# Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester

**URL:** https://discuss.privacyguides.net/t/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protester/36007
**Category:** News
**Tags:** article
**Created:** 2026-03-05T23:14:20Z
**Posts:** 133

## Post 1 by @Harisfromcyber — 2026-03-05T23:14:20Z

Read an article from 404 Media that was interesting: [Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester](https://web.archive.org/web/20260305204857/https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/) .

Quote from Proton:

" **…the company behind Proton Mail, told 404 Media in an email: “We want to first clarify that Proton did not provide any information to the FBI, the information was obtained from the Swiss justice department via MLAT. Proton only provides the limited information that we have when issued with a legally binding order from Swiss authorities, which can only happen after all Swiss legal checks are passed. This is an important distinction because Proton operates exclusively under Swiss law.** ” "

Edit: switching over code block for bolded quoted text.

---

## Post 2 by @Harisfromcyber — 2026-03-05T23:16:02Z

Sorry all, seems like a subscriber-only article. Quoted the main item.

---

## Post 4 by @CarefulMouse — 2026-03-05T23:38:22Z

I have seen commentary online that this means Proton only gave payment info and no other information. I haven’t seen an indication the scope of information provided to Swiss authorities was limited to payment data.

I think it is notable that even if you **pre-fund** your account with alternative payment methods, you cannot delete credit card data while on a paid plan. I personally feel that if the account is sufficiently pre-funded with available credits through alternative methods (Cash, BTC, Gift Card) I would think you could delete your payment method.

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/f/b/fb7575449b5b34bc47c5728f7de339613bbe301a.png)  
 ![image2](https://forum-uploads.privacyguidesusercontent.com/original/3X/1/4/14cac8533215ab1330e117d29e3cf66f7cd02d95.png)

---

## Post 5 by @Valynor — 2026-03-05T23:49:41Z

“Proton Mail Helped FBI” != “Proton did not provide any information to the FBI”

so right from the start this is a bad article because the headline states something that is immediately rejected by PM in the article.

They got presented with a **legally binding order from Swiss authorities** , they followed the law. And honestly that’s all there is to say about it IMHO.

Edit: almost the same thing happened 2021 with a French activist.  
Proton Mail will give up data they have on you when presented with a valid court order.  
Only use it over Tor and pay in cash if your threat model requires it.

---

## Post 6 by @CarefulMouse — 2026-03-05T23:57:06Z

See if this [archive.org](http://archive.org) link works, if you want to edit the OP:

> **[Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester](https://web.archive.org/web/20260305204857/https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/)**
>
> A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.

---

## Post 7 by @archetypicalswan — 2026-03-06T00:17:03Z

I don’t know why 404media chose the framing they did here. Articles pitched this way only end up making people less likely to choose privacy-based big tech alternatives. Proton didn’t help the FBI, they were forced to provide data to the Swiss government who then helped the FBI.

I don’t think it’s _good_ that Proton revealed this info, but I fail to see what choice any company has in the matter? They could refuse to follow the law I guess?

The same applies for Tuta, mailbox, etc. and would defend them equally.

---

## Post 8 by @passkeys — 2026-03-06T00:20:07Z

Proton is a legal entity that has to follow the law. Proton provides a way to pay for an account anonymously via cash. The user decided to use a tracible credit card. It’s their own fault for terrible opsec.

---

## Post 9 by @Harisfromcyber — 2026-03-06T01:24:35Z

added now, thanks @CarefulMouse!

---

## Post 10 by @Julie — 2026-03-06T01:27:15Z

In the case of another activist they provided is backup email adress.

That’s the way he was caught…

---

## Post 11 by @arise1984 — 2026-03-06T03:16:28Z

Expecting to be fully anonymous then proceed to pay a service with visa/mastercard that could be tracked back to them is a massive fukup from that activists. Thats like opsec 101.

---

## Post 12 by @anon51983832 — 2026-03-06T06:27:30Z

I might be missing something, but if someone simply had a Proton subscription paid with their credit card, would authorities have access to the contents of their emails or aliases (from SimpleLogin or Proton)? I’m not sure what metadata Proton collects.

On the other hand, a Catalan activist or politician, as mentioned above, had an Apple recovery account. What does this imply? If the recovery account were with Tuta, would that change anything?

---

## Post 13 by @CarefulMouse — 2026-03-06T07:41:33Z

This issue as I see it is that it’s not exactly clear either of these examples could lead to doxing in the future. For example, Mullvad [permanently deletes payment data sometimes after only 20 days.](https://mullvad.net/en/help/privacy-policy) Whereas, as I mentioned above, Proton does not even allow the user to manually clear the data. There is certainly clear benefit in Proton storing your payment info, but to restrict the user from manually deleting the data is a very odd choice given the nature of their Privacy claims.

The issue with the recovery email situation, in my opinion, is the unclear nature differentiating recovery email address vs. verification emails. See [this take on the dark patterns](https://discuss.privacyguides.net/t/proton-mail-discloses-user-data-leading-to-arrest-in-spain/18191/38) which I think exist both before and after account creation related to the recovery email address.

---

## Post 14 by @anon4124882 — 2026-03-06T07:54:23Z

There is so much poor discussion of this on Reddit. The title is also to blame for how it portrays Proton.

Human error when setting up your OPSEC is to blame. Not the company following the law or the law itself.

This just goes to show, when choosing privacy first services, always use the most private option to pay for it. It’s also best to harden your account by changing your settings such that no IP logs or anything are recorded. And of course using a strong password with 2FA is always the way to go.

---

## Post 15 by @Bhaelros — 2026-03-06T08:59:13Z

So, people expect Proton to close down whole business because they complied with **Swiss** court order? That “activist” also used their own credit card for payment. Who would have tought Proton will give whatever info they have to courts if there is a valid order? Which are also very limited, like your IPs, recovery methods, subject of the mail, and so on. Blaming Proton for complying with local law and also having zero clue about privacy, well..

