# Everything in Proton or Using different services?

**URL:** https://discuss.privacyguides.net/t/everything-in-proton-or-using-different-services/29664
**Category:** Questions
**Created:** 2025-08-01T20:16:47Z
**Posts:** 31

## Post 1 by @oci3o — 2025-08-01T20:16:47Z

Hey all,

Given the recent changes in the UK, I am looking to properly 100% move to privacy respecting services, and close most none respecting services I have left soon.

So I need to make a choice and I’d like to ask the community, here are my two choices.

1. Everything into Proton, ProtonVPN, Proton Drive, Mail, Pass etc.
2. Use different services.
  1. Tutamail.
  2. Proton Drive (Free due to my very limited need for file storage).
  3. Bitwarden.
  4. Ente Photos.
  5. Mullvad.
  6. Notesnook.
  7. Addy.

Now I think the better choice is to have everything with different providers, but I trust proton I dont think they will become “evil” or end up switching to selling data.

So what would the community do? I’m thinking proton as their stuff is outside the UK, but obviously the others help if something happens to proton.

TIA!

---

## Post 2 by @anon39279085 — 2025-08-01T20:28:47Z

My rule of thumb is you can choose to be in the proton ecosystem or go seperate, either choice is fine just make sure that if you;re gonna go to the proton ecosystem at least take steps to where you can get out, eg. use custom domain on emails.  
_ **However** _  
**Always seperate your password manager and 2FA no matter what, in the event of your account being compromised or lost, the next thing you want is to lose those too**

---

## Post 3 by @PaleCrow55 — 2025-08-01T20:32:44Z

I personally use Proton (also using a custom domain for some addresses) and Ente for separate 2FA.

---

## Post 4 by @PaleCrow55 — 2025-08-01T20:35:00Z

> [@anon39279085](#):
>
> Always seperate your password manager and 2FA no matter what

One extra point to add to that is even if you use separate services, it is still possible for lockout if you happen to put the password to your 2FA app in your password manager and the TOTP for your password manager in your 2FA.

---

## Post 5 by @anon39279085 — 2025-08-01T20:36:49Z

yes in the event you forget your master password and stuff like what you said and etc.

It’s just a matter of, best not to put every egg in one basket basically

---

## Post 6 by @Spongeboob — 2025-08-01T21:06:41Z

I’m using the whole proton suite as well. I’ve got the unlimited plan, have been enjoying it for 2 months now. If I’m not mistaken there’s an option to have a separate password for proton pass? I might be wrong though.

Despite Proton’s recent announcement of their 2fa app, I’m sticking with Ente for the time being.

---

## Post 7 by @PaleCrow55 — 2025-08-01T21:19:35Z

> [@Spongeboob](#):
>
> If I’m not mistaken there’s an option to have a separate password for proton pass? I might be wrong though.

There’s an option for an _additional_ password for Proton Pass.

> [@Spongeboob](#):
>
> Despite Proton’s recent announcement of their 2fa app, I’m sticking with Ente for the time being.

Same

---

## Post 8 by @yes — 2025-08-01T21:27:11Z

I use the entire Proton suite + Ente for photos, [Stratum](https://stratumauth.com) for 2FA and Bitwarden as my (main) password manager.

---

## Post 9 by @anon11657877 — 2025-08-01T21:59:53Z

Use different services when using a service is necessary and use local solutions when possible instead of shifting trust to providers.

- Proton Mail or [Mailbox.org](http://Mailbox.org)
- Just use external storage (USB drives or external HDD) for backups or possibly Syncthing to transfer data to other devices
- KeePassXC or other KeePass forks depending on the OS, see above for how to sync it
- Your phone’s photo gallery app or an image viewer on your desktop OS, see above for how to backup photos
- Mullvad
- Offline notebook or possibly even a physical notebook if your threat model allows it
- Any PG recommended email aliasing service

---

## Post 10 by @anon73250778 — 2025-08-02T02:13:33Z

- I just transferred most of my VPN to Mullvad simply because it integrates well with Tailscale.
- I have my own domain for emails.

* * *

On the flip side, I am attempting to move my Joplin Notes and put them in the Proton Pass’ note functionality. It currently lacks markdown support and I need it for a checklist. Alternatively I am thinking of just using a local file and have it be synced around via Syncthing rather than a dedicated Docker container inside TrueNAS because I am too lazy to figure out why the Docker service isn’t seen remotely even if I have Tailscale on.

