Proton: From Privacy’s White Knight to the New Centralized Empire?
After dissecting digital censorship and the surveillance tentacles spreading across the internet in my previous post, I found myself facing a sharp irony. Proton, the Swiss stronghold I picked years ago for my email with their Mail Plus plan at under €4 a month, is starting to get on my nerves. Not because they sold my data, they hold the line there, but because the company is turning into something voracious, fixated on growth and centralization. What if Proton, the white knight of data protection, were becoming a Google in eco-friendly clothing? Let’s not dance around it: the uncomfortable questions need asking now, before our dependence blinds us to them.
The growth obsession: from refuge to commercial machine
Proton began as a revolt against mass surveillance, a crowdfunded project started by CERN scientists to protect dissidents and journalists. Today? It is a many-headed hydra: email, VPN, storage, calendar, password manager, even a crypto wallet launched in February 2025 for self-custody of your Bitcoin, plus Docs, fully operational and updated regularly through 2025 to support secure collaboration. They passed 100 million accounts in 2023, and their “prudent” expansion policy, no debt, self-funded, does a poor job of hiding a frenzy of new services. Critics on Reddit and forums like Techlore keep making the same point: the mobile apps feel dated, the bugs persist, but Proton would rather add features than polish the fundamentals (hello there, Apple).
None of this is evil, of course. But it smells like a commercial turn. In 2025, with the arrival of Lumo, their AI assistant meant to “improve” interactions across their ecosystem, email included, users started shouting on r/ProtonMail: “Now they have the technology to decrypt our business secrets!”. Proton insists it is a security feature, with client-side processing and no access to the data: conversations are not stored on their servers, and all decryption happens on your own device. Even so, the argument rages on. The AI may stay local today to preserve end-to-end encryption, but some fear that future features will shift to server-side processing, undermining the zero-knowledge model that gives Proton its strength. This race for growth erodes the story the company originally told. We fled Big Tech to escape exactly this, not to build a new empire flying the privacy flag.
The ecosystem trap: centralization is your worst enemy
Proton’s all-in-one universe is tempting. Encrypted email, secure storage, hardened VPN, a genuine all-you-can-eat buffet. But putting everything with a single provider? That is a disaster for data protection. The forums say it over and over: “Handing all your data to Proton creates one massive point of failure.” Picture it: one breach, one legal loophole, and your email, files, passwords, and calendar are exposed all at once.
Proton publishes threat models for its storage and its crypto wallet, acknowledging that perfect security does not exist. Yet it keeps pushing integration, “Upgrade to the full plan and get everything!”, as if diversifying were a sign of weakness. The supreme irony: we leave Google to escape centralization, then rebuild the same monster at Proton. Experts at outlets like Cybernews remind us that even with end-to-end encryption, metadata piles up. And what happens if Proton becomes too big to fail? We know how that story goes with banks.
Transparency? A façade with cracks in it
Proton prides itself on transparency: independent audits by Securitum, annual reports on legal requests (Swiss only, and refused across the board for the VPN), public key verification through Key Transparency, and Proton Pass released as open source. Credit where it is due. But dig a little: Proton Mail’s core server remains closed source, as Wikipedia notes. The audits are partial, and users point out that the published code does not necessarily match what runs in production.
Worse, the recent AI work like Lumo sets off storms: “Proton had no access to our email; now they can decrypt it for the AI?” says one Reddit thread. Their transparency report is impeccable, but selective, with nothing at all about the audits they chose not to publish. For a company built on trust, that is a glaring contradiction. We deserve better than opacity dressed up as virtue.
Depending on Proton: privacy as a product
Too many users stop at Proton, convinced they have found the privacy holy grail. “I have Proton, I am fine!”, and that is where it ends. Proton encourages the attitude: guides on data protection (their blog on raising kids online, for instance), student discounts, but very little encouragement to look at anything else. Discussions on r/degoogle put it plainly: “The risks are the same as anywhere else; diversify!”
Proton turns privacy into an attractive subscription rather than a learning process. Its privacy policy is solid, but where is the nudge toward self-hosting, or toward combining several providers? Instead, you get locked into their ecosystem. Convenient, yes, and risky: real privacy is autonomy, not brand loyalty.
The Swiss myth: a sanctuary coming apart
Proton leans on Switzerland as a shield: neutrality, strict laws. But 2025 changes the picture. The government is pushing the VÜPF revision: mass surveillance, an obligation for providers with more than 5,000 users to collect government-issued identification, aimed squarely at VPNs and encrypted email. Proton has frozen its Swiss investments and started moving infrastructure to countries like Germany. “Legal uncertainty,” they call it. Smart of them, but it demolishes the myth of an unshakable refuge.
Players like Tuta and Nym are sounding the alarm: this is worse than the United States. Proton admits it might relocate if things get worse. Fair enough, but it proves that “Swiss privacy” is a shaky marketing argument. And in the meantime, what are the rest of us supposed to do?
Question your allies, or lose your freedom
Proton is still one of the best options for privacy: strong encryption, a no-logs VPN, real audits. But the cracks, runaway growth, risky centralization, half-hearted transparency, encouraged dependence, a wobbling Switzerland, leave me with doubts. This is not hatred; it is a call to keep your eyes open. Real privacy means questioning even the good guys. And I would bet, without going too far out on a limb, that they will eventually push us all toward a single all-in-one plan, the way Adobe did with Creative Cloud.
It is on us to stay alert and avoid the trap.