> **[Proton Mail encryption explained | Proton](https://proton.me/support/proton-mail-encryption-explained)**
>
> Proton Mail stores all data in an encrypted form. Here you can read about what is end-to-end encrypted and how the stored data is saved.

---

## Post 16 by @anon4124882 — 2026-03-06T09:05:40Z

> [@Bhaelros](#):
>
> people

Most of these people don’t understand tech, policy, privacy, and how it works with the law. These are barely armchair experts on the matter yapping about things that don’t follow logic. I don’t mean to be crudely evaluating others but those in the know who are in the privacy community would come to the same conclusions about discourse on the topic elsewhere.

Just read the reddit threads.

---

## Post 17 by @ph00lt0 — 2026-03-06T09:16:09Z

I unsubscribed from 404media, crazy clickbait and dump article.

---

## Post 18 by @anon4124882 — 2026-03-06T09:19:08Z

I really thought they were better equipped to properly evaluate the facts and express them more factually and not succumb to dumb clickbait titles when they are being paid for it.

I would not have gone so far as to have unsubscribed (yet) but yes, this is very disappointing.

---

## Post 19 by @arise1984 — 2026-03-06T10:27:03Z

Its not just on reddit, its everywhere. On hackernews, on mastodon. I would’ve expect the crowd at hackernews and mastodon to be more capable of rational thinking than reddit trolls but nope, they bandwagon with pitcfork yap about how proton aren’t privacy respecting. I’m not really a fan of proton, but come on people… Credit is where its due and pitchfork should be the same too. This is just classic opsec fail, nothing more.

---

## Post 20 by @iluvprivacy — 2026-03-06T10:27:36Z

What do you do if they already have your payment information from a previous transaction? I think Proton should find a way or give us the option to delete any other identifiable information that they may have so that we can start fresh.

I’m going to have to revisit my relationship with email after this. It’s exactly what I said before on PG - that it’s best to minimize or even avoid emails.

---

## Post 21 by @passkeys — 2026-03-06T10:29:30Z

[Proton’s response on Reddit](https://www.reddit.com/r/ProtonMail/comments/1rlt75p/comment/o8xtkgt/):

> First, let’s correct the headline: Proton did not provide information to the FBI. What happened is that the FBI submitted a Mutual Legal Assistance Treaty (MLAT) request, which was processed by the Swiss Federal Department of Justice and Police. Proton operates exclusively under Swiss law, and we only respond to legally binding orders from Swiss authorities, after all Swiss legal checks have been passed. **This is an important distinction.**
> 
> Second, let’s talk about what this case actually involved. This wasn’t a routine investigation. Swiss authorities determined that the legal threshold was met because a law enforcement officer was shot, and explosive devices were found during a protest in 2024. Switzerland has one of the strongest legal frameworks for privacy in the world, and its standard for granting international legal assistance is exceptionally high. This case met that standard.
> 
> Third, let’s talk about what was actually disclosed. No emails were handed over. No message content. No metadata about who the user communicated with. The only information Proton could provide was a payment identifier because the user chose to pay with a credit card. This is information the user themselves provided to us through their choice of payment method. Proton also accepts cryptocurrency and cash payments, which would not have been linkable to an identity.
> 
> If anything, this case demonstrates exactly what we’ve always said: Proton holds very little user data by design. Even under the most serious legal circumstances, the only data that could be produced was a payment record. Our encryption means we simply cannot access email content even if ordered to.
> 
> We understand that stories like this can be alarming, and we take our users’ trust seriously. We will continue to fight for privacy and challenge any legal order we believe does not meet the strict requirements of Swiss law. But we also want to be transparent: no service can operate outside the law entirely, and Swiss law requires compliance with valid legal orders in serious criminal cases. What we can promise is that the legal bar in Switzerland is among the highest in the world, and our architecture ensures we have as little data as possible to hand over.
> 
> **For users who want maximum anonymity:** use Proton with a VPN or Tor, pay with cash or cryptocurrency, and don’t add a recovery email.

---

## Post 22 by @iluvprivacy — 2026-03-06T10:30:56Z

Here’s the problem and I’ve said this before. No company executive is going to risk going to jail to defend you. Doesn’t matter if it’s Proton and Tuta. I think PG should try to steer people away from email. Usage should be kept at the bare minimum. Of course, they’ll follow all lawful orders.While I do believe Proton would do everything possible in court to resist handing the information out, if the judge says hand over the data, they will. What will you do then?

---

## Post 23 by @iluvprivacy — 2026-03-06T10:36:16Z

@jonah, is there a way to get a Proton and Tuta rep to participate here rather than just relying on Reddit?

For existing users, who have made the mistake of using a credit card to pay and gave Proton/Tuta a recovery email, is there a way to remove it? Will any of these companies work with its users to clean up their accounts to remove all identifiable information?

---

## Post 25 by @passkeys — 2026-03-06T10:46:36Z

I will try and get someone from the Proton team to respond in here, but I would imagine there’s not much more they can add from the comment posted on Reddit.

---

## Post 26 by @iluvprivacy — 2026-03-06T10:55:04Z

As a community, we need to demand both Proton and Tutanota give us the options to clean up our accounts. I’m glad that Proton cleared things up in their response, but just because we paid with a credit card once doesn’t mean that information should stay on the account forever. I’m officially going to stop sending any emails from both Proton and Tutanota until this is resolved. I might even close my accounts.

---

## Post 27 by @passkeys — 2026-03-06T10:58:49Z

I get what you’re saying and I wish the same, but it’s not as simple as that. Under Swiss law, Proton (and other Swiss companies) have to keep payment information up to 10 years per Article 958f of the Swiss Code of Obligations. It’s up to the user at the end of the day to manage their threat model and opsec.

---

## Post 28 by @iluvprivacy — 2026-03-06T11:06:53Z

Is it confirmed that Proton has to keep it for ten years? No way around that? Damn! What happens if I delete my account? Sounds like I’ll be done with my current Proton account.

