than your legal page can load.

Comparisons against operators

You can say your apps include WireGuard. You cannot say you are 'more no-logs' than a company that published a detailed operator policy and a long public track record unless you have an equivalent operator story. Compete on brand, niche, language, support hours, price. Do not compete on a court case you did not have.

Billing data vs traffic data

Keep two columns on a whiteboard. Column A: identity and money. Column B: what would tell a story about where someone browsed. No-logs, if it means anything, is about column B. Column A will exist. Chargebacks require it. Tax may require it. Password reset requires an inbox.

When a user asks 'do you log me,' answer both columns. 'We keep your email and invoices. We do not keep a browsing history in brand systems. Network logging is described by [operator policy].' People can handle that. What they cannot handle is a slogan that collapses when they open the billing portal.

Device lists sit on the line

A list of device names for a 5-device plan is account data. A list of every IP those devices used as source addresses for 90 days is closer to connection logging. Know which one your admin shows. If you show last IP, say so. If you do not know, you are writing fiction.

Parents will ticket you to kick a device. You need enough account data to do that. That is not a betrayal of no-logs. It is how a family plan works. Explain it without mixing in 'we watch your traffic.'

Tickets and attachments

Users will send screenshots of URLs. That is usage-ish data in your mailbox. Retain tickets on a schedule. Do not promise you never see destinations if your streaming macro asks for the exact show title and URL. Change the macro or change the promise.

Lawful requests: who gets the letter

Expect confusion. A brand domain gets a request. A hosting provider gets a request. A payment processor gets a request. Your policy should give a contact and a scope. Your contract should say who notifies whom.

If you promise 'we notify users of every request' you may be promising something a gag rule will not let you do. Do not copy notify-all language from a blog. Get counsel. I will not improvise criminal procedure for a country I am not advising you in.

What you can produce

Usually: whether an email has an account, subscription dates, maybe invoice metadata, maybe support transcripts. Usually not: a browsing diary you claimed not to have. If a request asks for the diary and you do not have it, say you do not have it. Do not stall in a way that looks like you are searching a system that does not exist.

If the operator might have technical records, do not answer for them. Route. Document that you routed. Your future self will need that file.

The press email

A journalist will ask if you log. If you hesitate, they will write the hesitation. Have a paragraph approved before launch. Not a slogan. A paragraph with roles, links, and what you will not claim. Put the same paragraph in the press kit and the help center so they cannot be played against each other.

Contract clauses that actually matter

Ask for: what is logged on nodes, retention, who is controller for what, subprocessors, breach notice, how legal requests are handled, data export if you leave, whether support tools can see source IPs, whether you may name the operator in your policy. If they forbid naming, your public no-logs story gets harder, not easier. Hidden operators plus loud no-logs is a smell.

Ask whether you can audit. If the answer is no, do not imply you audited. If the answer is 'we have a report we can share under NDA,' that is not a homepage badge unless you are allowed to speak about it.

Exit and deletion

When you leave a platform, account data should come with you or be deleted on a written schedule. Node-side data, if any, should follow the operator's policy, not your feelings. Write both into the customer-facing deletion section so you do not promise a wipe you cannot trigger.

This is unglamorous. It is also the difference between a brand and a landing page.

Marketing approval

Put a clause that the brand will not attribute operator claims the operator did not make. Then obey it. The fastest way to poison a white-label relationship is a partner ad that invents an audit for both of you.

Building a policy you can defend

Start with a data map, not with a slogan. List systems: website, portal, billing, helpdesk, apps, push, analytics, network operator, email provider. For each, what personal data, why, retention, who has access. Then write the policy from the map. Then write the homepage from the policy. That order is slower than copying a rival. It is the only order I trust.

Publish a short 'roles' section near the top. Most users will not read it. The ones who matter will. App reviewers might. Your future buyer, if you sell the brand, will.

Version the policy

Date it. When you add a chat tool, update it. When you enable a new protocol, you probably do not need a new privacy novel, but when you add a crash reporter you do. Store listings should match the dated page.

KloxVPN's consumer privacy page lives at /privacy. A white-label brand needs its own URL on its own domain. Linking ours as if it were yours is a controller error. Do not do it.

What 'good' looks like without fake certificates

Good is specific nouns, named processors, separate columns for account vs traffic, no stolen raid stories, no SOC 2 badge you do not have, no audit PDF you cannot produce, and support macros that use the same nouns. Good is also a 7-day money-back you can execute if you offer one, because refunds are part of trust even if they are not logs.

Perfect is not available. Specific is.

Key Takeaways

No-logs is a claim about records. A brand that does not operate the network cannot wear an operator's first person without naming the operator and linking a real policy. Controller versus processor is not decoration. It is who answers when someone asks who decided to keep an email, an invoice, or a packet log.

Write account data and traffic data as two piles. Tell the truth about both. Do not copy Mullvad's operator language onto a hosted brand, and do not treat their page as a KloxVPN promise. Use it as a reminder that serious logs language has nouns. Do not invent audits. Do not invent RAM-only servers you have never seen. Do not let affiliates invent them either.

If you take source and run nodes, your we gets bigger and so does your pager. If you stay hosted, your we stays a brand, and your honesty is in the disclosure. Either path can be a real business. Only one of the homepage slogans I see in this market is usually true.

For the consumer product, read our privacy page and the no-logs primer. For a brand you want to launch, start the policy before the store screenshots. Talk to us about white-label when you want the stack. Bring questions about admin visibility and who is named in the notice. That conversation is part of launch, not a polish item for later.

Launch a brand with a policy you can read aloud

KloxVPN white-label gives you branded apps on a hosted network or a source path you can operate. We will talk through roles, admin visibility, and what your public privacy page should not invent.

See white-label VPN

Frequently Asked Questions

Only with roles spelled out. If you do not operate the nodes, do not write as if you do. Link the operator's logging policy, describe what your brand systems keep (accounts, billing, tickets), and make sure the admin panel matches the sentence.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.