I am trying to get out of Proton Calendar. I am aiming for a Radicale server with a DAVx5 android client hosted in something like a Raspberry Pi but I haven’t gotten around it yet.

My 2FA codes are in my Yubikeys via the Yubikey Authenticator. I was supposed to just use Passkeys with Proton Pass but I am not 100% sold on Passkeys for now.

---

## Post 11 by @falcon — 2025-08-02T04:27:24Z

Recovery codes can mitigate such a lockout situation.

---

## Post 12 by @AnotherBloodyUsername — 2025-08-02T07:31:02Z

Been wondering this.

Personally I go with different services such as [Mailbox.org](http://Mailbox.org) for emails and calendar and hopefully contacts when they support groups.

They also support cloud storage accessible via webdav and can use joplin as well.

Tasks are done locally using [tasks.org](http://tasks.org) as Mailbox does not support recurring tasks.

Passwords I have been using dashlane since 2012 and they are quite good having started open sourcing their app and infrastructure.

Aegis for 2fa codes.

Vpn use mulvad

I would not necessarily stick with the whole proton system due to eggs in basket. But the point of degoogle debigtech is not put all your eggs in 1 basket

---

## Post 13 by @oci3o — 2025-08-02T16:29:05Z

This could be the way actually.

I quite like Tuta so may stick with them, I dont use email to email people really and I have a custom domain, so something like Purelymail maybe a shout given its price.

I was thinking of using a USB before I looked at the other services, and I wanted to leverage seedvault with grapheneos, might just try it with a USB and then restore to another profile and see what happens, worst comes to worst it doesn’t restore and I use Syncthing to my laptop.

---

## Post 14 by @ZenByte — 2025-08-02T17:00:15Z

The major issue for this setup is that it doesn’t play well when you are constantly sharing things with others, such as spouse, family, team, etc. where people need constant read/write access.

---

## Post 15 by @ZenByte — 2025-08-02T17:34:21Z

Doesn’t it make sense to prefer an ecosystem for related data since it limits the number of additional parties you need to trust? Email, password managers, contacts, and calendar usually share similar data.

For example, your email inbox could be thought of as an extension of your password manager since it can contain account information, it can often be used to verify you, and it can even be used to reset your password. Email aliasing service providers like SimpleLogin further co-mingle your email and password manager and present another party to trust unless you choose one that is owned by the same provider like SimpleLogin with ProtonMail, Apple’s Hide My Email with iCloud mail, and potentially Mozilla’s Firefox Relay with the upcoming Thundermail service in the future.

Likewise, contacts and calendar are usually paired with email as scheduling often goes through email. I’m not simply referring to personal emails, but nearly every business will send scheduling confirmations through email unless they’re trying to be annoying and only send it through SMS. As for contacts, even if you never manually enter a single contact, a potential breach of your mailbox would still leak a lot of people/businesses you interact with unless you delete all of your emails after reading them.

The point being that for a lot of people, using different providers for this stuff is less data compartmentalizing and more duplicating data with additional parties.

If the goal is fear of data loss and not privacy, then wouldn’t it make sense to simply make routine backups and to take steps to prevent accidental lockout?

---

## Post 16 by @oci3o — 2025-08-02T19:40:54Z

> Doesn’t it make sense to prefer an ecosystem for related data since it limits the number of additional parties you need to trust? Email, password managers, contacts, and calendar usually share similar data.

I think the concern from the community here, is what happens if Proton goes under? what happens if they turn evil, what happens if they are breached?  
Generally you gain better security from seperating the data, but again as you mentioned, it can be a benefit to trust one provider.

And I think data loss fear & privacy should be linked, what if your one provider goes under suddenly, think lavabit, and you only store data there.

And this is why I asked, to get different perspectives, my ideal would be get as many things on my devices as possible, and that is very possible, I can store music, photos etc on all my devices and keep them in almost real time sync with syncthing, I personally would prefer to use GrapheneOS seedvault, but I did some testing with its backups this afternoon and it really is not reliable, but as you mentioned, what if I wish to share a photo with someone? while that is rare for me, it happens from time to time, and I could just share it from my file system over a chat app and that would likely do 99% of the work.