---

## Post 30 by @anon4124882 — 2026-03-06T11:11:21Z

Poor OPSEC set up is on the user. Proton and Tuta offer private payment options. And provide ability to fully maximize your privacy and anonymity. In this case, the activist did not follow and set it up properly. That’s on the user.

What would you have Proton do? Break the law and not provide details it had for a legal order?

What you and everyone should know: the company/any company can only give info they have. If you can use a service they provide without providing any info, that’s what you should be doing if you’re going to be engaging in sensitive acts as an activist.

This is like being mad at Proton for your account being hacked because you did not have 2FA and used your birthday for your password. Buddy.. that’s on you then.

---

## Post 31 by @anon4124882 — 2026-03-06T11:15:43Z

> [@iluvprivacy](#):
>
> As a community,

Also, speak for yourself only please. Claiming to speak on behalf of a community makes you come off as more pretentious than actually knowledgeable. Sorry, no one else will say it but it needs to be corrected. I can’t believe I am the only one feeling icky about being included in someone else’s comment without even a general community consensus on a new news item.

---

## Post 40 by @Proton_Team — 2026-03-06T14:24:42Z

> [@iluvprivacy](#):
>
> just because we paid with a credit card once doesn’t mean that information should stay on the account forever.

Once a card is removed from an account that information is deleted.

**EDIT:** to clarify that, we will know you paid in the past and with credit card, but we don’t store the card details for past transactions.

As above:

_ **For users who want maximum anonymity:** use Proton VPN or Tor, pay with cash or cryptocurrency, and don’t add a recovery email._

---

## Post 41 by @archetypicalswan — 2026-03-06T14:45:29Z

How can this be? Don’t businesses need to store financial records?

Your response feels too good to be true. Are you _ **sure** _ that’s the actual way your systems are set up?

How would you ever survive an audit from a credit card company if this was the case? How would you address a chargeback from a customer who deleted their card?

---

## Post 42 by @CarefulMouse — 2026-03-06T14:53:14Z

If just feels so disingenuous to read this statement when items were already addressed as not being sufficient, but seemingly ignored.

> [@Proton_Team](#):
>
> **For users who want maximum anonymity:** use Proton VPN or Tor, pay with cash or cryptocurrency, and don’t add a recovery email.

Proton VPN - [Leaks your IP address](https://discuss.privacyguides.net/t/remove-protonvpn/33980/181)

The use of “Cryptocurrency” is effectively just Bitcoin. XMR was never implemented to be able to fund your account with XMR credits, and is [not available for most service plans.](https://digitalgoods.proxysto.re/en) Only Proton Pass is available at a significant mark-up.

> _The vast majority of cryptocurrencies operate on a **transparent** blockchain, meaning that every transaction’s details are public knowledge. This includes most well-known cryptocurrencies like **Bitcoin** and Ethereum._ [Source](https://www.privacyguides.org/en/advanced/payments/#virtual-cards)

In my opinion, a recovery email could be stored more securely. I guess there is no reason to re-iterate the very well authored [dark pattern](https://discuss.privacyguides.net/t/proton-mail-discloses-user-data-leading-to-arrest-in-spain/18191/38) post, but I’ll link it once more.

Even if you do decide to switch to BTC or Cash as a your new payment method - it’s not possible to delete your credit card while still subscribed.

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/f/b/fb7575449b5b34bc47c5728f7de339613bbe301a.png)

---

## Post 43 by @OhNoes — 2026-03-06T14:53:32Z

Well, maybe you should change your payment system then. With a subscription for a year I cant remove my credit card.

“Please add another payment method or cancel your subscription first”

---

## Post 44 by @KathyM — 2026-03-06T15:00:17Z

> [@Proton_Team](#):
>
> to clarify that, we will know you paid in the past and with credit card, but we don’t store the card details for past transactions.

So this case involved a user with an active recurring payment?

---

## Post 45 by @anon78546094 — 2026-03-06T15:19:28Z

AFAIK, Proton stores a payment token and some _essential_ transaction details (transaction ID, amount, date, currency and last 4-digits of the card), but **does not store the full card details.**

---

## Post 46 by @anon78546094 — 2026-03-06T15:20:31Z

Most services don’t let you change your payment method unless you **cancel the subscription** or **add a new payment method** , because the subscription is tied to the **payment token** that was generated when you first added a card. That token is what the billing system (and the payment processor) uses to charge you each cycle.

For me, that limitation feels reasonable—but, as @CarefulMouse pointed out, even after adding a cryptocurrency/cash payment method as the primary option, you still can’t delete the previously‑saved card. That restriction doesn’t make sense to me.

---

## Post 47 by @archetypicalswan — 2026-03-06T15:33:55Z

There is no meaningful difference there though. If you have that data you can then ask the card company for the rest.

And to be clear I actually don’t think proton did anything ”wrong” here, I just don’t think anonymity via credit card payment should be assumed by anyone.

---

## Post 48 by @anon78546094 — 2026-03-06T18:56:09Z

Aside from cash, there isn’t an _anonymous_ payment option for Proton services, since they don’t support Monero and BTC isn’t private. That’s the main reason I stopped using Proton services last year.

---

## Post 49 by @archetypicalswan — 2026-03-06T19:17:58Z

Totally fair!

---

## Post 50 by @Expert4870 — 2026-03-06T19:59:39Z

I 100% agree with you they should accept Monero, but Monero–\>Bitcoin–\>Proton is anonymous. It is not private, but it is anonymous.

---

## Post 51 by @PurpleDime — 2026-03-06T21:35:47Z

**IMHO, THE HEADLINE IS ACCURATE**

> [@Valynor](#):
>
> “Proton Mail Helped FBI” != “Proton did not provide any information to the FBI”
> 
> so right from the start this is a bad article because the headline states something that is immediately rejected by PM in the article.

I disagree. Words have meaning. How you use them matters, and this headline to me strikes accurate. Proton helped the FBI. They helped an FBI investigation. The fact that they didn’t directly hand over the user’s info to the FBI is irrelevant. The original request was made by the FBI, and they got the information they asked for from the Swiss government who compelled Proton to do so.

