A log is a record that a computer or website keeps of what happened

When you use a computer, phone, or website, that device or service writes down what you did — what time you logged in, what pages you visited, what files you opened, whether something went wrong. That written record is the log. Think of it like a security camera that writes text instead of recording video. The log sits on a server or your device's hard drive, and most of the time you never see it.

Logs matter because they are evidence. If your email account gets hacked, the log shows what time the hacker signed in and from where. If your internet connection drops, the log shows why. If a website crashes, the log tells the engineers what broke. For you as a person trying to stay safe, logs are both useful and risky — useful because they can prove what happened to your accounts, risky because companies and hackers both want access to them.

Key Takeaways

  • A log is a timestamped record of actions — logins, file access, errors — that a device or website automatically writes and stores.
  • Your device keeps logs about what you do locally; websites and internet providers keep logs about what you do online.
  • Logs can help you spot unauthorized access to your accounts by showing login times and locations you did not recognize.
  • Companies use logs to improve their services, but they also sell or expose log data, so understanding what gets logged helps you make privacy choices.
  • You can sometimes delete your own activity logs from websites, but logs on your device or your internet provider's servers are harder to control.

Where logs live and who can see them

Logs exist in three main places. First, on your own device — your computer, phone, or tablet keeps logs of what programs you ran, what files you opened, what errors happened. Second, on websites and apps you use — Gmail, Facebook, your bank, your email provider all keep logs of when you signed in, what you clicked, what you searched for. Third, with your internet service provider (ISP) — the company that gives you internet access logs which websites you visited and when, though not usually what you did on those websites.

Who can see these logs depends on where they live. Logs on your own device are visible to you (if you know where to look) and to anyone with physical access to your device or administrator access to your account. Logs on websites are visible to that company's employees and contractors, and sometimes to law enforcement if they have a warrant. ISP logs are visible to your internet provider and to law enforcement. In practice, this means a company employee, a hacker who breaks into a company's system, or a government agency with legal authority can all potentially read logs about you.

How to check login logs on your accounts

Most major websites and email services let you see a log of recent logins. This is one of the most useful things you can do to catch unauthorized access early. On Gmail, go to your account, click "Security" on the left, scroll down to "Your devices," and click "Manage all devices." You will see a list of every device that has logged into your account in the last 28 days, including the device type, location, and time. If you see a login from a place you were not or a device you do not own, you can sign that device out when ready.

Facebook shows login activity under Settings > Security > Where you're logged in. Twitter (now X) shows it under Settings > Security and account access > Sessions. Microsoft Outlook shows it under Account > Security. Most banks show login history in the account settings or under a "Recent activity" or "Login history" tab. If you cannot find it, search the website's help for "login history" or "recent activity." Check these logs once a month, especially on accounts that hold money or personal information. A login from a city you have never visited or a device you do not recognize is a sign that someone else has your password.

What happens to logs after you delete them

When you delete your activity from a website — clearing your search history on Google, deleting old messages from Facebook, removing your browsing history from your bank — you are usually deleting only what you see. The company's log of what you did still exists on their servers. Google still knows you searched for those terms; Facebook still has a record that you sent those messages. Deleting your activity just hides it from you and from other people on the platform.

The company keeps the underlying log for their own purposes: to improve their service, to show you targeted ads, to comply with legal requirements, or to sell the data to other companies. How long they keep it varies. Google keeps some logs for 18 months, others for longer. Facebook keeps logs indefinitely. Your bank may keep logs for seven years or more for regulatory reasons. You cannot truly delete a log once a company has written it — you can only delete your view of it. This is why privacy advocates recommend thinking before you search, message, or browse, rather than relying on deletion to erase your tracks.

Why logs matter for your privacy and security

Logs are a privacy risk because they are a detailed record of your behavior. If a hacker breaks into a company's database, they get not just your password but a log of everywhere you have been, everything you have searched for, everyone you have messaged. If a company is hacked or sells your data, that log becomes a product. If law enforcement wants to know where you were or what you were doing, they can subpoena logs from your ISP or from websites you used.

But logs are also a security tool for you. A login log can tell you if someone else is using your account. A file access log on your computer can tell you if malware has been reading your documents. An error log can tell you if a website you use has been compromised. The trade-off is real: the same record that protects you from hackers also exposes you to companies and governments that want to know what you are doing.

How to reduce what gets logged about you

You cannot stop logs from being created — that is how computers work. But you can reduce what gets logged. Use a VPN (virtual private network) when you browse, which hides your real IP address from websites and makes it harder for your ISP to log which sites you visit. Use private or incognito mode in your browser, which stops your browser from keeping a local log of your browsing history (though your ISP and the websites you visit still see it). Use a search engine like DuckDuckGo that does not log your searches, instead of Google, which does.

On your own device, you can turn off activity logging in your operating system settings. On Windows, go to Settings > Privacy & Security > General and turn off activity history. On Mac, go to System Settings > General > About and check what is being logged. On your phone, check app permissions — an app that you do not give permission to access your location cannot log your location. None of these steps make you invisible, but they reduce the amount of detailed information that gets written down about what you do.

What to do if you see suspicious activity in your logs

If you check your login history and see a login you did not make, act when ready. Change your password to something long and random that you have never used before. If the suspicious login is recent, sign out all other devices from that account right now — most email and social media platforms have a "sign out everywhere" button. Check what the unauthorized person did: did they change your recovery email or phone number? Did they read your data? Did they change your password? If they changed your recovery information, you may need to contact the company's support team to regain control.

After you have secured the account, check your other accounts. If someone got into your email, they can use the "forgot password" feature on your bank, social media, or other services to take over those too. Change passwords on any account that matters. If the breach involved financial accounts, consider placing a fraud alert with the credit bureaus or monitoring your credit report. Most importantly, do not panic — the fact that you checked your logs and caught it early means you can stop the damage before it spreads.

Frequently Asked Questions

Can I see what my internet provider logged about my browsing?

No, not directly. Your ISP keeps logs of which websites you visited, but they do not show you those logs. You can see what your own device logged by checking your browser history, but that is different from what your ISP saw. If you want to know what your ISP is logging, you would need to contact them directly — most will not tell you.

Do deleted text messages or emails leave a log?

Yes. When you delete a message from your phone or email account, you delete it from your view, but the company's servers still have a log that the message existed, when it was sent, and who it was sent to. The message content may or may not be recoverable depending on how the company stores it. Deletion is not the same as erasure.

What is the difference between a log and a cache?

A log is a record of what happened — actions, times, errors. A cache is a copy of data stored temporarily to make things faster. Your browser cache stores copies of web pages you visited so they load faster next time. A log records that you visited them. They serve different purposes and are stored differently.

If I use a VPN, does that stop websites from logging my activity?

No. A VPN hides your IP address from websites, so they cannot log your real location. But they still log that someone visited, what pages they looked at, and what they clicked on. A VPN protects you from your ISP and from location tracking, but not from the website's own logs.

How do I know if my device is logging too much?

Check your operating system settings under privacy or activity history. On Windows, Settings > Privacy & Security shows what Microsoft is logging. On Mac, System Settings > General > About shows Siri and analytics settings. On phones, go to Settings > Privacy to see what apps can access. You can turn off most logging, though some is necessary for the device to work.