---

## Post 17 by @lumino — 2025-08-02T21:42:41Z

Honestly, it depends. Proton has a good ecosystem and I am happy with them (I pay for Proton Unlimited). However I don’t use Pass (still pay for 1Password which still much better, especially because of the autofill shortcuts that I use all the time and the fact that the extensions work together with the desktop app). I also had to pay for Ente Photos because, honestly, is much better than Proton Drive for that task. And I also use Notesnook for notes since Standard Notes (which was bought by Proton) is really expensive. I also have a different cloud storage with cryptomator since Proton Drive does not backup files on my Mac (it only syncs the “Proton Drive” folder). They planned to release this feature on spring, but they missed it and who knows when they will finally do it.

This means: I do use the Proton ecosystem but I do complement their offering with other things that work better for me.

My suggestion: do whatever works for you. I don’t buy that “diversification” and “different baskets” is necessarily the best option, usually simplicity works better. I also don’t believe in sticking with one ecosystem or forcing yourself to it, when other other options might suit you best.

---

## Post 18 by @anonymous386 — 2025-08-03T01:53:58Z

Here is how I am thinking of this. It seems like we are asking two questions:

- Diversification vs. convenience?
- Proton’s security and trustworthiness?

Here are the relevant facts that are well established in this privacy community which answers those questions:

- Diversification is more important than convenience if you value privacy and security.
- Proton is trustworthy/private enough for the average person who does not have a high threat model.

From those two sentences, we basically have these two propositions:

- Diversification \> convenience
- Proton = trustworthy/secure

But I think the logical disagreement comes from this proposition:

- Proton = convenient

Position A says that if [Proton = convenient] and [Diversification \> convenience] then [Diversification \> Proton].

Position B says that diversification is not an end in itself, but rather a step to achieve privacy, which _is_ an end in itself. If [Proton = trustworthy/secure (for the average person seeking privacy and security)] and if [diversification is a step towards privacy and security] then [Proton \> Diversification] because it creates the very state of affairs that we seek to reach with diversification.

There’s probably other positions that people take than A and B, propositions that I didn’t mention or clarify, etc. Does this help clear the air, or is it just more confusing?

---

## Post 19 by @arise1984 — 2025-08-03T02:21:57Z

Its really up to each person threat model and needs, theres no generic “best” setup that works for everyone.

Personally i prefer and did segregation. Email, contact and calendar with a provider, and i used custom domain to not be locked to the provider. Pw manager with another provider, totp 2fa with another provider, cloud storage with another provider, notes with another provider. Only inconvenience for me is when logging in on a new device but that usually handled by the pw manager and i don’t change device that frequent.

---

## Post 20 by @AnotherBloodyUsername — 2025-08-10T15:53:10Z

> [@oci3o](#):
>
> I think the concern from the community here, is what happens if Proton goes under? what happens if they turn evil, what happens if they are breached?  
> Generally you gain better security from seperating the data, but again as you mentioned, it can be a benefit to trust one provider.
> 
> And I think data loss fear & privacy should be linked, what if your one provider goes under suddenly, think lavabit, and you only store data there.

This was exactly what I had been thinking. I was bummed at not getting the lifetime visionary plan when I may have been able to do so. But I never quite understood when they first launched a vpn after mail. There was a blog post about them having a less attack service since they did not do anything else but VPN and mail [Why Proton Mail Is More Secure Than Gmail | Proton](https://proton.me/blog/protonmail-vs-gmail-security)

Then they launched proton drive, and it seems as if proton are trying to be a whole drop-in replacement for Google services. Whereas when I first started working on degoogling, it was very much a case of use different options that can work together, which is why I have stuck with [mailbox.org](http://mailbox.org) for example as I can use any email app or calendar system as well as different cloud apps that support WebDAV. Or use davx5 etc. Plus, [mailbox.org](http://mailbox.org) only have paid plans, so there is no risk of free accounts bankrupting the service, unlike ProtonMail. Is [mailbox.org](http://mailbox.org) as good as proton mail? Not quite. But hopefully mailbox will just be as good as protonmail.