> [@Valynor](#):
>
> They got presented with a **legally binding order from Swiss authorities** , they followed the law. And honestly that’s all there is to say about it IMHO.

Yes, Proton followed the law. Nobody is saying they should have disobeyed the law. But the truth is this: **most Proton users are unaware of all the types of information Proton holds that are not E2EE and that can be shared with authorities.** And in my opinion, **that is partly Proton’s fault** because Proton is not completely upfront about it.

By that I mean that Proton doesn’t share ALL that information in their marketing or make it easily available on their website. It’s not front and center. They are open about the fact that some of the metadata around your emails is not E2EE, but that doesn’t cover everything. There are a lot of things they have NOT communicated in their marketing or on their website that you have to ask to know the answer.

I am sure that a lot of people here had no idea that your recovery email address could identify you until the controversy about that Spanish activist who was identified through their Apple ID that they used as recovery.

Some companies keep records of the information you delete, and we don’t know the full details of that. For example, 1Password keeps a record of all the email addresses you used with your account even after you change it. I had to ask Proton to find out if they keep records of deleted recovery email addresses. It was not in their marketing nor on their website. I don’t believe that has changed.

**PROTON BARES SOME RESPONSIBILITY AND CAN DO BETTER**

> [@arise1984](#):
>
> Expecting to be fully anonymous then proceed to pay a service with visa/mastercard that could be tracked back to them is a massive fukup from that activists. Thats like opsec 101.

Who said the activist expected to be anonymous? We don’t know that.

In my opinion, as with many companies, there is a significant gap between Proton’s marketing messaging and what they actually deliver in terms of protection. Ideally that gap should be tiny, but many people, understandably, only retain what is in the marketing.

If Proton were forthright about what they don’t protect in their marketing and communication on social media and websites, we would be less upset about these cases.

I understand that Proton is rightly obeying the law. But the reason these controversies look bad is because there is a lack of transparency and lack of effort to protect users’ privacy. I suspect that Proton doesn’t want to be so transparent that it hurts their marketing efforts, but I still believe that more transparency and better efforts to protect user privacy would go a long way.

> [@anon4124882](#):
>
> Human error when setting up your OPSEC is to blame. Not the company following the law or the law itself.

> [@Bhaelros](#):
>
> Who would have tought Proton will give whatever info they have to courts if there is a valid order? Which are also very limited, like your IPs, recovery methods, subject of the mail, and so on. Blaming Proton for complying with local law and also having zero clue about privacy, well..

> [@archetypicalswan](#):
>
> I don’t think it’s _good_ that Proton revealed this info, but I fail to see what choice any company has in the matter? They could refuse to follow the law I guess?

> [@anon4124882](#):
>
> What would you have Proton do? Break the law and not provide details it had for a legal order?

I disagree that there isn’t much Proton can do. There is actually a lot.

1. _ **Be transparent about ALL the things that can be shared about users in full detail.** _
2. _ **Be transparent about ALL the information that you retain and for how long.** _
3. _ **Make that information clear, explicit, comprehensive, and easy to find.** _

Put it in your marketing. Let people see it when they sign up and easily find this information when they visit your website. Include it in the welcome email.

1. _ **Make your credit card payments anonymous like Posteo.** _

Posteo is a private email provider based in Germany, and [they have found a way to NOT connect the data that they receive during credit card payments with your email account with them.](https://posteo.de/en/site/payment)

They have been doing this since 2009! Why can’t Proton follow this model?

1. _ **Accept anonymous payments.** _

Contrary to popular belief, [Proton does not accept anonymous payments.](https://discuss.privacyguides.net/t/proton-pass-and-simplelogin-are-separate-services/30706/26)  
And that is a big problem.

---

## Post 52 by @PurpleDime — 2026-03-06T21:51:45Z

[**PROTON DOES NOT ACCEPT ANONYMOUS PAYMENTS**](https://discuss.privacyguides.net/t/proton-pass-and-simplelogin-are-separate-services/30706/26)

> [@Proton_Team](#):
>
> **For users who want maximum anonymity:** use Proton VPN or Tor, pay with cash or cryptocurrency, and don’t add a recovery email.

> [@passkeys](#):
>
> Proton is a legal entity that has to follow the law. Proton provides a way to pay for an account anonymously via cash.

> [@anon4124882](#):
>
> Proton and Tuta offer private payment options.

> [@Proton_Team](#):
>
> **For users who want maximum anonymity:** use Proton VPN or Tor, pay with cash or cryptocurrency, and don’t add a recovery email.

Proton claims to support anonymous payments, but they don’t for the following reasons:

_**A) They don’t accept Monero**_

Case in point:

> [@CarefulMouse](#):
>
> The use of “Cryptocurrency” is effectively just Bitcoin. XMR was never implemented to be able to fund your account with XMR credits,

I have said in the past that I personally understand [Proton’s declared reasons for not accepting direct payments via Monero](https://optoutpod.com/episodes/protonwallet-andy-yen/). I don’t hold it against them. But for the rest, I absolutely do.

[_**B) Proton Cash Payments are not anonymous**_](https://proton.me/support/payment-options#cash)

**Proton cash payments require that you declare your Proton username, which compromises your privacy.** Many Proton usernames are linked to real names. When Proton receives a cash payment, a human agent has to manually add the payment to your account. Why? If I can pay Proton via credit cards without human interference reading my profile, why can’t I do the same with cash?

Plenty of privacy companies accept cash directly without requiring you to declare your username ( **Mullvad** , I **VPN** , **Posteo** ). **Why can’t Proton copy their model? Or the model of Tuta and Addy, that accept cash indirectly?**

[_**C) Proton gift cards cannot be purchased anonymously**_](https://shop.proton.me/products/proton-50-gift-card-print-at-home)

They cannot be bought with cash or Monero.

They can only be bought with credit cards or other cryptocurrencies that are **NOT anonymous**.

**Do you know which privacy companies allow their gift cards to be bought anonymously with cash and Monero?**

Tuta. Addy. SMS Pool. SimpleLogin.

