Case file · VPN
Proton VPN
Audited, open-source, genuinely strong no-logs. But the account is tied to an email, and privacy-seeking sign-ups can hit a verification step.
The systematized overview
The bureau vs the internet.
8.2/10 · KYC-on-trigger (email + verification)
World-class privacy engineering with an audited no-logs record that has held up in court. But it is not identity-free: every account needs an email, and Proton documents a human-verification step (email, SMS or CAPTCHA) that is more likely to fire for exactly the VPN and Tor users who want anonymity. A great tool, but level 2, not level 0.
3 recurring praises · 3 recurring gripes
Most praised: widely trusted for the audited no-logs record and open-source apps. Most cited downside: recurring complaints about the sign-up verification (sms/captcha) for tor and vpn users.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Specs & jurisdiction.
- Jurisdiction
- Switzerland
- Intel-sharing
- Outside 14 Eyes
- Logging
- No logs (audited)
- Anon. payment
- Cash by post, Bitcoin — email required; no Monero
- Protocols
- WireGuard, OpenVPN, Stealth
- Network
- 20,000+ servers · 110+ countries
- Devices
- Up to 10
- Kill switch
- Yes
- RAM-only
- No (full-disk encryption)
- Open source
- Yes
- Audited
- Yes — Securitum, 5 consecutive years
- Free tier
- Yes (unlimited data)
The full read
Our analysis, in plain words.
Proton VPN is, on the technical merits, one of the strongest privacy tools we have reviewed. The no-logs policy is not a marketing line: it is independently audited by Securitum for the fifth consecutive year, the apps are fully open-source, and the claim has twice survived real legal pressure. In 2019 a Swiss court-approved request returned nothing because the logs did not exist, and in 2025 Proton denied all 59 VPN data requests on the same basis. That is a genuinely strong reliability record.
The reason it is not level 0 is the account layer, not the network layer. Every account is created with an email that becomes your username, and Proton openly documents a human-verification step (email, SMS or CAPTCHA) that, in its own words, is more likely to appear if you are "using a VPN, a privacy browser, Tor, or a shared IP", precisely the profile of a privacy-seeking user. Proton mitigates this by storing only a cryptographic hash of the email or phone rather than the value itself, but a reserved right to demand verification under defined conditions is the definition of KYC-on-trigger, so we rate it level 2.
Payment anonymity is real but partial. Proton accepts cash by post and Bitcoin, which is more than most, but not Monero, and both methods require you to already have an account (and cash must reference your Proton username), so the payment links back to the account rather than standing alone the way a Mullvad account number does. Android users can side-step the account entirely with a "Continue as guest" option, but that is platform-specific and does not lift the service as a whole.
The 2021 Proton Mail case is the question everyone asks, so we address it head-on: it involved Proton Mail, not Proton VPN, and Proton states the IP-logging obligation "does not extend to ProtonVPN". The honest reading is that Swiss jurisdiction can compel IP logging for some services, and Proton VPN is protected structurally by an audited no-logs design (nothing to hand over) rather than by any promise that Switzerland will never compel it.
The score, broken down
How the 8.2 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
74 × 50% = 3.7 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
90 × 30% = 2.7 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
92 × 20% = 1.8 of 10
Weighted total 8.2 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“When you first sign up, you will be asked to choose how you will receive your human verification code, either via email or SMS ... You are more likely to be shown an SMS verification prompt if you are using a VPN, a privacy browser, Tor, or a shared IP.”
What it meansA documented verification-on-trigger, aimed at exactly the privacy-seeking users we care about. Proton stores only a cryptographic hash of the email or phone, not the value itself, so it is weaker than true KYC. But a reserved right to demand verification under defined conditions is the definition of KYC-on-trigger (level 2), not no-KYC. Activity privacy is excellent; account anonymity is not guaranteed.
Read the source →“The Company reserves the right, in its sole discretion, to block or restrict access in response to any activity that deviates significantly from normal usage patterns.”
What it meansAn anti-abuse power, not an identity demand, so it does not by itself set the KYC level. But it is a discretionary right to cut off your access that account-number VPNs do not hold over you, so it belongs on the reliability ledger.
Read the source →No government ID is ever required. But account creation needs an email (it becomes your username), and Proton documents a human-verification step (email, SMS or CAPTCHA) that is more likely to fire for VPN, Tor and shared-IP users. Anonymous payment exists (cash by post, Bitcoin) but both require an existing account, and cash must reference your Proton username, so the payment is not unlinked from the account the way an account-number VPN is. Android alone offers a no-account "Continue as guest" option.
