Every web request starts with a DNS lookup, and whichever resolver answers it can see the domain names requested. VPN providers often run their own resolvers, and two of the best-known alternatives are Cloudflare’s 1.1.1.1 and Google Public DNS. Both operators publish privacy statements describing what they log and for how long. This guide sets out what each statement says, and why a retention figure is a statement by the operator rather than independent proof. It is general information and does not rank resolvers or VPN services.
Why the resolver matters
Cloudflare’s documentation notes that most devices use a resolver supplied by the internet service provider by default, that some ISPs and third-party DNS providers log queries, and that DNS queries are typically sent in plaintext, so anyone on the network path can see which sites are being looked up even when page content is encrypted. Encrypted DNS changes the second point; it does not change who runs the resolver at the other end. The site’s guides to DNS leaks and to encrypted DNS cover the network-path side.
What Cloudflare states for 1.1.1.1
Cloudflare’s page for the 1.1.1.1 public resolver (the page header shows it as updated on 6 May 2026) lists commitments in its own words. Cloudflare states that it:
- will not sell or share users’ personal data with third parties, or use it to target advertising;
- will not store the source IP address in non-volatile storage, apart from randomly sampled network packets from at most 0.05% of traffic, used for troubleshooting and denial-of-service mitigation;
- anonymises source IP addresses by truncation, and deletes the truncated address within 25 hours;
- keeps limited transaction and debug logs, which are deleted within 25 hours, and shares them with no third party other than APNIC, which gets limited access to anonymised data for research.
The same page lists the log fields, which include the queried name and type, response code, data centre and country, and says aggregated statistics, such as counts of requests by region, may be stored indefinitely. It also says Cloudflare retained one of the top four accounting firms to audit its practices and publish a report, which is linked from its certifications page.
What Google states for Public DNS
Google’s privacy page for Public DNS (last updated 3 September 2024 according to the page) describes two kinds of log:
- Temporary logs are the only logs that store both the device’s IP address and the DNS query. They are subject to deletion within 24 to 48 hours, and may be kept longer solely to resolve security and abuse issues.
- Permanent logs are a sample of the temporary logs in which the IP address is replaced by a country, region and city location, no more specific than 1 square kilometre and 1,000 users. They record fields such as the requested domain name, request type, transport protocol and response code.
Google states that it does not use personal information from the service to target ads, and does not correlate Public DNS log data with other Google services except to address security and abuse.
Reading these as claims
Both pages are the operators’ own descriptions. A few distinctions help when reading any resolver or VPN logging statement, including a VPN provider’s DNS terms:
- Stated retention is a policy. Periods such as 25 hours or 24 to 48 hours describe what the operator says it does. The statements do not, on their face, say what happens if a legal demand arrives inside the retention window, and this guide makes no claim about that.
- Exceptions are part of the claim. Cloudflare’s sampled packets and Google’s longer retention for security and abuse are carve-outs in the text, so a headline such as “deleted within a day” is not the whole statement.
- An audit is only as useful as its scope. Cloudflare cites an external accounting-firm audit. Whether such a report covers every commitment listed on the page, and for what period, can be confirmed only by reading the report itself. The guide on logging policies and independent audits explains the same questions for VPN audits.
- Anonymised is not the same as absent. Both operators keep aggregated or location-level data in some form, and say so.
Where a VPN fits
Which resolver answers while a VPN is connected depends on how the VPN app and the device are configured, and on whether any queries leak elsewhere. That is why a DNS leak test is a separate check from reading a privacy statement. A provider’s own resolver adds a further party whose statement must be read: the VPN company. Switching to a public resolver can change which statement applies, but it does not make the logging question disappear.
Common questions
Does encrypted DNS stop the resolver seeing my lookups?
No. Encryption protects the path between the device and the resolver. The resolver itself still receives the query, which is why its logging statement matters.
Is a shorter retention period always better?
A shorter stated period reduces the time data is held under the operator’s policy, but the exceptions, the scope of any audit and the operator’s legal environment all affect how much weight the statement deserves.
The bottom line
Cloudflare and Google both publish specific, time-bound logging statements for their public resolvers, and the details differ: Cloudflare states 25-hour deletion of its logs, while Google states 24 to 48 hours for temporary logs and keeps location-level sampled logs. Each is the operator’s own claim, and the independent element, such as the external audit report Cloudflare refers to, needs to be read directly to see what it covers. The same approach applies to a VPN provider’s DNS and logging terms: separate what is stated from what has been independently checked.
Sources
- 1.1.1.1 Public DNS Resolver: Cloudflare’s commitment to privacy (developers.cloudflare.com)
- Your Privacy: Google Public DNS (developers.google.com)