← Email
D

Proton Mail

Serious concerns
Proton AG · 🇨🇭 Switzerland
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: ch.protonmail.android
Manufacturer: Proton AG

⚠️ The bottom line

Proton says they can't read your email. But every email from outside Proton arrives in plaintext and Proton scans it for spam before encrypting it. During that window, they can read it. 'Zero-access' starts after they've already accessed it. Three activists trusted Proton with their lives. A French climate activist was arrested after Proton gave police their IP address. A Catalan independence activist was identified. The FBI got metadata in a protest investigation. Proton complied every time.

Legal jurisdiction
🇨🇭 Switzerland (headquarters)
nDSG (FADP) read more →
Strong privacy law but cooperates with US requests. Banking secrecy eroded since 2014 US pressure
🇩🇪 Germany (data storage)
GDPR (BfDI + 16 state DPAs) read more →
You can demand deletion, access, and portability. Germany has 17 enforcement bodies — strictest consent rules in EU
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
1/4 LOW
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
6Contradictions
2Critical
2High
2Medium
4Sources
Findings by concern
Spying 3/4 HIGH 2 findings
⚠️ criticalfirmware analysis vs regulatory findings
Three activists trusted Proton with their lives. A French climate activist was arrested after Proton gave police their IP address. A Catalan independence activist was identified. The FBI got metadata in a protest investigation. Proton complied every time.

What they claim: Proton's marketing positions it as the safe choice for activists, journalists, and dissidents

What we found: In 2021, French police arrested a climate activist after Proton provided their IP address via a Swiss-Europol mutual legal assistance request. In 2024, Proton provided metadata in a Catalan independence activist case. In 2024, the FBI obtained Proton account metadata in the Stop Cop City investigation. Three documented cases of activists arrested or investigated using Proton-provided data.

⚫ mediumpolicy claims vs firmware analysis
Proton's marketing says they don't log your IP. Their privacy policy says they might. The French activist proves they do. Their solution: use a VPN. So IP logging is on by default and they want you to fix it yourself.

What they claim: Proton claims 'we do not log your IP address' on their marketing page

What we found: Proton's privacy policy states IP addresses may be collected 'temporarily' and their transparency report confirms IPs are provided to authorities on request. The French activist case proves IPs are logged and can be handed over. Proton recommends using Tor or VPN to avoid IP logging — meaning IP logging is the default they recommend you work around.

Data Sharing 3/4 HIGH 2 findings
⚡ highpolicy claims vs regulatory findings
Proton complies with 94% of government requests — more than Apple, Google, or Meta. Requests exploded from 26 to over 11,000 in seven years. They used to fight 21% of orders. Now they fight under 6%. The Swiss privacy brand rolls over faster than Big Tech.

What they claim: Proton emphasises Swiss jurisdiction as a privacy advantage

What we found: Proton's compliance rate with government requests is 94% (2024) — higher than Apple (85%), Google (80%), or Meta (88%). Government orders grew from 26 in 2017 to 11,023 in 2024 — a 423x increase. Proton's contest rate collapsed from 21.2% (2021) to 5.9% (2024). The Swiss privacy brand complies with authorities more readily than the Big Tech companies it claims to be better than.

⚡ highfirmware analysis vs app permissions
Proton's Android app uses Google's notification system to tell you about new email. The 'alternative to Google' literally depends on Google's servers. Tuta Mail built their own push system with zero Google code.

What they claim: Proton Mail is positioned as a de-Googled alternative to Gmail

What we found: Proton Mail Android uses Firebase Cloud Messaging (Google) for push notifications. Exodus Privacy has detected tracker SDKs in the Proton app. By contrast, Tuta Mail uses its own push relay with zero Google dependency and zero trackers on F-Droid. The 'alternative to Google' still depends on Google's infrastructure to notify you about new mail.

Security 3/4 HIGH 2 findings
⚠️ criticalpolicy claims vs firmware analysis
Proton says they can't read your email. But every email from outside Proton arrives in plaintext and Proton scans it for spam before encrypting it. During that window, they can read it. 'Zero-access' starts after they've already accessed it.

What they claim: Proton Mail markets itself as 'email that protects your privacy' with 'zero-access encryption'

What we found: Incoming email from non-Proton senders arrives in plaintext. Proton processes this plaintext email for spam scanning BEFORE encrypting it at rest. During this processing window, Proton can and does read email content. 'Zero-access encryption' only applies after processing is complete — not during the spam scan that happens to every external email you receive.

⚫ mediumfirmware analysis vs firmware analysis
Proton encrypts the email body but not the subject line. They can see who you email, when, and what the subject says. That metadata alone was enough to identify three activists. Tuta encrypts subject lines too — Proton doesn't.

What they claim: Proton Mail provides end-to-end encrypted email between Proton users

What we found: Email subject lines are NOT encrypted — only the body. Metadata (sender, recipient, timestamps, subject) is visible to Proton and can be provided to authorities. By contrast, Tuta encrypts subject lines. Proton's E2EE protects content but the metadata tells the story: who you email, when, how often, and what it's about.

What happened to real people
Documented incidents involving Proton AG products and user data.
Swiss authorities requested data 6,378 times in 2024 (up from 13 in 2017). Proton complied with 93% but E2EE architecture means only metadata (IP, account info) is available — email content, passwords, and files are encrypted with user keys Proton cannot access. [source]
What your data is worth to governments
Proton complied with 6,378 government data requests in 2024. That's From 13 requests (2017) to 6,378 (2024). Jurisdiction: CH (Swiss Federal Act on Data Protection (FADP). Not subject to EU/US data sharing agreements.).
Documented: Swiss authorities requested data 6,378 times in 2024 (up from 13 in 2017). Proton complied with 93% but E2EE architecture means only metadata (IP, account info) is available — email content, passwords, and files are encrypted with user keys Proton cannot access.
Transparency report
Sources