Privacy setup without Proton

Hello everyone. I’m trying to create a privacy setup without Proton and I need some assistance.

First of all, why not Proton? I’m preparing for a near future scenario where VPNs are going to get banned or heavily regulated in my country. Our government is very restrictive with the internet and has already started preparations for implementing an ID verification mandate for VPN providers. What is being different from most of the other countries, the government will be the one collect information on which apps and social media profiles you verified, and they will log usernames and VPN subscriptions in a government database under your name(they openly stated that). Regardless of which Proton service it is, on bank receipts it shows up as “Proton AG.” Now, this is a problem for me because knowing how things work in my country (with the least number of brain cells possible), it is not a distant possibility that either my bank account will be blocked or the police will pay me a visit at my door solely for paying for a very very scary mail provider also happens to be a VPN company, even if I don’t use the VPN. No, I cannot pay anything with crypto either, because that is also banned and heavily regulated with know your custmer standards where I live.

So I ended up reviewing my alternatives for what the Proton ecosystem provides. I aimed to segregate my services instead of being locked into a single ecosystem.

-Mail: While this one was supposed to be the easiest on the list, I was heavily disappointed with my alternatives. I want to abstain from self hostingthis one because I still think hosting your own email requires a lot of effort and maintenance, and unfortunately, I don’t have the time and energy for that. First, I paid for a monthly subscription with Tuta; at first, everything seemed okay, but then I noticed that I wasn’t able to receive certain emails from various services (especially local services I need to use). Also, the UI is… very Tuta. I also tried the paid Mailbox.org plan, and it was worse for me than Tuta I couldn’t even receive banking emails that I need most. For Tuta and Mailbox.org, I got the feeling that I’m going to miss certain emails without knowing. Posteo is the one I haven’t tried yet and I will give that a try too.

So in the end, I still have a question mark about what I’m going to do for my mail setup. For now, Tuta is the best contender, but for my case, it still feels unreliable.

-Aliases: There is no question here addy.io is the way to go.

-Drive/Photos: There are very good alternatives here, but unfortunately, I’m on budget because of the exchange rates. I’m open to paying less with lesser convenience on this one. Ente and Filen are both good options, but honestly, I’m thinking about getting myself a cheaper non bigtech drive storage option and encrypting my files with Cryptomator. But the problem is, I have around 300 GBs worth of images and videos in my gallery, and I don’t know how manageable it will become with Cryptomator and no thumbnails. I’m open to suggestions here, especially on self-hosting (outside of my home).

-VPN: As I mentioned, the main reason I’m trying to get away from Proton is a possible future where paying a VPN company (or one that also offers/is associated with a VPN service) becomes criminalized. All of the issues I mentioned are also valid for Mullvad. It is possible that I cannot pay them with my bank card, anonymous pre-paid cards (they don’t exist where I live), or crypto. Also, ISPs here are blocking VPNs with DPI, and honestly, it is a very fierce cat and mouse game. Even Proton’s stealth protocol occasionaly fails. I can only think maybe I’ll rent a VPS and host my own VPN, but I’m not sure how private that is going to be (from the VPS owner) aside from just bypassing restrictions. So yeah, I’m pretty hopeless on this part.

-Password Manager/Authenticator: I don’t have any problems here because I wasn’t using Proton Pass in the first place.

I’m open to all help and critique. Thanks in advance.

Use cash.

Mullvad takes cash in the mail. However, given what you’ve described, connecting directly to a VPN from your local IP may draw unwanted attention. The VPS self-hosted VPN idea is good. You’re then trusting the cloud provider over authorities in your own country. You can look into confidential computing (e.g. AMD SEV-SNP) to try and make what you’re doing on the VPS more private from the cloud provider, but that adds complexity, and, potentially, cost.

300GB isn’t very big, but bigger than many cheap VPS’s have access to by default. Cryptomator+any other cloud storage you have access to should work. If you have family or friends that don’t mind a used 1TB USB drive attached to a cheap computer and wireguard/tailscale might be cheaper in the long run than paying for cloud storage if you don’t already have access, but that’s work.

It’s just one of their issues.

Send cash or buy a voucher via ProxyStore (mentioned above).

In this case, you should generally stick to what works for people around you, provided it doesn’t compromise your privacy more than your ISP already does.