Tim

Proton AG is a Swiss technology company (formerly Proton Technologies AG) Known for its privacy. However, the fact is many of numerous pieces of evidence suggest that Proton deceived everyone.

Proton moniter and track the people, logging and leak the personal infomation.

This is true, and it's not an isolated case. Since proton began monitoring French activists in 2023, there have been cases almost every year. The latest case is in September 2025 when proton deleted the account of a journalist who disclosed information to the South Korean government.

TL;DR: ProtonMail complied with a Swiss court order and logged a user’s IP address, handing it to French authorities and enabling the arrest of a climate activist linked to property occupations. CEO Andy Yen says Proton had no choice under Swiss law, deplores the outcome, and insists email contents remained encrypted and inaccessible to Proton. Critics accuse Proton of overstating its anonymity guarantees; some argue encrypted email can’t truly protect users from legal compulsion. Proton contends ProtonVPN is less vulnerable to such orders and says it fights many requests, but transparency reports show thousands of Swiss requests and hundreds of legal battles.

TL;DR: Proton Mail repeatedly complied with legal requests—this time handing a recovery email to Spanish authorities that helped identify a suspected Catalan activist linked to Democratic Tsunami—exposing limits of its privacy claims. Earlier compliance with a Swiss court led to a French climate activist’s arrest after Proton logged and handed over an IP address. Across jurisdictions, Proton has provided data to law enforcement thousands of times (5,971 requests in 2022), raising concerns that its marketing of strong anonymity and no-logs protections misleads users who can still be unmasked through legal compulsion and cross-company cooperation.

TL;DR: Proton suspended journalists’ accounts after a CERT complaint about a South Korean cyberattack report, disrupting secure communications and responsible disclosure efforts. The company gave vague, late explanations, refused to name the complaining agency, and initially failed to privately resolve the issue. Though some accounts were later reinstated, the episode damaged trust and suggested Proton’s enforcement and transparency practices can undermine press freedom and whistleblower protections—contradicting its privacy-focused reputation.

Proton marketed its new AI, Lumo, as “fully open source” and not using user data for training, but support later said that claim reflects a future intention, not the current reality. That mismatch—especially since Proton has released other products’ source code at launch—feels misleading and undermines trust. Framing an inaccurate, promotional statement as a “long-term intention” conflicts with Proton’s transparency branding and raises legitimate concerns about honesty and reliability rather than being a minor oversight.

Proton’s all-in-one ecosystem centralizes email, storage, passwords and more under a single account, creating a bigger attack surface and stronger incentives to lock users in. Forcing users to buy an expensive Unlimited plan or create secondary accounts to mix subscriptions is anti-consumer and pushes account consolidation that magnifies risk. Using Proton Pass alongside other Proton services on one account further couples sensitive secrets to the same credentials. Proton’s lack of per-product isolation (e.g., a separate security key for Proton Pass) and account-level entanglement make users more vulnerable if credentials are compromised.

ProtonVPN’s public server claims are misleading: many listed “country” servers use Smart Routing and aren’t physically located where advertised, inflating country counts and server availability. Secure Core documentation hides exit-server locations and contradicts Smart Routing, creating unclear threat models. This bait‑and‑switch harms users who choose nearby servers for performance or jurisdictional safety and represents false advertising by obscuring real server geography and limitations during purchase.

TL;DR: Proton reportedly ghosted independent critic THO after he declined a sponsorship and asked for an interview, contradicting their promise that sponsorship decisions wouldn’t affect access. The episode looks like a petty, access-driven response that undermines Proton’s credibility and raises concerns about quid‑pro‑quo influence. More broadly, sponsorships and access journalism create conflicts of interest that can soften scrutiny of powerful companies; Proton’s behavior here suggests it may prioritize reputation control over transparent engagement, which is worrying for a firm that markets itself on trust and independence.

Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester, Privacy guides link

WARNING: ProtonVPN fake locations, unexpected downtime, etc

"TL;DR:

  1. Many of their locations are blatantly fake. For example, Berlin suddenly gives you a server in Frankfurt. Same story with locations like Luxembourg. I didn’t review all of their locations but I’m sure there’s plenty more that are fake. This has been independently verified with traceroute, AS path and by engaging their upstream providers. M247 for example doesn’t even have any racks in Berlin, but they do have IP space wrongfully geolocated there.
  2. They almost exclusively use M247 and Datapacket. They don’t have any, or very little, own hardware. Not to mention that M247 and Datapacket both have strong UK ties (because of business incorporation) and can easily be compelled to lawful intercepts or netflow sharing.
  3. Their servers are either completely overloaded (i.e. in Cyprus, there’s plenty of people on Reddit complaining about this situation already), or randomly go down (a server I’ve connected to randomly went down 3 days ago and hasn’t come back up. No update, notification or anything, it’s just dead)."

While I don’t care so much about the fake locations, I think renting your VPN servers from the two biggest VPN-related carriers where sharing netflow data with intelligence in real-time can not be ruled out, but then advertising yourself as “the better VPN” is hilarious.

Even worse is the fact they publicly tweet that journalists rely on their SecureCore feature. I’ve taken a very close look at how it works: it sandwiches a middle-hop in a “safe jurisdiction” into your traffic. They supposedly own the hardware for those middle-hops. But here’s the worst part: those middle-hops are hosted in countries like Switzerland that have active intercepts on all cross-border traffic by law. They’re willfully advertising a safety feature that leads to your traffic going through legal intercepts. That’s borderline insane.

And if that wasn’t enough yet, I’ve taken a closer look at who their upstreams for those servers are. Surprise, they’re almost single-homed to Hurricane Electric. Who’s Hurricane Electric? You guessed it right, a dirt-cheap Tier-2 (Tier-1 wannabe, too bad not all Tier-1s peer with them) based in the US. They have a plethora of carriers to choose that would be subject to European law (Telia AS1299, Telecom Italia AS6762, Orange France AS5511, …) but instead they go for the cheapest US-based carrier they could get.

All in all, I’ve stopped using ProtonVPN. It’s nothing more than a pile of shit wrapped in fancy marketing. I’m not going to make any accusations because it’s impossible for me to prove, but to me they look like an overt honeypot at best, and like a covert honeypot or controlled opposition at worst.

Before people jump at me “this is a hate post” or “did you just make this up to hate on them” - no, the three points that I highlighted here can be verified by anyone with little effort.

Stop using ProtonVPN if you care about more than marketing.

TL;DR: Since August, 2026, multiple Reddit users have reported encountering varying subscription prices for Proton VPN Plus, strongly proved the company is conducting price sensitivity or A/B testing. Although Proton has formally denied engaging in these practices, rival VPN provider Windscribe publicly called them out on Twitter. Windscribe presented concrete evidence found directly within Proton website’s source code, exposing a contradiction to Proton's official denial. This technical discrepancy indicates that Proton is indeed testing differential pricing models on unsuspecting customers, sparking widespread debate regarding transparency, corporate honesty, and fair consumer pricing practices across the digital privacy industry.

Summary: Proton, despite privacy branding, repeatedly complied with legal/data requests enabling arrests, misrepresented product openness (Lumo), suspended journalists’ accounts with poor transparency, misled users about VPN server locations via Smart Routing, pressured/ghosted critics over sponsorships, and centralizes services—creating lock‑in and increased user risk, Don't use proton as possible. by the way this is my first time to write blog on HIVE and use fully english if have some mistake please tell me thanks!

NOTE: This acticle write fully by myself, not AI, not Bot, I'm objective and neutral possible, and all points are supported by sources.