Comparisons

URnetwork vs Windscribe

8 min readView as markdown ↗

Windscribe is the freemium VPN whose no-logs policy has passed a criminal court test; URnetwork splits the path so the exit never learns who you are and the operator cannot read the sealed session.

Choose Windscribe if you want a no-logs record already tested in court, a free tier large enough to use daily, and filtering you can tune. Choose URnetwork if you want residential exits, a split path, and open code on both halves. Both let you start without an email address. Windscribe has the stronger public record. URnetwork splits visibility between its operator and a member-run provider.

Windscribe is run by Windscribe Limited of Ontario, Canada, founded by Yegor Sak. It publishes open-source apps, criticizes its own industry's marketing, and writes "no identifying logs" rather than "no logs", naming the data it keeps. Its network spans 69 countries and 112 cities by its own mid-2026 count, all stated as physical locations.

URnetwork uses member-run exits. The provider does not receive your source IP on the relayed path. Native apps seal traffic to the provider by default. How URnetwork works explains the full design. The threat model holds the complete record of what is stored and enforced.

Six differences that affect the choice

WindscribeURnetwork
Trust modelOne company; its servers terminate the tunnel, and the policy governs what gets written downTwo relay parties; the exit never sees your IP, and the operator cannot read the sealed session
Exit addressDatacenter ranges in 69 countries and 112 cities, all physical by its own disclosureResidential addresses; ordinary traffic to the sites you visit
Evidence under pressureCriminal charges dismissed by an Athens court in 2025; a seized server held nothing in 2026Open client and server code; no court test, and no independent audit of the protocol or server code
Free tier10 GB/month with a confirmed email, 2 GB without, in about ten countriesA daily data allowance that resets every morning
FilteringR.O.B.E.R.T.: DNS-level ad, tracker and malware blocking with rules you setA "Block ads and trackers" toggle in every app, off by default, nothing to tune
Whole-stack sourceApps open source; servers closedClient and server code public

Caveats below the table:

  • Post-quantum encryption is on URnetwork's side of this table: the X25519MLKEM768 client-to-provider session is default in the native apps, skipping any provider it cannot seal to rather than downgrading. The browser extension has no sealed session; there, the operator's data path logs nothing, pinned by a test in the open code.
  • URnetwork ships apps on Android, iOS, macOS, Windows, and Linux plus a browser extension paired with its web app, each with an explicit kill switch toggle; the extension's defaults on.
  • Windscribe accepts cryptocurrency, and its free tier works with no email at 2 GB. URnetwork's Instant Account takes one tap and no email at any tier.
  • Windscribe Pro is about $9/month or $69/year as of mid-2026, with a per-location plan at about $1 a month per location and a small monthly minimum. URnetwork Pro is $5/month or $40/year. Current numbers are at ur.io/products.
  • Torrenting: Windscribe has historically allowed P2P. URnetwork drops BitTorrent-class traffic at each provider's exit to protect the member carrying it, lawful downloads included.

Three tests on the record

Windscribe's history is unusual in that the company published each event itself.

  • July 2021: two servers seized in Ukraine held an unencrypted OpenVPN server certificate and private key. The key could not decrypt past traffic. It could, in principle, let whoever held it impersonate Windscribe servers to users whose connections were redirected to an impostor. Windscribe disclosed the lapse and rebuilt: keys held only in memory, short-lived rotating certificates, and in time a RAM-only server stack.
  • April 2025: an Athens court dismissed criminal charges against founder Yegor Sak. A Windscribe server in Finland had allegedly been used in June 2023 to breach a system in Greece. Prosecutors subpoenaed the Finnish datacenter, took the name on the hosting bill, and charged Sak personally for an unknown user's traffic. The case ended after about two years because no activity logs existed to produce. What identified anyone at all was the rented server's billing trail, which pointed at the company.
  • February 2026: Dutch authorities seized a Windscribe server in the Netherlands. Windscribe's own report says the machine ran entirely in RAM and held nothing but a stock operating system.

Windscribe has also published three third-party security audits: the desktop apps (Leviathan Security Group, 2021), the Android and iOS apps (Leviathan, 2022), and the rebuilt RAM-only server stack (Packetlabs, 2024). None is a no-logs attestation, and Windscribe ranks them itself: "Audits are snapshots. Court cases are stress tests."

How you verify a privacy claim — point-in-time audits vs court and raid evidence vs open continuous verification
Windscribe's April 2025 dismissal is the middle kind of evidence, the adversarial kind it rates above audits. URnetwork's is the third kind: open code anyone can check on any day, with no independent examination of the protocol or the operator's server code yet.