---

## Post 21 by @The_Centurion — 2025-08-10T22:31:45Z

You can have a little bit of both. It doesn’t have to be all one or one of everything. I use Proton for email, VPN, and drive. However, I maintain a secondary email address with Tutanota, use BitWarden for my password manager, and have my 2FA covered with YubiKey. I didn’t want to put all my eggs in one basket with Proton because it presents a single point of failure if my account is compromised. It also makes switching to different services harder (should Proton ever have a change in values).

---

## Post 22 by @landordragen — 2025-08-10T22:43:27Z

> [@The_Centurion](#):
>
> It also makes switching to different services harder (should Proton ever have a change in values).

Thankfully Proton makes it easy to export everything, on every service they provide.

---

## Post 23 by @win11.shading291 — 2025-08-24T21:33:45Z

> [@The_Centurion](#):
>
> It also makes switching to different services harder (should Proton ever have a change in values).

+1 to this. With the [CEO promoting Trump](https://discuss.privacyguides.net/t/proton-ceo-endorses-trump-nominee-for-assistant-attorney-general/24020), the disingenuous launch of [their AI](https://discuss.privacyguides.net/t/proton-markets-lumo-as-open-source-but-support-calls-it-a-long-term-intention-not-the-instantaneous-state/30004) and lately the disingenuous launch of their [2FA app](https://discuss.privacyguides.net/t/introducing-proton-authenticator-secure-2fa-your-way/29612), I would definitely not put everything in Proton.

---

## Post 24 by @iluvprivacy — 2025-08-24T23:20:10Z

I can no longer recommend Proton Pass and SimpleLogin. The PG community needs to avoid these two products until Proton changes its policy.

---

## Post 25 by @dngray — 2025-08-25T02:33:07Z

My general rule is to keep three major islands

- Email
- VPN (anonymization)
- Secret storage (passwords)

I’d only ever consider mixing Email/VPN if i have a local backup and a domain custom domain name that would allow me to migrate email to a new provider.

> [@win11.shading291](#):
>
> +1 to this. With the [CEO promoting Trump](https://discuss.privacyguides.net/t/proton-ceo-endorses-trump-nominee-for-assistant-attorney-general/24020), the disingenuous launch of [their AI](https://discuss.privacyguides.net/t/proton-markets-lumo-as-open-source-but-support-calls-it-a-long-term-intention-not-the-instantaneous-state/30004) and lately the disingenuous launch of their [2FA app](https://discuss.privacyguides.net/t/introducing-proton-authenticator-secure-2fa-your-way/29612), I would definitely not put everything in Proton.

That’s misinformation he did not “promote Trump” Trump was already voted in as president. The way I read it he was massaging Trump’s ego probably in the hopes that there won’t be bullshit regulation that hits his industry. If anything he was promoting [Gail Slater](https://en.wikipedia.org/wiki/Gail_Slater) (the pick that Trump made). More so specifically because of her work with antitrust.

Gotta remember these CEOs will say whatever they think is going to get the best result for their company at the time.

---

## Post 26 by @arise1984 — 2025-08-25T02:49:06Z

Maybe try proton for a few weeks first though before jumping full turkey moving all your data there on day 1. Since proton works on e2e basis, most things thats basic on cleartext service either aren’t available yet, doesn’t work as expected or just buggy. Among proton product, simplelogin, protonvpn and standard notes are the only 3 that i could stomach. Mail, calendar, drive, pass i use other services.

---

## Post 27 by @anon92357554 — 2025-08-25T04:27:48Z

> The way I read it he was massaging Trump’s ego probably in the hopes that there won’t be bullshit regulation that hits his industry. If anything he was promoting [Gail Slater](https://en.wikipedia.org/wiki/Gail_Slater) (the pick that Trump made). More so specifically because of her work with antitrust.

To paraphrase, he didn’t say “I support Gail Slaters” and called it a day, he said Republicans care about the little guy and Democrats care about big business.

Surely you can see the irony of him saying this while advocating for Gail Slater, who left her anti-trust job over a decade ago to work for [Internet Association](https://en.wikipedia.org/wiki/Internet_Association), a lobbyist group for big tech (including Google, Amazon, and Meta). She worked for the government after that and then sidestepped ‘working for the little guy’ to being a [lobbyist for Roku](https://www.politico.com/newsletters/politico-influence/2022/08/03/roku-in-house-lobbyist-00049653), arguably the worst offender in the country when it comes to privacy.

