Most VPNs say "no logs" without saying what that actually covers. This page exists so you don't have to take that on faith — here is exactly what CarrotVPN collects, exactly what it never collects, and how long anything we do collect is kept. For a broader look at how to evaluate any VPN's no-logs claim (including ours), see our explainer on what a no-logs policy really means.
Table of Contents
Our No-Logs Statement
"We do not collect, store, or share any logs of your VPN activity — including browsing history, DNS queries, IP addresses, connection timestamps, session duration, or data content. Your online activity is completely invisible to us."
This statement covers your VPN activity specifically — what you do once connected. It does not mean CarrotVPN collects zero data of any kind; the App still needs a small amount of non-activity data to run (crash reports, ad delivery, purchase confirmation). The breakdown below draws that line explicitly, item by item.
Data-by-Data Breakdown
What We Do Collect (Non-VPN)
The items marked "collected" above are not VPN activity — they're the minimum needed to keep a free, ad-supported app running:
- Crash and performance data is aggregated and anonymized. It tells us "the app crashed on X Android version" — not who you are or what you were doing when it happened.
- Advertising identifiers are used by our ad network to serve and measure the ads that fund the free tier. This is separate infrastructure from the VPN tunnel itself and has no visibility into your VPN traffic.
- Purchase confirmation applies only if you buy an in-app upgrade. Google Play Billing handles the transaction; we receive confirmation that a purchase was made, not your card details. See our Refund Policy.
Retention Periods
Since VPN activity data (browsing, DNS, IP, timestamps, session data) is never collected in the first place, there is no retention period to disclose for it — there's nothing sitting on a server waiting to be deleted. Aggregated crash data and advertising data are retained only as long as needed for debugging and ad measurement, per our providers' standard retention windows, and are not linked back to your VPN sessions.
Jurisdiction
CarrotVPN is developed by Vinnorokom IT, based in Bangladesh. A no-logs policy is only as strong as the data a company actually has to hand over — and since we don't collect VPN activity logs, there's nothing to disclose even if legally compelled to respond to a request. We have never received a government or law enforcement request for user VPN activity data; if we ever did, our answer would be the same regardless of who's asking: we have no logs to provide.
How to Think About Verifying This
Any VPN's no-logs claim, including this one, is ultimately a policy statement rather than something you can directly inspect from outside the company. Reasonable ways to weigh it:
- Check specificity — vague claims ("we log minimal data") are a weaker signal than the itemized breakdown above
- Check the business model — CarrotVPN is funded by in-app advertising, not by selling user data, which is consistent with not collecting activity logs in the first place
- Check consistency — this page, our Privacy Policy, and CarrotVPN's Google Play Data Safety listing should all describe the same practices; if you spot a mismatch, tell us
Nothing to Log, Nothing to Leak
WireGuard® encryption, zero VPN activity logs, free on Android.
Download CarrotVPN Free