proton.me privacy policy — score 88/100 (low risk)
Last analyzed
Proton AG · proton.me
Report details
low riskProton offers strong privacy by default with end-to-end encryption, minimal data collection, and no ad tracking, though some user data does flow to US-based processors for support and payments.
Proton's privacy policy demonstrates a strong commitment to data minimization and user privacy, anchored by end-to-end encryption and Swiss legal jurisdiction. The policy is transparent about its limited data collection and explicitly prohibits using user content for AI training. However, there are notable exceptions regarding IP logging for abuse prevention, and several third-party processors operate outside the EU/EEA (specifically in the US, Taiwan, and Macedonia), relying on Standard Contractual Clauses for legal cover. The policy also lacks specificity on data retention periods for temporary logs.
Category Assessment
Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.
Proton requires no personal information for account creation, uses self-hosted analytics without retaining IPs, and accepts anonymous payment methods like cash and Bitcoin.
The policy is detailed and specific about what is collected, the legal bases used, and the circumstances under which data might be retained or disclosed.
While core service data is processed internally, support and payment data is shared with US-based processors like Zendesk, Stripe, and Chargebee, and internal processors exist in Macedonia and Taiwan.
Data is transferred to the US, Singapore, Taiwan, and Macedonia using Standard Contractual Clauses, but the policy lacks detail on supplementary measures addressing Schrems II risks for US transfers.
Proton Scribe runs locally by default and explicitly does not use any user data for model training, providing a clear opt-in for server-side processing.
Users can access, edit, delete, or export personal data directly through the Account interface, and the policy mentions the right to lodge a complaint with a supervisory authority.
Key Findings
Notable clauses, issues, or positive practices discovered (critical first)
Conditional IP Logging Undermines No-Log Claim
IP addresses are not permanently logged by default, but can be retained temporarily for abuse prevention or permanently if Terms of Service are breached, which is a significant exception to the no-logging claim.
International Transfers to US Processors via SCCs
Several third-party processors operate outside the EU/EEA, specifically in the United States and Taiwan, relying on Standard Contractual Clauses for data transfers, which poses a risk under Schrems II.
Vague Retention Periods for Temporary Data
The policy allows for permanent retention of IP addresses and hashed verification data without specifying a maximum retention period, relying on vague determinations of 'legitimate interests' and 'applicable Swiss legal requirements'.
Strong Data Minimization and Encryption by Default
Proton explicitly states it cannot access end-to-end encrypted content and collects minimal personal data, not even requiring personal information for account creation.
AI Feature Respects Privacy by Default
Proton Scribe's AI feature operates locally by default and explicitly does not use user data for model training, which is a strong privacy-positive stance.
Consumer Takeaway
Proton is one of the stronger privacy-focused services available, genuinely minimizing the data it can access and refusing to train AI on your content, but you should be aware that using customer support or payment features exposes some data to US companies, and your IP can be logged if you violate their terms.
Compliance Posture
Proton aligns well with GDPR principles, particularly regarding data minimization, encryption by default, and user rights. The appointment of an EU representative (Proton Europe sàrl in Luxembourg) and explicit mention of GDPR compliance reinforce this posture. The main compliance risks stem from international data transfers to third-party processors in the US and Taiwan, which rely on SCCs without detailed mention of supplementary technical measures post-Schrems II.
EU Transfers
Data transfers to the US (Zendesk, Stripe, Chargebee, PayPal) and Taiwan (ProtonLabs Taiwan) rely on Standard Contractual Clauses. While the policy lists these guarantees, it is silent on supplementary technical measures (such as strong encryption in transit/at rest controlled by Proton) that are often required to make these transfers lawful under the Schrems II ruling. Transfers to Macedonia (ProtonLabs DOOEL) are not covered by an EU adequacy decision and lack specified transfer mechanisms in the policy.
Detected Signals
Specific data points and practices identified in the text
Evidence Snippets
Direct quotes from the policy supporting these findings
We do not have the technical means to access the content of your encrypted emails, files, calendar events, passwords, or notes.
By default, we do not keep permanent IP logs in relation with your Account. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our Terms of Service
Proton Scribe does not use content data or any of your data to train its models.
We will only disclose the limited user data we possess if we are legally obligated to do so by a binding request coming from the competent Swiss authorities.
Missing or Unclear
- No specific data retention periods for temporary IP logs or hashed verification data
- No mention of supplementary technical measures for US data transfers post-Schrems II
- No mention of a Data Protection Impact Assessment (DPIA)
- No specific details on the right to data portability format
- No mention of transfer mechanisms for data sent to Macedonia
Questions to Ask
- What are the exact maximum retention periods for temporarily stored IP logs and hashed verification data (phone numbers, emails) used for anti-spam?
- What supplementary technical measures (e.g., encryption, pseudonymization) are applied to data transferred to US-based processors like Zendesk and Stripe under Standard Contractual Clauses?
- How does Proton ensure that third-party processors like Zendesk and Atlassian delete support data upon request when a user exercises their right to deletion?
- Under what specific criteria is a user determined to be 'engaged in activities that breach our Terms of Service' triggering permanent IP logging, and is there an appeals process?
- What transfer mechanism is used for data sent to the processor in Macedonia, which lacks an EU adequacy decision?
Share this analysis
Anyone with this link can view the result above.
Built by DentroChat
100% European AI chat for everyone
Chat with AI, work with files, generate images, and search the web. Data stays in Europe.