A VPN should never be used for privacy unless you can prove they don't log, which is difficult. You would literally have to be in their datacenters and audit all their infra.
are we not mixing up private networks with user (consumer) privacy? not an expert by any means, but isn't VPN used exactly for creating non-public networks? e.g. when you log into your work network when WFH or connecting your branch office users to the head office servers and corporate applications...