There's also usually another disconnect: between tech industry publicity and tech industry reality. Mullvad could have been, and maybe even still is, lying about how they operate, because it's good for business.
At least there have been some public and external audits that brings up the trust a bit, if you trust that those external companies are honest and putting their reputation on the line.
Government investigations pursue lots of avenues unlikely to be fruitful. It's basic due diligence to check all the boxes; you don't say "standard procedure is to issue a warrant, but we'll make an exception to our process in this case because their website suggests it won't get any data, plus they hired an auditor."
> Mullvad could have been, and maybe even still is, lying about how they operate
Could they? Sure.
Do they have anything on me?
* One BTC transfer
* IPs where I'm connecting from (if they are lying and storing them)
* My traffic (if they are lying and storing it)
* My unencrypted traffic (if they are lying and storing it)
Do they have ... on me?
* Email? - nope
* Phone number? - nope
* Credit card? - nope
* My first name, family name? - nope
* My address? - nope
* My mother's maiden name? - nope
Because I never provided it to them because they never asked for them.
Unless you're using another VPN/proxy/Tor/... to connect to the VPN, the IP where you're connecting from (respectively the full 4-tuple including source/destination port) likely does identify your address.
Of course. It doesn't help what I'm getting pretty much the same IPs from my provider.
Double (triple|quad) hop, tied to different entities is necessary if you want at least plausible deniability. Thankfully I don't do things what may be of the interest of someone who can raid Mullvad offices.
But I recently discovered a VPS provider who only needs an email address to confirm an order, so it can be used as a bootstrap for a something pretty anonymous. Still needs an email, but as I said in some other comment recently, you can do that (if you are okay with leaving some traces) with a Google device with WiFi only capability.
You can pay a Bitcoin lightning invoice on this site and get a redeemable Mullvad voucher instantly. Extremely convenient. Since you've only done 1 BTC transaction, I assume it was a large one for lots of time. However, when your time runs out, this option is great. It's an extra layer of privacy and you don't have to wait for the transaction to settle on chain.
Exchange has my CC number and the 'card holder' (though I never put my name there, lol). A non-business card is probably the most easy way to identify someone globally.
If someone comes to exchange - they could identify me (and they can just tap their server to listen to email which do have all the transaction info, including CC# in the plaintext, lol).
To establish a correlation between my wallet and Mullvad account someone needs to find that transaction in Mullvad customer data. Which - they claim they don't have.
So yes, someone can identity what I bought services from Mullvad and... nothing more?