Yes, Proton’s SimpleLogin allows their gift cards to be bought anonymously, since before they were acquired, and still Proton won’t follow that model.

All this is extremely poor implementation when you compare it to Proton’s competition who have been doing it well for years. It’s even more egregious that they are doing it right with SL but not with Proton native services.

_There’s a bonus reason I won’t mention because I have been preparing a post about it since last year, and I’d rather share it when I have all the info I need. But I suspect someone will hit my bingo card._

> [@anon4124882](#):
>
> This just goes to show, when choosing privacy first services, always use the most private option to pay for it.

I agree that it’s best to use the most private option available. Proton has more private options than credit cards, but the fact remains, as it stands, Proton does not accept anonymous payments.

**PAYMENT RETENTION POLICY UNCLEAR:  
PROTON, PAYMENT PROCESSING COMPANIES, & VIRTUAL CREDIT CARDS**

> [@Proton_Team](#):
>
> **EDIT:** to clarify that, we will know you paid in the past and with credit card, but we don’t store the card details for past transactions.

**Are you 100% sure about that?**

That is not my understanding.

**What about past PayPal transactions? Do you store the PayPal account’s details?**

> [@CarefulMouse](#):
>
> I think it is notable that even if you **pre-fund** your account with alternative payment methods, you cannot delete credit card data while on a paid plan. I personally feel that if the account is sufficiently pre-funded with available credits through alternative methods (Cash, BTC, Gift Card) I would think you could delete your payment method.

> [@iluvprivacy](#):
>
> What do you do if they already have your payment information from a previous transaction? I think Proton should find a way or give us the option to delete any other identifiable information that they may have so that we can start fresh.

Indeed, it is unclear if deleted payment methods that have been used can be traced to the user.

The way I understand it, Proton does not keep a record of the cardholder name, in fact I don’t even think it is required. They also do not keep a record of the full number of your credit card, just the last 4 digits. They do however, keep a record of the country your credit card is from.

On the flip side, Proton’s payment processing companies, Stripe and Paddle, keep a record of all the digits in your credit card, as well as the country. I was told that both Proton and their payment processing companies keep a record of past payment info for up to 10 years.

Here’s what I don’t understand.

**1) If Proton does not keep a record of the cardholder name and only the last 4 digits, how was the owner of the Proton account identified? Did Stripe provide the info?**

If it was provided by Stripe, then it just goes to show that Proton’s minimum data retention policy for card payments is moot.

**2) Can deleted virtual credit cards (VCC) be traced?**

This is an important question to ask all VCC providers. Especially if you use them with Proton and other privacy services.

**If I delete a VCC, is it actually deleted, in that my provider also loses all record of it?**

Because if a deleted VCC can be traced, that is an issue. I intend to ask my provider, and I recommend you ask yours. And when they give you an answer, ask them to triple-check.

Too many times, I have been told things by customer service agents at my bank and even Proton that were bad information. This is why I always ask them to triple-check with colleagues and superiors.

[**Proton should follow Posteo’s example**.](https://posteo.de/en/site/payment)

In 2009, they found a way to anonymize credit card payments.  
I don’t see why Proton can’t do the same. Or why they didn’t start doing that from the very beginning since Proton Mail launched 5 years later, in 2014.

---

## Post 53 by @iHateKYC2 — 2026-03-07T00:09:58Z

This person publicly associated their protonmail they pay for, with a personal credit card, on a public facebook page associated with a questionable movement. They made the probable cause easy for the feds.

This is why you always operate as if you’re being watched, don’t wait till it’s confirmed you are being watched.

---

## Post 54 by @PurpleDime — 2026-03-07T10:43:46Z

That doesn’t change the fact that Proton could have preemptively done more to protect its users. Many of Proton’s competition, which includes email providers, have better privacy for payments. [See my two comments above.](https://discuss.privacyguides.net/t/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protester/36007/51) If Proton had followed their competition’s model, it would have been much harder for the FBI to identify that user through Proton, as they would have much less data to offer.

---

## Post 55 by @shadowwwind — 2026-03-07T12:30:59Z

The way I understand Posteo’s approach, it relies on trusting them not to store connection/with PayPal and credit card payments that they actively delete the connection.

With a system using blind signatures like Taler it should be possible to cryptographically disconnect transactions and accounts.

What I want to say is, Posteo’s approach only protects against somebody trying to tie payment and account together retroactively. They could get forced to change it without users noticing.

A system using blind signatures could cryptographically guarantee to make a connection impossible.

---

## Post 56 by @Scott — 2026-03-07T16:17:25Z

Encase anyone is wondering how Tuta handles “anonymous” payments:

> **[Terms and Conditions for Tuta Gift Cards | Tuta](https://tuta.com/gift-cards-terms)**
>
> Terms and Conditions for Tuta Gift Cards

“Gift cards can only be purchased by customers who have provided credit card details or PayPal as a payment method.”  
I assume these gift cards are the vouchers we can buy from ProxyStore.

===============================================  
Under “How can I upgrade my Tuta account with cryptocurrency?” Tuta seems to be saying the exact opposite.

“We plan to add Bitcoin as a payment method to Tuta in the future. You can already buy Tuta gift cards with the cryptocurrencies Monero or Bitcoin or with cash via our partner [Proxystore](https://digitalgoods.proxysto.re/).”

“To redeem a gift card from Proxystore, please follow the instructions in Proxystore right after ordering the gift card. You will get a gift card link. When you use the link, you need to choose ‘Use existing account’ or create a new account, depending on where you want to apply the credit to. Once you have added the gift card, you can check the credit on your account under Settings → Payment. When upgrading your account, you can now choose ‘Account balance’ so that no payment details need to be linked to your Tuta account.”

=============================================  
Finally we have “What payment methods does Tuta support?”

“When booking a paid subscription in Tuta, you can pay via Credit Card (Visa, Mastercard, American Express), via PayPal, or via bank transfer. Payment via bank transfer is only available for business customers in the EU. If you would like to pay your personal plan via bank transfer, please contact our sales team.”

