VPNs are well-known because they supposedly enhance your privacy and prevent you from being tracked.
In fact, “VPN” has become a word in itself, pronounced vee-pee-en, and it’s a crowded market with companies advertising online, on TV, and even in print media all aiming for your money.
Most VPNs are a free application that you can download from the internet, but you usually need a paid subscription to make it work or to unlock premium services.
The app will discover all network traffic between your device and the company's servers and "unleash" you on the internet by appearing to be located somewhere else - perhaps even in a different country - which effectively masks the true source of your data packets , and therefore makes it difficult to track you down.

The connection to privacy, we imagine, comes from the fact that VPN contains the word "private" in its name.
In fact, the “private” part of a VPN isn’t really about anonymity. The P in VPN simply refers to the idea of using a public network to transmit traffic.
In fact, if you've ever used a corporate VPN you'll be well aware that your corporate VPN fully authenticates you, perhaps with a password and a 2FA token, so the company knows who you are before you connect.
Your traffic is private because VPNs use encryption to protect raw network packets from detection, but your traffic is not anonymous when you're on the company's virtual network.
In short, the VPN itself knows who you are and sees what you're getting, even if the servers through which the encrypted VPN packets travel don't.
And that's a good thing, because it means you're only sharing that corporate network with other people who are supposed to be there and who can be held accountable for behavior , rather than with a random group of strangers.
What about the log files?
As we mentioned above, consumer VPNs can arrange to decrypt your traffic and display it online far away from where you are, so not only do they disguise your physical location (which actually improves your privacy somewhat), but they also allow you to hide your country of residence.
For many people, this is the main value of a personal VPN service – it allows them to bypass censorship that may be implemented by ISPs in their country, and it also allows them to bypass so-called geoblocking which helps them, for example, watch foreign.

But this also means that you trust the VPN provider a lot, because that provider essentially becomes your new ISP, so you need to know the extent to which it (or not) follows the laws in the various countries where it is based.
Many VPNs tell you that they “keep no logs at all,” and therefore that they wouldn’t have anything on you that they could hand over to law enforcement even if they wanted to.
However, many countries have legal mechanisms by which various authorities – with or without a warrant, depending on the jurisdiction – can compel a service provider not only to start keeping logs on specific individuals, but also to keep quiet about the fact – in other words, it is very likely that they are keeping your logs and cannot tell you even if you ask them.
Of course, some VPNs will assure you that this cannot happen because their companies are registered in countries where such legal provisions do not exist.
But any VPN knows where you are and, to some extent at least, who you are while you are using the system, and may need to keep some amount of logs in memory for some or all connections, just to make the service work reliably.
What you should assume, therefore, is that anything they know about your traffic for handling purposes while you are connected to the internet is never stored anywhere permanently, either accidentally or by design.
And history shows that ephemeral data – things that should be permanently deleted from memory when they are no longer needed and never written to disk or forwarded to another server – has a way of surviving when they shouldn't.
Besides, as you may recall, both Google and Facebook recently admitted that, sometimes, the passwords you had typed during the login process – data that was supposed to be kept only in RAM and purged after validation – were stored in log files on their respective systems .
What happened this time?
According to a report published last week by VPNMentor, its researchers came across copious amounts of user logs from seven VPNs operating out of Hong Kong.
VPNMentor reported that the affected services are: UFO VPN, FAST VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, Rabbit VPN.
Looking further we see that all seven of these products were rebranded by one primary provider – software and IT services are often sold this way, with the same (or very similar) code and back-end systems forming the core of offerings from several different franchisees.
As you probably guessed, this data was not supposed to be publicly accessible, but was exposed through a cloud database – ElasticSearch, in this case – that was not configured properly.
According to VPNMentor, approximately 1 billion database entries related to approximately 20 million users were identified, including various data fields such as the following:
Activity logs, PII (names, emails, home address), cleartext passwords, Bitcoin payment information, support messages, personal device information, technical specifications, account information, direct Paypal API links.
So it seems that these VPNs are not only collecting data they shouldn't have kept at all, like passwords, but also exposing it publicly.