The only thing that she has made the news for so far is when she got rolled over by the administration and her deputies [were fired for refusing to push through a questionable merger deal between HPE and Juniper](https://www.msn.com/en-us/politics/government/want-your-company-s-merger-approved-pay-a-maga-influencer/ar-AA1KTmi4). As someone who lobbied on behalf of big tech/Roku, it’s not surprising that she didn’t take a stand and instead signed her own name to allow the merger to go through.

She has similarly rolled over for the housing industry as well. Here’s a quote from an article 2 days ago:

> “By all indications there is very little appetite for antitrust enforcement from the DOJ,” Francis X. Riley, a partner at **Saul Ewing LLP.** , said. “They just aren’t doing anything. They are letting these mergers go through with limited investigations or limited exchange of information, and this sheds light on the fact that the DOJ is not going to be active in antitrust enforcement actions.”

> **[Is the real estate industry getting its antitrust enforcement wish? ](https://www.housingwire.com/articles/is-the-real-estate-industry-getting-its-antitrust-enforcement-wish/)**
>
> Many real estate professionals hoped for weaker antitrust scrutiny from a Trump DOJ, and so far it appears they are getting their wish.

I say this not to call out your perspective but to point out that at face value, the lip service that the Proton CEO paid to her has more to do w/ his company than an intrinsic interest in protecting privacy.

> [@dngray](#):
>
> Gotta remember **these CEOs will say whatever they think is going to get the best result for their company at the time.**

I agree and disagree at the same time. The Proton CEO has made it clear that he will ‘play the game’ to benefit _his company_. To Americans he tweets about Republicans standing up for the little guy, yet to Europeans he sounds like a ‘woke liberal’ as he talks about [transparency, science, freedom, not taking democracies for granted and standing up to America](https://youtube.com/watch?v=ndlCMGxLQ38).

His amorality is a benefit _so long as it aligns with you as a consumer_. With that said, I did not come across the CEO for Tuta or Disroot or Ente or any other privacy company warmly embracing Gail Slater given her lobbyist background for companies that are anti-privacy.

Personally, I jumped ship from Proton after his brazen comments, but I admittedly wasn’t overly invested in the Proton ecosphere to begin with, so the decision wasn’t very hard for me. For others, I would encourage diversification.

---

## Post 28 by @dngray — 2025-08-25T05:03:28Z

> [@anon92357554](#):
>
> To paraphrase, he didn’t say “I support Gail Slaters” and called it a day, he said Republicans care about the little guy and Democrats care about big business.

Because that’s the narrative they want to hear. It’s obvious lip service for a man who has a ego issues.

> [@anon92357554](#):
>
> Surely you can see the irony of him saying this while advocating for Gail Slater, who left her anti-trust job over a decade ago to work for [Internet Association](https://en.wikipedia.org/wiki/Internet_Association), a lobbyist group for big tech (including Google, Amazon, and Meta). She worked for the government after that and then sidestepped ‘working for the little guy’ to being a [lobbyist for Roku](https://www.politico.com/newsletters/politico-influence/2022/08/03/roku-in-house-lobbyist-00049653), arguably the worst offender in the country when it comes to privacy.

Maybe so, but he didn’t pass any comment on Roku.

> [@anon92357554](#):
>
> The only thing that she has made the news for so far is when she got rolled over by the administration and her deputies [were fired for refusing to push through a questionable merger deal between HPE and Juniper](https://www.msn.com/en-us/politics/government/want-your-company-s-merger-approved-pay-a-maga-influencer/ar-AA1KTmi4). As someone who lobbied on behalf of big tech/Roku, it’s not surprising that she didn’t take a stand and instead signed her own name to allow the merger to go through.
> 
> She has similarly rolled over for the housing industry as well. Here’s a quote from an article 2 days ago:

All of this is after the post by Andy.

> [@anon92357554](#):
>
> I say this not to call out your perspective but to point out that at face value, the lip service that the Proton CEO paid to her has more to do w/ his company than an intrinsic interest in protecting privacy.