No mention of crypto of gift cards.  
It’s like the three sections of their FAQ were written by different people as company policy changed.

---

## Post 57 by @ignoramous — 2026-03-07T18:45:01Z

> [@Valynor](#):
>
> They got presented with a **legally binding order from Swiss authorities** , they followed the law

As a Swiss entity, Proton is subject to EU’s jurisdiction. They keep saying only Swiss law applies, but that’s incorrect as Quad9 found out.

Deeply unserious to simply regurgitate Proton’s marketing claims as some gospel of truth.

> Quad9 has no office or standing in Germany (we are a Swiss entity), but due to the Lugano Convention treaty it was possible for Sony to serve an injunction in Switzerland and drag Quad9 into legal proceedings [in Germany].
> 
> [Quad9 Turns the Sony Case Around in Dresden](https://quad9.net/news/blog/quad9-turns-the-sony-case-around-in-dresden/) (2023).

> [@anon4124882](#):
>
> people don’t understand tech, policy, privacy, and how it works with the law. These are barely armchair experts on the matter yapping about things that don’t follow logic. I don’t mean to be crudely evaluating others but those in the know

The problem is the baseless and oft times misleading marketing on the part of privacy providers themselves. There’s a lot of distrust [among people] because there’s a lot at stake. And when the push comes to shove, businesses will do what they ought to do, protect their business interest at all costs, engage in posture talk, confuse deliberately, rather be honest & direct.

---

## Post 58 by @ignoramous — 2026-03-07T18:56:45Z

> [@CarefulMouse](#):
>
> example, Mullvad [permanently deletes payment data sometimes after only 20 days.](https://mullvad.net/en/help/privacy-policy)

What?! Re-read the link you shared. Only the `transaction_id` is deleted, whatever that means, and that too only from Mullvad’s databases, not from the payment provider’s, who may have it permanently stored for all we know.

Besides, Mullvad is clear that it keeps the rest of the payment information in its own database (regardless of whether the payment provider does or not) for around for 7 years.

> Certain payment data must be kept for the statutory retention period described in applicable local laws such as the Swedish Accounting Act (some information must be stored for seven years from the end of the fiscal year).

---

## Post 59 by @CarefulMouse — 2026-03-07T20:40:29Z

Services must follow the record keeping laws of where they do business, you cannot expect otherwise.

The point I’m making isn’t that there was purchase data retained. The issue is that you cannot de-associate the payment info from the account holder in Proton. There is a difference between “CarefulMouse uses Proton” and “CarefulMouse uses Proton and also their account name is XYZ”

---

## Post 60 by @iHateKYC2 — 2026-03-08T00:07:41Z

swap crypto to monero, send to monero wallet 2, swap monero to btc. easy solution.

Yes, Proton should add Monero and be transparent on all the ways your anonymity could be broken since they advertise themselves as **pro-privacy** more than any other company. They only accept Monero for their “password manager” which just proves they are scared to add it to protonmail for legal reasons.

But it’s still the users responsibility to have good practices regarding their opsec, and being informed on how they could be de-anonymized.

---

## Post 61 by @archetypicalswan — 2026-03-08T02:31:28Z

Switzerland is famously **not** in the EU.

---

## Post 63 by @ignoramous — 2026-03-08T10:29:08Z

> [@archetypicalswan](#):
>
> Switzerland is famously **not**

:man_facepalming:

> The [Lugano Convention] aims to achieve the same level of circulation of judgments between the EU countries and Switzerland, Norway and Iceland.
> 
> …
> 
> The [Lugano Convention] follows the present rules of the EU on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters between EU countries.

> **[Strengthening cooperation with Switzerland, Norway and Iceland: the Lugano...](https://eur-lex.europa.eu/EN/legal-content/summary/strengthening-cooperation-with-switzerland-norway-and-iceland-the-lugano-convention.html)**

---

## Post 64 by @ph00lt0 — 2026-03-08T10:31:52Z

Switzerland is not part of the EU and surely not part of the jurisdiction. You are highly misunderstanding the framework here.

---

## Post 65 by @Lux — 2026-03-08T10:32:14Z

Probably the best thing would be to create a new account and pay with cash or monero. And don’t use any recovery method tied to your identity in anyway. It would be a pain with Proton Pass but you could transfer to another password manager and then back to Proton with a clean account.

---

## Post 66 by @ignoramous — 2026-03-08T10:33:17Z

> [@ph00lt0](#):
>
> Switzerland is not part … of the jurisdiction… highly misunderstanding

Citation, please. Thanks.

---

## Post 67 by @ph00lt0 — 2026-03-08T10:34:00Z

> **[EU countries | European Union](https://european-union.europa.eu/principles-countries-history/eu-countries_en)**
>
> Find out more about EU countries, their government and economy, their role in the EU, use of the euro, membership of the Schengen area or location on the map.

---

## Post 68 by @ignoramous — 2026-03-08T10:35:07Z

Is Switzerland subject to Lugano? [Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester - #63 by ignoramous](https://discuss.privacyguides.net/t/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protester/36007/63)

If so, what does it mean for Swiss based companies like Quad9 who were dragged through court by Sony Germany?

---

## Post 69 by @ph00lt0 — 2026-03-08T10:36:37Z

Not quite the same as being in the jurisdiction…

I guess we mean the same it just isn’t as straightforward as you made it seem.

---

## Post 70 by @ignoramous — 2026-03-08T10:46:28Z

> [@ph00lt0](#):
>
> same as being in the jurisdiction

> [@ignoramous](#):
>
> As a Swiss entity, Proton is **subject to** EU’s jurisdiction

Hopefully, [these (and possibly other) lawyers](https://www.legal500.com/guides/chapter/switzerland-enforcement-judgments/) have not “misunderstood the framework”. If they have, you probably stand a chance to correct them all.

