noKYCme

Case file · VPN

Private Internet Access

Court-proven no-logs — but US-based, Kape-owned, and email-gated.

KYC-on-trigger · Level 2
Based
United States
Price
From ~$2–12 / month
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

7.5/10 · KYC-on-trigger (email identity)

The best-tested no-logs claim in the mainstream tier: US courts subpoenaed PIA in 2016 and 2018 and got no usable user data, and three Deloitte no-logs audits back it up. But sign-up needs an email, the terms reserve a right to verify your identity, it sits in the US (Five Eyes), and it is Kape-owned. Exceptional on logging, weaker on anonymity and ownership.

What the internet says

3 recurring praises · 3 recurring gripes

Most praised: the court-proven no-logs record is widely cited as best-in-class evidence. Most cited downside: us jurisdiction and kape/crossrider ownership are recurring trust concerns.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Specs & jurisdiction.

Jurisdiction
United States
Intel-sharing
5 Eyes member
Logging
No logs (court-proven 2016 + 2018, Deloitte-audited)
Anon. payment
Gift cards, crypto — email required
Protocols
WireGuard, OpenVPN
Network
~91 countries
Devices
Unlimited
Kill switch
Yes
RAM-only
Yes (NextGen, out of beta 2025)
Open source
Yes
Audited
Yes — Deloitte no-logs 2022/2024/2025
Free tier
No

The full read

Our analysis, in plain words.

PIA has the best-tested no-logs claim in the mainstream tier. Its privacy policy states plainly that it collects "zero user logs," and that claim has been proven twice in US federal court: in a 2016 FBI hoax-bomb-threat investigation a subpoena returned only a cluster of US east-coast VPN IP addresses, and in the 2018 Ross Colby case subpoenaed records again showed nothing to hand over. Three Deloitte ISAE-3000 no-logs audits (2022, 2024, 2025) and a RAM-only NextGen network (out of beta in 2025) reinforce it. On reliability this is as strong as anything short of Mullvad's physical raid.

It is level 2, not no-KYC, for two reasons: sign-up requires an email, and the privacy policy reserves a right to verify your identity under defined conditions. Neither is a fund-freeze or a hard government-ID gate, and gift-card or crypto payment can keep billing anonymous, but they place PIA above the no-KYC floor. Both together put it at level 2, KYC-on-trigger: the mandatory email plus the reserved right to verify identity are exactly the "identity handle and a documented reserved verification right" that the methodology treats as level 2 rather than 1.

The standing caveat is governance. PIA is US-based (Five Eyes) and owned by Kape Technologies, formerly Crossrider, a firm with a documented adware history that also owns several "best VPN" review sites. The court record and audits predate and survive the acquisition, and nothing structural has changed, but an owner that could quietly alter posture is exactly the kind of trust risk this axis exists to weigh, which is why trust sits at 77 rather than higher.


The score, broken down

How the 7.5 is built.

Privacy 3.4Trust 2.3Reliability 1.8 Headroom 2.5

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

68/100

68 × 50% = 3.4 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

77/100

77 × 30% = 2.3 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

90/100

90 × 20% = 1.8 of 10

Weighted total 7.5 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +5Accepts anonymous payment (gift cards and crypto)
  • +5No activity logs ("zero user logs"), court-proven and Deloitte-audited
  • +5RAM-only NextGen network (out of beta 2025)

Trust

  • +6Open-source apps
  • +6Three Deloitte ISAE-3000 no-logs audits (2022, 2024, 2025)
  • +5No-logs proven in two US federal court cases (2016, 2018)

The fine print, read for you

The clause they bury.

Verbatim — the catch
“we may require certain information from you in order to verify your identity and locate your data.”

What it meansA reserved right to request identifying information, plus a mandatory email at sign-up, is what puts PIA at KYC-on-trigger (level 2) rather than 1. It is not a fund-freeze or a hard ID-to-use-the-VPN gate, and PIA holds no activity logs, but the discretionary verification right plus the email handle keep it off the no-KYC floor.

Read the source →
KYC trigger threshold

A valid email is required to register, and the privacy policy reserves a right to verify your identity under defined conditions, which is what places PIA at level 2. No government ID is requested up front, and gift-card or crypto payment can keep billing anonymous, but the email handle plus the reserved verification right keep it above level 0/1.

Policy review — point by point

  • Reserved right to verify identity

    The privacy policy reserves a right to require information to "verify your identity," the basis for the level-2 rating.

  • Account closure without notice

    Terms: "PIA reserves the right to close your account at any given time without any given notice." A discretionary account-kill clause.

  • Sole-discretion usage restriction + arbitration

    PIA reserves a sole-discretion right to limit or restrict usage, and mandates AAA binding arbitration with a class-action waiver.

  • No government-ID requirement

    No government ID is requested to sign up or pay; gift-card and crypto payment are supported.

Jurisdiction analysis

United States, a Five Eyes member, normally a strong mark against a VPN. PIA mitigates it the way Mullvad mitigates Sweden: the risk is neutralised by outcome, since two US court subpoenas returned no user data because none is logged. The residual concern is governance (Kape ownership), not jurisdiction.


We keep watching

Incident & policy timeline.

  1. 2018

    No-logs upheld again in US federal court

    In the Ross Colby case (San Jose federal court), subpoenaed PIA records again showed no usage logs to hand over, a second real-world validation.

    source ↗
  2. 2016

    No-logs upheld in an FBI investigation

    In an FBI hoax-bomb-threat investigation, a subpoena to PIA returned only a cluster of US east-coast VPN IP addresses, no user activity, because none was logged.

    source ↗
  3. 2019

    Acquired by Kape Technologies

    Kape (formerly Crossrider) has a documented adtech/adware history and also owns VPN review sites. The acquisition does not undo the court record or the audits, but it is a standing governance and trust consideration.

    source ↗

The verdict

Where it stands.

Strengths

  • No-logs proven in two US court cases
  • Three Deloitte no-logs audits
  • RAM-only NextGen network
  • Anonymous payment (gift cards, crypto)
  • Open-source apps
  • Unlimited devices, low price

Trade-offs

  • Email required plus a reserved right to verify identity
  • US (Five Eyes) jurisdiction
  • Kape/Crossrider ownership is a documented trust question
  • Discretionary account-closure and usage-restriction clauses
Visit Private Internet Access No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • The court-proven no-logs record is widely cited as best-in-class evidence
  • Cheap, unlimited devices, open-source apps
  • Three Deloitte audits seen as strong ongoing proof

Recurring complaints

  • US jurisdiction and Kape/Crossrider ownership are recurring trust concerns
  • Email required at sign-up
  • Distrust of Kape-owned VPN review sites

Sentiment splits cleanly: near-universal praise for the court-proven logging record, persistent wariness about US jurisdiction and Kape ownership. No corroborated data-betrayal or freeze pattern exists.


Keep exploring

Related lists & categories.


Ask the bureau

Private Internet Access, common questions.

Is Private Internet Access no-KYC?

Not fully. Its no-logs record is strong, court-tested and Deloitte-audited, but sign-up requires an email, the terms reserve a right to verify your identity, and it is US-based and Kape-owned, so it is not identity-free. We rate it KYC-on-trigger (level 2).

Has PIA ever handed over user activity?

No. In two US court cases (the 2016 FBI investigation and the 2018 Ross Colby case) subpoenaed records showed PIA had no usage logs to provide, a strong real-world signal, though you are still trusting the operator rather than an account-number architecture.

Is the no-logs claim independently verified?

Yes, twice over: it has been proven in two US federal court cases and independently audited by Deloitte three times (2022, 2024, 2025) under the ISAE-3000 standard.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.