TunnelBear VPN Logging Practices: An In-Depth Review and Analysis

When it comes to choosing a virtual private network (VPN) service, the provider‘s logging policy is one of the most critical factors for privacy-conscious users. Many VPN services claim to keep "no logs" of user activity, but not all live up to that promise. As a cybersecurity expert with over a decade of experience, I‘ve seen firsthand how logging practices vary widely across the VPN industry.

In this comprehensive review, I‘ll be taking a deep dive into the logging practices of TunnelBear VPN. TunnelBear has built a reputation as a user-friendly and privacy-focused VPN provider, but does it truly walk the walk when it comes to protecting user data? Let‘s find out.

TunnelBear VPN Overview

Founded in 2011 by Daniel Kaldor and Ryan Dochuk, TunnelBear is a Canada-based VPN provider known for its playful bear-themed branding and user-friendly apps. In 2018, TunnelBear was acquired by antivirus giant McAfee, but continues to operate as a separate entity.

TunnelBear offers VPN apps for Windows, Mac, Android, iOS, and browsers like Chrome and Firefox. It uses military-grade AES-256 encryption and supports secure VPN protocols including OpenVPN, IKEv2, and WireGuard. TunnelBear has a network of 1,800+ servers across 49 countries.

One of TunnelBear‘s key selling points is its no-logging policy. On its website and in marketing materials, TunnelBear claims to keep "no logs" of user activity or personal data. But what does that really mean? Let‘s take a closer look.

TunnelBear‘s No-Logging Policy

What is a no-log VPN?

A "no-log" or "zero-log" VPN is one that does not collect or store any logs of user activity or connection data. This means the VPN provider has no records of what websites you visit, what files you download, or what apps you use while connected to the VPN.

No-log VPNs provide the highest level of privacy, as there are no logs that could potentially be accessed by authorities or hackers. Even if a no-log VPN provider were compelled to hand over user data, it would have nothing to give.

TunnelBear‘s logging claims

In its privacy policy, TunnelBear makes the following clear no-logging promises:

"TunnelBear does NOT store users originating IP addresses when connected to our service and thus cannot identify users when provided IP addresses of our servers. Additionally, TunnelBear does NOT keep logs on user activity, including no logging of browsing history, traffic destination, data content, or DNS queries. In sum, TunnelBear does not store any information that would allow us to match an IP address to an account."

Specifically, TunnelBear states it does not collect any of the following data:

  • IP addresses visiting the TunnelBear website
  • IP addresses upon VPN connection
  • DNS queries while connected
  • Details of applications, services, or websites used while connected

This covers all the key bases for a no-log VPN. By not collecting any IP addresses, traffic logs, or DNS queries, TunnelBear ensures it has no records of what users do while connected to the VPN.

What data does TunnelBear collect?

Like any VPN service, TunnelBear does need to collect some basic data for operational purposes. According to its privacy policy, TunnelBear collects the following information:

  • Email address (for account correspondence)
  • Payment information (if using a paid plan)
  • Total lifetime amount of data used (but not specific usage details)
  • TunnelBear app diagnostics and crash reports
  • OS version of your device and TunnelBear app version (for troubleshooting)

Importantly, none of this collected data can be used to identify an individual user‘s online activities. And as we‘ll cover later, TunnelBear has taken steps to verify its no-logging claims through independent audits.

So on paper, TunnelBear appears to be living up to its no-logging promises. But there are a few other factors to consider when assessing TunnelBear‘s privacy practices.

Jurisdiction and Ownership

Canada (Five Eyes)

One potential red flag with TunnelBear is that it‘s based in Canada, a member of the Five Eyes intelligence alliance. The Five Eyes countries (US, UK, Canada, Australia, and New Zealand) have agreements to share intelligence data and have been known to engage in mass surveillance of internet activity.

In theory, this means Canadian authorities could compel TunnelBear to log user data and hand it over. However, if TunnelBear is truly keeping no logs as it claims, there would be no data to provide, even under a gag order.

As TunnelBear states in its privacy policy: "As TunnelBear does not have any information regarding our customers‘ online activities, there is nothing for law enforcement agencies to request."

McAfee ownership

As mentioned earlier, TunnelBear was acquired by US cybersecurity firm McAfee in March 2018. This initially raised some concerns among privacy advocates, as the US is an unfavorable jurisdiction for VPNs due to surveillance programs and data retention laws.

However, TunnelBear has continued to operate independently as a separate entity from McAfee. According to TunnelBear, the acquisition has not affected its privacy practices or no-logging policy in any way.

In a blog post addressing the acquisition, TunnelBear co-founder Daniel Kaldor wrote:

"McAfee recognizes and respects the trust that TunnelBear users have placed in us over the years, and I‘m confident that we will continue to uphold the values that we have built our company on. To put it simply, TunnelBear will continue to be TunnelBear."

Of course, as users we have to take TunnelBear at their word on this. But as I‘ll detail below, TunnelBear does have a strong track record of transparency.

Transparency Reports and Audits

Annual security audits

To back up its security and no-logging claims, TunnelBear undergoes annual independent security audits. These audits, conducted by respected cybersecurity firms Cure53 and Verified, are intended to identify any vulnerabilities or logging discrepancies in TunnelBear‘s service.

The most recent audit, performed by Cure53 in 2022, concluded:

"As part of the tests conducted for this audit, the four members of the Cure53 team can confirm that no logging or storage of personal identifiable information is taking place at any point during a VPN connection setup with the TunnelBear applications."

Previous audits from 2017-2021 have also verified TunnelBear‘s no-logging claims. While not a complete guarantee, these audits provide a higher level of assurance than most VPNs offer.