> The Lugano Convention (Convention on Jurisdiction and the Recognition and Enforcement of Judgments in Civil and Commercial Matters concluded in Lugano on 30 September 2007, “LugC”) regulates the Swiss recognition and enforcement of judgements in civil and commercial matters that have been rendered in a LugC member state. In addition to Switzerland, the member states are the European Union (and thus all EU countries) as well as Norway and Iceland. It is therefore the most important treaty for recognition and enforcement of private law civil and commercial decisions in Switzerland …

* * *

Edit:

> [@ph00lt0](#):
>
> mean the same it just isn’t as straightforward as you made it seem

We mean different? And if “it just isn’t as straightforward”, please back it up with citations, because you have created uncertainty and doubt in me.

---

## Post 71 by @ph00lt0 — 2026-03-08T11:08:39Z

Your claim that Proton must directly follow orders from EU judges is incorrect. Proton ignores foreign requests unless validated through MLAT procedures by Swiss authorities. Article 271 of the Swiss Criminal Code prohibits direct cooperation with foreign entities.

I understand it works this way:

Foreign authority → Swiss Federal Police/Justice (MLAT) → Swiss judge approves → Proton provides the data it has.

This can also be read in proton’ transparency report.

> … The only legally binding requests are ones from the Swiss authorities. Under Swiss regulations, we cannot legally comply with foreign requests that are not supported by Swiss authorities (such as the ones addressed directly to us by foreign law enforcement authorities).

> **[Transparency report | Proton](https://proton.me/legal/transparency)**
>
> Proton's transparency report with aggregate statistics of legal orders from the Swiss authorities, covering Proton Mail, Proton Drive, and Proton Calendar.

The complexity of these laws and international relations is one many lawyers earn good money on. It is not that simple.

---

## Post 72 by @ph00lt0 — 2026-03-08T11:26:28Z

Fun fact you can also get such gift cards for proton pass and simplelogin. I would agree it would be nice if it was also available for proton mail, vpn, drive etc.

---

## Post 73 by @ignoramous — 2026-03-08T11:31:19Z

> [@ph00lt0](#):
>
> Your claim that Proton must directly follow orders from EU judges is incorrect

Where did I say that?

Besides, the text of Lugano Convention is directly opposed to what you’re claiming.

I need third-party citations. The Lugano Convention is explicit in its wording and has played out exactly so for Quad9 just 3yrs prior.

> [@ph00lt0](#):
>
> [Proton] cannot legally comply with foreign requests that are not supported by Swiss authorities

That’s Proton’s marketing weasel … Of course, they’re bound to respect requests “supported by Swiss authorities,” who are bound to the EU due to Lugano.

> [@ph00lt0](#):
>
> complexity of these laws … many lawyers earn good money on. It is not that simple

Like I said, you also stand to earn a great deal of money if your understanding of the framework is that it is “highly misunderstood”.

---

## Post 74 by @ph00lt0 — 2026-03-08T11:41:53Z

> [@ignoramous](#):
>
> As a Swiss entity, Proton is subject to EU’s jurisdiction.

This is were you wrote that or perhaps unintentionally implied?

I am not familiar with the Quad9 case. Will get back later on that.

I dont believe this is a marketing claim. There are no known cases of Proton cooperating with foreign entities directly. And as I have cited above that would also bring them in legal trouble.

Dont worry about my salary :smiley: (not a lawyer but I do deal with these kinds of assesements).

---

## Post 75 by @PurpleDime — 2026-03-08T11:46:50Z

> [@shadowwwind](#):
>
> The way I understand Posteo’s approach, it relies on trusting them not to store connection/with PayPal and credit card payments that they actively delete the connection. […] Posteo’s approach only protects against somebody trying to tie payment and account together retroactively.

The fact remains that as a private email provider, they made efforts early on to not connect credit card and PayPal payments to your account, which is smart. Proton didn’t do that. As far as I know, Posteo hasn’t been involved in any data handover controversies, but I intend to ask them about it, as well as the reliability of their private payment system.

> [@shadowwwind](#):
>
> They could get forced to change it without users noticing.

What do you mean by this? That the German government or the EU could compel Posteo to start connecting credit cards to accounts and legally forbid them from disclosing it to their users?

Maybe. That would be extreme. In such a case, I would hope Posteo would be open to their users, and if they can’t because of legal threats, that the information would leak, like what happened with Apple and the UK. The UK tried to force Apple to make their encryption less private and forced them not to say anything about it. The information still leaked, and it made a lot of noise.

> [@shadowwwind](#):
>
> They could get forced to change it without users noticing.

> [@iHateKYC2](#):
>
> swap crypto to monero, send to monero wallet 2, swap monero to btc. easy solution.

I respect your ingenuity, but for most people that is not easy. Using cryptocurrency in general is not easy for the average user, even more so when you’re trying to avoid KYC.

The easiest way for the average user to pay anonymously is to use cash and gift cards. They should be able to use cash to directly credit their account and/or buy a gift card from the service provider or a trusted reseller.

Any service that wants to make anonymous payments easy for their users must support those methods. I absolutely want Proton to support direct payments via Monero one day, but even if they did, it is not the most user-friendly method for the average user. It’s not something my mom could do, and frankly, it’s not easy for me either.

> [@iHateKYC2](#):
>
> They only accept Monero for their “password manager” which just proves they are scared to add it to protonmail for legal reasons.

I think their fear goes beyond Monero, because, [as I’ve demonstrated earlier](https://discuss.privacyguides.net/t/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protester/36007/52), none of their payment options are actually anonymous which to me is very suspicious.

> [@iHateKYC2](#):
>
> But it’s still the users responsibility to have good practices regarding their opsec, and being informed on how they could be de-anonymized.

I don’t deny that the user has some responsibility, but Proton bears some responsibility too.

I don’t know if the analogy fits perfectly, but to me, it’s like someone trying to lose weight and eat healthy in an environment where unhealthy food is marketed as healthy, and food lobbies fight tooth and nail against regulation that would make it easy to tell the difference between healthy and unhealthy food.

Does the person trying to lose weight have some responsibility? Yes. But so does the environment they live in. It’s not surprising that it is far easier for that same person to take better care of their health in a different environment where food and other health-related industries are well regulated and there is clear transparency about what they actually offer.

