Case file · VPN
Private Internet Access
Court-proven no-logs — but US-based, Kape-owned, and email-gated.
The systematized overview
The bureau vs the internet.
7.5/10 · KYC-on-trigger (email identity)
The best-tested no-logs claim in the mainstream tier: US courts subpoenaed PIA in 2016 and 2018 and got no usable user data, and three Deloitte no-logs audits back it up. But sign-up needs an email, the terms reserve a right to verify your identity, it sits in the US (Five Eyes), and it is Kape-owned. Exceptional on logging, weaker on anonymity and ownership.
3 recurring praises · 3 recurring gripes
Most praised: the court-proven no-logs record is widely cited as best-in-class evidence. Most cited downside: us jurisdiction and kape/crossrider ownership are recurring trust concerns.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Specs & jurisdiction.
- Jurisdiction
- United States
- Intel-sharing
- 5 Eyes member
- Logging
- No logs (court-proven 2016 + 2018, Deloitte-audited)
- Anon. payment
- Gift cards, crypto — email required
- Protocols
- WireGuard, OpenVPN
- Network
- ~91 countries
- Devices
- Unlimited
- Kill switch
- Yes
- RAM-only
- Yes (NextGen, out of beta 2025)
- Open source
- Yes
- Audited
- Yes — Deloitte no-logs 2022/2024/2025
- Free tier
- No
The full read
Our analysis, in plain words.
PIA has the best-tested no-logs claim in the mainstream tier. Its privacy policy states plainly that it collects "zero user logs," and that claim has been proven twice in US federal court: in a 2016 FBI hoax-bomb-threat investigation a subpoena returned only a cluster of US east-coast VPN IP addresses, and in the 2018 Ross Colby case subpoenaed records again showed nothing to hand over. Three Deloitte ISAE-3000 no-logs audits (2022, 2024, 2025) and a RAM-only NextGen network (out of beta in 2025) reinforce it. On reliability this is as strong as anything short of Mullvad's physical raid.
It is level 2, not no-KYC, for two reasons: sign-up requires an email, and the privacy policy reserves a right to verify your identity under defined conditions. Neither is a fund-freeze or a hard government-ID gate, and gift-card or crypto payment can keep billing anonymous, but they place PIA above the no-KYC floor. Both together put it at level 2, KYC-on-trigger: the mandatory email plus the reserved right to verify identity are exactly the "identity handle and a documented reserved verification right" that the methodology treats as level 2 rather than 1.
The standing caveat is governance. PIA is US-based (Five Eyes) and owned by Kape Technologies, formerly Crossrider, a firm with a documented adware history that also owns several "best VPN" review sites. The court record and audits predate and survive the acquisition, and nothing structural has changed, but an owner that could quietly alter posture is exactly the kind of trust risk this axis exists to weigh, which is why trust sits at 77 rather than higher.
The score, broken down
How the 7.5 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
68 × 50% = 3.4 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
77 × 30% = 2.3 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
90 × 20% = 1.8 of 10
Weighted total 7.5 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“we may require certain information from you in order to verify your identity and locate your data.”
What it meansA reserved right to request identifying information, plus a mandatory email at sign-up, is what puts PIA at KYC-on-trigger (level 2) rather than 1. It is not a fund-freeze or a hard ID-to-use-the-VPN gate, and PIA holds no activity logs, but the discretionary verification right plus the email handle keep it off the no-KYC floor.
Read the source →A valid email is required to register, and the privacy policy reserves a right to verify your identity under defined conditions, which is what places PIA at level 2. No government ID is requested up front, and gift-card or crypto payment can keep billing anonymous, but the email handle plus the reserved verification right keep it above level 0/1.
Policy review — point by point
-
Reserved right to verify identity
The privacy policy reserves a right to require information to "verify your identity," the basis for the level-2 rating. ↗
-
Account closure without notice
Terms: "PIA reserves the right to close your account at any given time without any given notice." A discretionary account-kill clause. ↗
-
Sole-discretion usage restriction + arbitration
PIA reserves a sole-discretion right to limit or restrict usage, and mandates AAA binding arbitration with a class-action waiver. ↗
-
No government-ID requirement
No government ID is requested to sign up or pay; gift-card and crypto payment are supported. ↗
United States, a Five Eyes member, normally a strong mark against a VPN. PIA mitigates it the way Mullvad mitigates Sweden: the risk is neutralised by outcome, since two US court subpoenas returned no user data because none is logged. The residual concern is governance (Kape ownership), not jurisdiction.
We keep watching
Incident & policy timeline.
- 2018
No-logs upheld again in US federal court
In the Ross Colby case (San Jose federal court), subpoenaed PIA records again showed no usage logs to hand over, a second real-world validation.
source ↗ - 2016
No-logs upheld in an FBI investigation
In an FBI hoax-bomb-threat investigation, a subpoena to PIA returned only a cluster of US east-coast VPN IP addresses, no user activity, because none was logged.
source ↗ - 2019
Acquired by Kape Technologies
Kape (formerly Crossrider) has a documented adtech/adware history and also owns VPN review sites. The acquisition does not undo the court record or the audits, but it is a standing governance and trust consideration.
source ↗
The verdict
Where it stands.
Strengths
- No-logs proven in two US court cases
- Three Deloitte no-logs audits
- RAM-only NextGen network
- Anonymous payment (gift cards, crypto)
- Open-source apps
- Unlimited devices, low price
Trade-offs
- Email required plus a reserved right to verify identity
- US (Five Eyes) jurisdiction
- Kape/Crossrider ownership is a documented trust question
- Discretionary account-closure and usage-restriction clauses
Across the internet
What reviewers report.
Consistently praised
- The court-proven no-logs record is widely cited as best-in-class evidence
- Cheap, unlimited devices, open-source apps
- Three Deloitte audits seen as strong ongoing proof
Recurring complaints
- US jurisdiction and Kape/Crossrider ownership are recurring trust concerns
- Email required at sign-up
- Distrust of Kape-owned VPN review sites
Sentiment splits cleanly: near-universal praise for the court-proven logging record, persistent wariness about US jurisdiction and Kape ownership. No corroborated data-betrayal or freeze pattern exists.
Keep exploring
Related lists & categories.
Ask the bureau
Private Internet Access, common questions.
Is Private Internet Access no-KYC?
Not fully. Its no-logs record is strong, court-tested and Deloitte-audited, but sign-up requires an email, the terms reserve a right to verify your identity, and it is US-based and Kape-owned, so it is not identity-free. We rate it KYC-on-trigger (level 2).
Has PIA ever handed over user activity?
No. In two US court cases (the 2016 FBI investigation and the 2018 Ross Colby case) subpoenaed records showed PIA had no usage logs to provide, a strong real-world signal, though you are still trusting the operator rather than an account-number architecture.
Is the no-logs claim independently verified?
Yes, twice over: it has been proven in two US federal court cases and independently audited by Deloitte three times (2022, 2024, 2025) under the ISAE-3000 standard.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.