> [@anon92357554](#):
>
> I agree and disagree at the same time. The Proton CEO has made it clear that he will ‘play the game’ to benefit _his company_. To Americans he tweets about Republicans standing up for the little guy, yet to Europeans he sounds like a ‘woke liberal’ as he talks about [transparency, science, freedom, not taking democracies for granted and standing up to America](https://youtube.com/watch?v=ndlCMGxLQ38).

Proton primarily sells “encryption services” either in the case of Proton Mail and VPN services. I would speculate this has more to do with pacifying the current administration and avoiding the previous kinds of interest. Surely we remember this? [US attorney general William Barr says Americans should accept security risks of encryption backdoors](https://techcrunch.com/2019/07/23/william-barr-consumers-security-risks-backdoors/) as well as the [repealing of section 230](https://www.cfr.org/in-brief/trump-and-section-230-what-know).

It’s same “shift” that some other companies did in their messaging when Trump got elected. To some extent these relationships have [benefited US tech companies](https://www.bbc.com/news/articles/cdj2m3rrk74o).

---

## Post 29 by @anon92357554 — 2025-08-25T15:25:11Z

The conversation in a nutshell

> **Andy Yen** : Gail Slater is a great pick and Republicans are the only one standing up for the little guy  
> **Public Outcry** : Hmmm… _Full-throated_ support of the incoming administration/Gail Slater seems odd since they haven’t signaled that they care about privacy or anti-trust outside of breaking apart ‘woke’ companies? This isn’t going to end well.  
> **Gail Slater** : _Less than 6 months into the job and Slater has had her deputies fired for not pushing through a bad merger, and she has become a toothless yes-(wo)man for the administration_  
> **Paraphrasing your response** : How could Andy Yen have _possibly_ known we would end up here when he supported Gail Slater, who left her anti-trust work to be a lobbyist for big tech?

Not you specifically, but generally there is a Libertarian streak among many privacy forums that has a large blind spot. Most of us can objectively see in Europe how ‘protect children on the internet’ is a pretext to erode privacy, or in retrospect how government used 9/11 to erode our privacy, yet every current Republican anti-privacy directive goes unchallenged.

There’s obvious examples like aggregating governmental data for ‘efficiency’ that just so happens to [create more expansive data profiles on every American](https://www.nytimes.com/2025/04/09/us/politics/trump-musk-data-access.html), to pushing through laws that allow [ISPs to sell user data for profit](https://www.consumerreports.org/consumerist/president-trump-signs-resolution-killing-internet-privacy-rules-allowing-isps-to-keep-selling-your-data/), or creating a pipeline for [your personal health data to be shared with big-tech](https://www.wpbf.com/article/trump-health-tracking-system-privacy-concerns/65554668) by default, or things like [requiring IDs in the US to ‘protect the children’](https://discuss.privacyguides.net/t/wyoming-and-south-dakota-age-verification-laws-could-include-huge-parts-of-the-internet/30066), or things like [giving private Governmental data to Palantir to compile a police state](https://www.msn.com/en-us/news/other/how-palantir-is-powering-a-new-age-of-authoritarian-control/ar-AA1G0AGm), yet there is little/no interest on the majority of the board to reflect critically on whether the administration is pro-privacy or anti-privacy, and subsequently, what it means when a pro-privacy CEO is seen giving the effusive praise.

**Bringing things back on topic, I would encourage that users diversify their privacy services to hedge risk** I care about privacy more than Proton’s profitability, I don’t think I can say the same for Andy Yen given his statements.

---

## Post 30 by @dngray — 2025-08-25T15:32:45Z

> [@anon92357554](#):
>
> **Paraphrasing your response** : How could Andy Yen have _possibly_ known we would end up here when he supported the administration?

I don’t think it was really about that at all as it’s not like he was involved in the decision making process that led to her being given that position. I think people are reading more into it than what is actually there.

There are quite likely a lot of other things the Trump administration does that he doesn’t agree with, and for the time being I totally expect he would keep those thoughts to himself as any CEO would.

> [@anon92357554](#):
>
> **Bringing things back on topic, I would encourage that users diversify their privacy services to hedge risk**

Agreed, that way you limit risk if you were to be locked out of something.

---

## Post 31 by @Tux — 2025-08-27T07:07:04Z

Self-host everything you can. Email can be tricky (need a clean IP and a domain name). Proton is probably OK, but as far as I remember you do not get IMAP access on the free tier. For me, that’s a non-starter.