What "no identifying logs" stores

The phrasing is deliberate, and the policy names what it keeps: a total of bytes transferred over the last 30 days, a last-activity timestamp, and the account credentials. Per-session connection data is held in memory and discarded on disconnect. Source IPs, browsing history, and records of past sessions are listed as not stored. That is a more exact disclosure than most of the industry writes.

The disclosure does not change the geometry. A Windscribe server terminates your encryption, so one position holds your source IP and your destinations at the same instant, and the policy decides what is recorded from that view. The 2021 seizure shows the operational side of the same fact: where servers can see, safety depends on discipline around every machine in the fleet, and the 2025 and 2026 outcomes are evidence that the discipline is real.

URnetwork removes the position instead. The provider never receives your source IP on the relayed path, and the sealed session keeps the operator from reading the traffic it relays, so no single party holds your identity and your destinations together. A seized relay holds no key that decrypts user traffic. What the operator does store is recorded in the threat model; a browsing history is not part of it.

The map and the free tier

Windscribe's location claims carry their own disclosure: every location is stated to be physically where it says, with one labeled novelty exception, an Antarctica location served from Toronto and named as a joke. IPinfo's December 2025 study measured Windscribe at 0% virtual locations, one of three providers in twenty to score zero, with Mullvad and IVPN. Windscribe also criticizes inflated server-count marketing, and its own numbers are modest for the category.

Advertised locations vs measured reality — share of advertised locations measured virtual or unmeasurable per provider (IPinfo, December 2025)
Windscribe, Mullvad and IVPN are the measured-0% tier. URnetwork appears as a mechanism rather than a percentage, because a provider is the presence.

URnetwork counts differently. A location exists only while a member's device is online in it, and the network geolocates the connection it observes rather than accepting a declared city; an address that resolves like a datacenter or a VPN range is detected and demoted. Windscribe's zero was measured from outside. Nobody has run that study on URnetwork.

Both free tiers are funded by subscriptions rather than by user data, and Windscribe's policy forbids selling it. The shapes differ: Windscribe's allowance is monthly, 10 GB with a confirmed email and 2 GB without, in about ten countries; URnetwork's resets daily, so one heavy weekend cannot exhaust the month, and when it runs out the connection stops rather than slowing.

Where Windscribe wins

  • Evidence under pressure. A 2025 court dismissal, a 2026 seizure that found a bare RAM-only server, and a 2021 lapse it disclosed itself. URnetwork has no adversarial test on its record.
  • Consistency. Datacenter servers behave the same every session; URnetwork's speed moves with the providers in your window.
  • R.O.B.E.R.T.: filtering with rules you set, against a single toggle.
  • A free tier measured in gigabytes per month, usable with no email at 2 GB.
  • P2P, historically allowed; URnetwork drops it at the exit by design.
  • Per-location pricing if you need only a couple of places.

Where URnetwork wins

  • The split. The exit never learns who you are, and the operator cannot read the sealed session. No single party holds identity and destinations together.
  • The exit address. Residential IPs work where datacenter ranges are blocked or flagged.
  • Reach and aim. Member devices in 90+ countries; browse countries, search for a city.
  • Whole-stack source. Client and server code are public; Windscribe opens its apps and keeps its servers closed.
  • One-tap anonymity. An Instant Account with no email, restored on a new device by its recovery phrase; on-chain USDC payment.
  • Price. $5/month or $40/year against about $9/$69, plus the daily free allowance.
  • The supply side. Members can share their connection as participants in the UR protocol. Windscribe has no equivalent role.

Limits and evidence

URnetwork's main limits:

  • No independent audit covers the protocol, the connect engine, or the operator's server code. Two 2025 third-party assessments cover other surfaces: a penetration test of the web application and API (April–May 2025), and the Leviathan MASA AL2 assessment of the Android app, which passed. Leviathan writes that its assessment "should not be read as a holistic security evaluation or comprehensive penetration test." Neither examined logging, retention, or the data path.
  • No court, raid, or seizure has tested URnetwork's storage design. Windscribe's has been tested three times.
  • The split assumes the operator and the providers in your window are independent. Nothing in the system attests that independence, the operator could itself run providers, and no outside party has measured the fleet. See the threat model, §6.1.
  • The WireGuard-compatible fallback endpoint assigns one stable tunnel address, so several providers could recognize the same client across sessions. The native tunnel is the recommended path.
  • Coverage counts are self-published on both sides, and only Windscribe's have been measured: IPinfo confirmed its all-physical claim from outside.

Windscribe's limit is structural. Its servers terminate the tunnel, so one company can see your real IP and your destinations together, and its openness stops at the apps: the servers, the part that holds that view, are closed. The record above is strong evidence about conduct. It does not change what the position can see.

Trying URnetwork costs nothing: the Instant Account takes one tap and no email, so you can test it against your own sites before paying for either product. More questions are answered in the FAQ.