It‘s worth noting that TunnelBear limits the scope of its audits to only its client apps, not its server network or infrastructure. A full end-to-end audit of the entire VPN service would be even better from a transparency perspective. Still, TunnelBear is ahead of the curve compared to most VPNs.

Regular transparency reports

TunnelBear also publishes regular transparency reports detailing any requests for user data it has received. According to TunnelBear‘s 2022 transparency report, it received 11 requests from law enforcement over the past year, but did not provide any user data in response:

"TunnelBear received 11 requests for subscriber data from law enforcement agencies in 2022. We did not provide any information in response to these requests as we do not log any of our subscribers‘ activity."

Furthermore, TunnelBear is committed to disclosing any requests it receives, including secret gag orders. As stated in its transparency report:

"Situations may arise where we are legally required by a court order to keep a request secret. However, if that were to happen, we require an expiration date after which we would disclose the request to the public."

Handling of DMCA complaints

One area where some VPNs have been caught logging is in their handling of copyright infringement notices. Under the US Digital Millennium Copyright Act (DMCA), copyright holders can file complaints against VPN providers for users downloading copyrighted content.

Some VPN services have handed over user data in response to DMCA notices, calling their no-log policies into question. However, TunnelBear states unequivocally in its privacy policy that it does not log any user activity in relation to DMCA notices:

"It is our policy to not log what our users do online. Because of this, we are unable to identify particular users that may be violating copyrights. If we receive a valid DMCA takedown notice, our support team will respond noting that we do not log user activity."

Connection and disconnection logs

VPN providers often claim they do not log user activity, but do log limited metadata about VPN connections such as timestamps and number of connections. For example, NordVPN admits in its privacy policy that it logs "the timestamp of the last successful login attempt."

However, TunnelBear states it does not log any connection or disconnection timestamps:

"In addition to not logging browsing activities and originating IP addresses, TunnelBear also does not log connection timestamps, session duration, or bandwidth used that could be used to determine user behavior."

Ideally a VPN would not keep any logs at all, but connection logs are not as big a privacy concern as traffic or IP address logs. Still, it‘s a plus that TunnelBear doesn‘t collect this metadata while some competitors do.

Logging Comparison to Other VPNs

To put TunnelBear‘s logging practices in context, let‘s see how they stack up against some other major VPN providers. A 2021 study by the Commonwealth Scientific and Industrial Research Organisation (CSIRO) examined the privacy policies and logging claims of over 200 VPN services.

The study found that while 84% of surveyed VPNs claimed to keep no logs, only 14% explicitly stated they collected no user data that could potentially be linked to an individual account. Notably, TunnelBear was one of the few VPNs that fell into this 14% "verified no-logs" category.

Here‘s how TunnelBear compares to a few other big names in the VPN industry:

VPN Provider No-Log Policy Connection Logs IP Address Logs Browsing Logs Jurisdiction
TunnelBear Yes No No No Canada (Five Eyes)
NordVPN Yes Yes (last successful login timestamp) No No Panama
ExpressVPN Yes Yes (dates connected to VPN) No No British Virgin Islands
ProtonVPN Yes No No No Switzerland
Private Internet Access Yes Yes (connection timestamp) No No USA (Five Eyes)

As you can see, while all these VPNs claim to be "no-log", most do admit to keeping some form of connection metadata. TunnelBear and ProtonVPN are the only ones that state they keep no connection logs whatsoever.

Of course, we have to rely on these VPNs to be truthful in their privacy policies. But TunnelBear is one of the few to put its money where its mouth is with annual independent audits. The only other VPN on this list that comes close is ExpressVPN, which has also undergone partial audits of its server network.

Analysis and Conclusion

Based on my analysis of TunnelBear‘s privacy policy, transparency reports, and audit results, I believe TunnelBear is one of the rare VPN providers that lives up to its no-logging claims. By not collecting any IP addresses, traffic logs, DNS queries, or connection timestamps, TunnelBear ensures it has no data that could be tied to an individual user‘s activity.

Of course, no VPN is completely without privacy tradeoffs. TunnelBear‘s jurisdiction in Canada is not ideal, as it opens up the potential for data requests from Five Eyes authorities. And its ownership by US-based McAfee may give some users pause.

However, these concerns are largely offset by TunnelBear‘s strong track record of transparency. The fact that it publishes regular transparency reports and submits to annual independent security audits shows a genuine commitment to user privacy.

TunnelBear also deserves credit for being more transparent about its logging practices than many competitors. While other VPNs may claim to keep "no logs" in marketing, the fine print of their privacy policies often reveals that they do collect some connection metadata. TunnelBear explicitly states it does not log things like timestamps that other "no-log" VPNs admit to keeping.

At the end of the day, logging comes down to trust. No VPN can completely prove that it doesn‘t keep logs. But by being transparent and backing up its claims with audits, TunnelBear has earned a higher level of trust than most.

As a cybersecurity professional, I would have no qualms about recommending TunnelBear to anyone looking for a truly log-less VPN solution. While it may not be the fastest or most feature-rich VPN out there, TunnelBear is hard to beat when it comes to privacy and transparency.

The only users I would hesitate to recommend TunnelBear to are those with exceptional threat models, like journalists and activists in high-risk countries. For those users, I would lean towards an audited provider in a more privacy-friendly jurisdiction, such as ProtonVPN or Mullvad.

But for the vast majority of users just looking to protect their online privacy from snooping ISPs and data-hungry advertisers, TunnelBear is an excellent choice. Its easy-to-use apps, robust encryption, and independently verified no-logging policy make it a top contender for privacy-focused VPN shoppers.

References

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

Similar Posts