Private Mail Guide
A glowing transparent mail tube carries an envelope between two servers, secured by a padlock in a dark blue 3D scene.
Email privacy

Is Proton Mail Really Private? Encryption and Limits

Proton Mail limits provider access to inbox content, but it does not hide all metadata, secure compromised devices, or make ordinary email anonymous.

By Private Mail Guide Editorial · · 5 min read

Is Proton Mail really private? Yes, for a realistic consumer threat model: it keeps stored message content out of the provider’s routine reach, automatically uses end-to-end encryption (E2EE) between Proton users, and does not fund the service by profiling inboxes for ads. It is a strong upgrade from conventional webmail if your concern is ad-tech surveillance, an exposed mail server, or someone snooping on public Wi-Fi. It is not anonymous email. Proton can access some metadata, other providers may see messages you exchange with their users, and anyone who controls your password, recovery channel, or unlocked device may read your mail.

Threat models Proton Mail serves

  1. You want less ad-tech surveillance. Strong fit. Proton says it does not use account activity for targeted advertising or profiling. Its tracker protection is enabled by default and proxies remote images to conceal your IP address, device details, and precise open time from known tracking pixels. Detection lists can miss custom tracking links, so this reduces tracking rather than eliminating it.

  2. You are worried about an ISP or public-Wi-Fi snoop. Strong fit for message content. HTTPS and mail-transport encryption prevent a nearby attacker from simply reading your inbox traffic. Your ISP can still see that you connect to Proton and observe timing and volume; a VPN or DNS over HTTPS (DoH) changes parts of that network-metadata exposure, not the email itself. As the EFF explains, encryption does not hide every piece of metadata or rescue a compromised endpoint. It also does not stop phishing or malware on its own.

  3. A stalker ex may know your password or control your recovery email. Conditional fit. Zero-access encryption does not help once an attacker signs in as you or opens an existing session. Use a unique password, add TOTP or a FIDO2 security key, keep recovery codes outside any Apple or Google account the other person can access, and revoke old sessions. If your ex has your iCloud password, do not make that iCloud mailbox Proton’s only recovery route.

What Proton actually encrypts

Data or routeDefault protectionImportant limit
Message bodies and attachments stored by ProtonZero-access encryptionYour signed-in devices can decrypt them
Mail between two Proton usersE2EESender and recipient endpoints still see plaintext
Mail to a Gmail, Outlook, or other external userUsually TLS in transitThe recipient’s provider can normally read its copy
Mail arriving from an external providerTLS in transit, then zero-access storageThe sender’s provider may retain a readable copy
Subject, sender, recipient, timestamps, and related routing dataEncrypted at rest, but not end-to-end encryptedProton can access this metadata

Those distinctions come directly from Proton’s encryption documentation (vendor-sourced). Zero-access encryption means Proton stores a message in a form it cannot later decrypt. It is not the same as E2EE from sender to recipient: an ordinary incoming message can be processed for spam and viruses before Proton encrypts it for storage.

Proton’s mail-specific privacy policy lists metadata available because of SMTP: sender and recipient addresses, the originating IP of incoming mail, attachment names, subject lines, and sent/received times. Metadata can map relationships even without revealing prose, which is why EFF advises treating it as sensitive. For a conversation where concealing the social graph matters, email is the wrong protocol; use an appropriate E2EE messenger.

Proton AG is governed by Swiss law. Foreign authorities cannot issue it a directly binding demand, but they can proceed through Swiss legal-assistance channels. Proton’s transparency report says it received 9,301 Proton Mail orders in 2025, contested 988, and complied with 8,313. Compliance does not mean decrypted message bodies were supplied: the same report says Proton has no means to decrypt encrypted mail, files, or invitations.

The limit is identity and account metadata. In 2021, Proton began collecting an activist’s IP address after a binding Swiss order; TechCrunch documented the police-report details. Proton’s current privacy policy says permanent account IP logging is off by default, but that is not a promise that targeted collection can never occur. This case is the clearest reason not to confuse “private” with universally anonymous.

The catch

The marketing headline is broader than the everyday encryption boundary. E2EE is automatic when both parties use Proton. With a normal external recipient, you must deliberately use a password-protected message or configure PGP; otherwise the other provider can read its copy. Proton also retains access to useful metadata and operates under law, like every centralized mail service.

The supporting evidence is respectable but bounded. Proton publishes source code and audit links, and a Securitum assessment dated May 2021 reviewed the web application. An audit is a point-in-time examination of a stated scope, not a permanent guarantee covering every later release or server-side process.

Pricing

Pricing checked September 4, 2026. Proton Free uses the same core encryption and is the budget pick. Proton’s current plan guide lists Mail Plus at €4.99 month-to-month or €47.88 per year, and Proton Unlimited at €12.99 month-to-month or €119.88 per year; checkout may localize currency and tax. Proton’s terms allow a full refund within 30 days of an initial direct purchase. App-store purchases follow the store’s refund rules.

A 10-minute privacy setup

  1. Create the account with a unique password. Choose a recovery address that your threat model allows, then save Proton’s recovery phrase somewhere the person you are avoiding cannot reach.
  2. Open Settings → All settings → Account and password → Two-factor authentication. Enable TOTP or, preferably for phishing resistance, a FIDO2 security key. Both methods work on free and paid plans. Store one-time recovery codes offline.
  3. Open Security and privacy → Session management and revoke devices you do not recognize. Proton documents a “Revoke all other sessions” control.
  4. Under Email privacy, confirm Block email tracking on each device. For sensitive mail to a non-Proton user, click the lock in the composer, set a message password, and share that password through a separate channel.

A private mailbox still needs patched devices and skeptical link-clicking. Tech Sentinel is Private Mail Guide’s sister publication for broader cybersecurity incident coverage.

Verify it worked

Send one message to another Proton address and one password-protected message to an external address. Before sending, inspect the lock beside each recipient; Proton’s lock-icon guide explains the encryption state. Open a newsletter containing trackers and look for the tracker-protection badge, then revisit Session management to confirm only your devices remain. These checks verify your settings and message route, not Proton’s entire architecture or legal posture.

Sources

  1. What is encrypted within Proton Mail?
  2. Proton Mail Privacy Policy
  3. Proton transparency report
  4. What Should I Know About Encryption?
  5. Securitum ProtonMail security audit
  6. ProtonMail logged IP address of French activist after order by Swiss authorities

Related