Policy review — point by point
-
Discretionary access restriction
Terms reserve the right, "in its sole discretion, to block or restrict access" for usage that "deviates significantly from normal usage patterns." Anti-abuse in intent, but a discretionary kill-switch over your access nonetheless. ↗
-
Unilateral changes to terms
Proton "reserves the right to review and change these Terms at any time", with continued use counted as consent; explicit advance notice is not mandated in the ToS itself. ↗
-
Arbitration, class-action waiver, liability cap
Disputes go to binding individual arbitration with a class-action waiver, and liability is capped at $100 or the amount you paid. Standard US-facing boilerplate, flagged for completeness. ↗
-
No government-ID requirement
Nothing in the terms requires government ID or formal KYC to sign up or pay (a VAT number may be requested for business plans only). ↗
Switzerland, outside the 5/9/14 Eyes alliances and with strong privacy law. Note the nuance the 2021 Proton Mail case exposed: Swiss authorities can compel some services to begin logging, so the protection for VPN rests on the audited no-logs architecture (nothing to hand over) rather than on an absolute legal shield.
We keep watching
Incident & policy timeline.
- 2026
Fifth consecutive annual no-logs audit passed
Securitum reviewed the production VPN infrastructure and found no logs of browsing activity, DNS queries, destination services, traffic contents or user-identifiable connection metadata. The audit covers server-side logging, not account or sign-up anonymity.
source ↗ - 2025
All 59 VPN data requests denied
Proton's transparency report shows every one of 59 legal requests for VPN user data was denied because "we do not have any customer IP information." Read this on its own: Proton Mail, a separate service, complied with thousands of orders.
source ↗ - Sep 2021
Proton Mail (not VPN) compelled to log an activist IP
A Swiss order forced Proton Mail to log a French climate activist's IP address. Proton states this obligation "does not extend to ProtonVPN." The episode shows Swiss jurisdiction can compel IP logging for email; Proton VPN is protected structurally by audited no-logs, not because Switzerland forbids compulsion.
source ↗ - 2019
Court order returned nothing
A Swiss court-approved data request could not be fulfilled because the logs it sought did not exist, an early real-world test of the no-logs claim.
source ↗
The verdict
Where it stands.
Strengths
- Independently audited no-logs, five years running
- Fully open-source apps
- No-logs held up under a 2019 court order and 59/59 denied requests in 2025
- Genuinely free tier: unlimited data, no ads
- Strong Swiss jurisdiction, outside 14 Eyes
Trade-offs
- Email is mandatory at sign-up (it becomes your username), so not identity-free
- Documented human-verification (SMS/email/CAPTCHA) more likely for VPN and Tor users
- No Monero; cash and Bitcoin both require an existing account
- Servers use full-disk encryption, not RAM-only/diskless
- Discretionary right to restrict access for abnormal usage
Across the internet
What reviewers report.
Consistently praised
- Widely trusted for the audited no-logs record and open-source apps
- The 2019 court test and 2025 transparency figures are often cited as proof it holds
- Free tier is regarded as the best genuinely-unlimited free VPN
Recurring complaints
- Recurring complaints about the sign-up verification (SMS/CAPTCHA) for Tor and VPN users
- Occasional reports of unexplained account restrictions
- Frequent conflation with the 2021 Proton Mail IP-logging case
Community sentiment is strongly positive on the privacy engineering and mixed on the account experience (verification friction). No corroborated pattern of VPN-side data betrayal exists; the recurring concerns are about account anonymity and sign-up friction, consistent with our level-2 rating.
Keep exploring
Related lists & categories.
Ask the bureau
Proton VPN, common questions.
Is Proton VPN no-KYC?
Not fully. The no-logs policy is strong, audited, and has held up in court, but creating an account requires an email and can trigger a human-verification step (SMS, email or CAPTCHA), so the account is not identity-free the way an account-number VPN is. We rate it KYC-on-trigger (level 2).
Can you use Proton VPN anonymously?
You can reduce linkage with a throwaway email and by paying with cash or Bitcoin, but an email is still required, verification may be requested (more so over Tor and VPN), and payment must reference the account. On Android a no-account "Continue as guest" option exists. So activity is private, but the account is not guaranteed-anonymous.
Did Proton VPN hand over user data in the 2021 case?
No. That case involved Proton Mail, not Proton VPN, and Proton states the IP-logging obligation does not extend to Proton VPN. In 2025 Proton denied all 59 legal requests for VPN data because it holds no customer IP information.
Is the no-logs policy actually verified?
Yes, as far as server-side logging goes: it has passed five consecutive annual independent audits by Securitum and was tested in a 2019 Swiss court order that returned nothing. The audits cover the VPN infrastructure, not the separate question of sign-up anonymity.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.