Concerns About Proton Logging Practices

I just got an email from Proton Wallet saying I have early access to their service, which is exciting. However, when I tried to log in, I ran into an error that said, “Proton Wallet is not supported in your region.”

This got me thinking, and I’d love to hear your thoughts on a few concerns I have.

  1. VPN Usage: I always use a VPN (ProtonVPN, Mullvad) for my online activities, and I’m a bit concerned about whether Proton can still track users in this case. Can anyone share insights on how Proton handles privacy for VPN users?
  2. Logging Practices: Does anyone know which services keep logs, what kind of data is logged, and how that data is used?
  3. Flagging user: Why Proton flag its users and keep this information?

I really appreciate any thoughts or experiences you can share!

@Proton_Team

I’d dive into their privacy practices. With this, the generic error message might be they detected a VPN and chose to error you out rather than deal with it.

I’m sure having a Waller has strict GDPR and related law requirements I suspect proton must enforce by some means. To ensure they stay in their legal jurisdiction, they will exclude unknown or countries/provinces they aren’t equipped to deal with.

3 Likes

Without knowing where you live, it’s hard to say why it doesn’t work in your region, if you read their terms and use in the link on the error message, it does cover that the service is prohibited in basically any country that has a trade embargo or sanctions with the US.

As for all of the VPN stuff, you can easily find answers to all of your questions by reading Proton’s support documentation:

1 Like

I live in Iran, a U.S. sanctioned country, and I use a VPN to access the internet. I’m certain I opened my Proton wallet while connected to the VPN.

My question is why does Proton flag accounts like mine, and how does that process work? What criteria do they use for logging accounts and associating locations?

I understand they must comply with legal regulations, but it’s concerning that I was flagged even before using the service, without connecting from an Iranian IP address.

1 Like

I live in Iran, which is on the sanction list, but I use a VPN to access the internet. I’m certain I opened my Proton wallet while connected to the VPN.

I understand that this service is unavailable due to the terms. However, I would like to know how the account logging and flagging mechanism works, especially since I did not connect to the Proton wallet using an Iranian IP address.

1 Like

I reached out to Proton about this issue, and here’s their response:

“In general, we keep as little data as possible and make these login decisions in real-time without storing any sensitive data.”

I can confirm that their response is accurate in this case. After some experimentation, I discovered that they use the time zone sent by the browser to determine your location, which is separate from using a VPN.

1 Like

Services like F-Droid also store telemetry on installs, but they use country codes instead of IPs. Proton could be doing something similar.

1 Like

It’s possible, but I believe my account isn’t flagged since I can access my Proton wallet through the Mullvad browser, which spoofs my timezone. However, I can’t access it through Brave or the application, where my timezone isn’t spoofed.

1 Like