> [@ph00lt0](#):
>
> Fun fact you can also get such gift cards for proton pass and simplelogin. I would agree it would be nice if it was also available for proton mail, vpn, drive etc.

[Proton git cards cannot be bought anonymously.](https://discuss.privacyguides.net/t/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protester/36007/52) They don’t accept cash or Monero.

---

## Post 76 by @ignoramous — 2026-03-08T11:48:31Z

> [@ph00lt0](#):
>
> not familiar with the Quad9 case. Will get back later on that.

You wrote those responses without referring to Quad9’s writeup on the case? Sounds like you were debating for the sake of it.

> [@ph00lt0](#):
>
> Dont worry about my salary :smiley:

I assure you, I don’t give a …

> [@ph00lt0](#):
>
> dont believe this is a marketing claim

Marketing weasel\*

> [@ph00lt0](#):
>
> also bring them in legal trouble

Proton has indeed been dragged through the courts in Ireland, for example.

> [@ph00lt0](#):
>
> perhaps unintentionally implied

No.

---

## Post 77 by @ph00lt0 — 2026-03-08T12:00:53Z

Right okay i checked out the quad9 story briefly. MLAT was not followed in the Sony Dresden case because it was a private civil lawsuit, not a criminal or law enforcement matter. You really cannot compare private law and criminal law like this. It really misrepresents what is going on.

The quad9 story is troubling but not quite representative here.

For criminal procedures also Quad9 lists the same argument as Proton btw. [Quad9 Turns the Sony Case Around in Dresden | Quad9](https://quad9.net/news/blog/quad9-turns-the-sony-case-around-in-dresden/) and [Compliance and Applicable Law | Quad9](https://quad9.net/privacy/compliance-and-applicable-law/)

---

## Post 78 by @Encounter5729 — 2026-03-08T12:04:28Z

Please don’t use uppercase letters, it looks very spammy.

I am pretty sure all payment providers need to keep a 5-year history of your transactions, etc. So VCC even if deleted will still be kept by the provider. Out of subject though.

---

## Post 79 by @PurpleDime — 2026-03-08T12:24:27Z

> [@Encounter5729](#):
>
> Please don’t use uppercase letters, it looks very spammy.

How does it look spammy? I’m only using them to title sections of my text.

> [@Encounter5729](#):
>
> I am pretty sure all payment providers need to keep a 5-year history of your transactions, etc. So VCC even if deleted will still be kept by the provider. Out of subject though.

I don’t think it’s off-topic, because VCCs are promoted as a way to protect your privacy when making payments, and some Proton users use VCCs. You could be right, but the only way to know for sure it to ask. I intend to ask my provider.

All providers are different. My VCC provider is a bank and all my VCC payments are not reflected as VCC payments in my statements. This means that when I look at a payment I made with a VCC, it shows my real credit card number in the statement. Not my VCC number.

I complained about this to my bank because I have over 10 VCCs, and I would like to be able to tell from my statements to which VCC does each payment correspond to, but I can’t. I now realize that there might be a privacy benefit to this, unless the bank can tell which VCC I used internally. It’s another thing I need to ask them.

Even if you are right, I do wonder if there would be a privacy benefit to opening a bank account that is exclusively used for private purchases, and every year or so, close that bank account, and open a new one for the same purposes at another bank. I wonder if rotating bank accounts every couple of years, would protect your privacy, if you keep closing your previous accounts. I imagine it would be much harder to trace account that doesn’t exist anymore.

---

## Post 80 by @Encounter5729 — 2026-03-08T12:40:30Z

> [@PurpleDime](#):
>
> How does it look spammy? I’m only using them to title sections of my text.

Because no one does this, and it flashes a message among other. Also, if you have many sections, you message might just be to long.

* * *

Again, keeping records 5 years ( I think sometimes more) for banks is the law. Closing an account and doing that every years might ensure only your last 5 years are accessible to LE, but not a shorter time than that.

For the VCC, I guess banks have to retain the card number and name associated. So payments will not be anonymous.

---

## Post 81 by @Blackbird — 2026-03-08T12:53:24Z

Why is everyone upset when you can just buy it from Proxystore?

---

## Post 82 by @PurpleDime — 2026-03-08T12:59:23Z

> [@Encounter5729](#):
>
> Because no one does this

That’s not a good enough reason. I do it because I want my text to be clear and legible.

> [@Encounter5729](#):
>
> Also, if you have many sections, you message might just be to long.

I try to be as succinct as I can, but sometimes I have much to say, and there are limitations to how many comments you can make in a row. I can’t make three short comments, so I make two longer comments.

> [@Encounter5729](#):
>
> Again, keeping records 5 years ( I think sometimes more) for banks is the law.

Where is this law? Because it is likely we are not in the same location. Again, you may very well be right, but there is only one way to know for sure, and it’s to ask you bank and VCC provider. I want to be sure which is why I intend to ask.

> [@Encounter5729](#):
>
> For the VCC, I guess banks have to retain the card number and name associated. So payments will not be anonymous.

My bank, which is my VCC provider allows me to name my VCCs whatever I want. I have tested it. I made a payment to a service with **Bugs Bunny** as my VCC cardholder name.  
I then asked that business to provide me with all the info they had on that payment, and the name they had on record was Bugs Bunny.

Obviously, my bank knows my real name, but it remains unclear if a deleted VCC can be traced back to me. It’s safer to assume that it can, but I intend to ask to be sure.

---

## Post 83 by @ignoramous — 2026-03-08T14:13:39Z

> [@ph00lt0](#):
>
> MLAT was not followed in the Sony Dresden case because it was a private civil lawsuit, not a criminal or law enforcement matter. You really cannot compare private law and criminal law like this

I specifically quoted,

> [@ignoramous](#):
>
> > … regulates the Swiss recognition and enforcement of judgements in civil and commercial matters …

I wonder if you are debating yourself? I’ll leave you two at it.

> [@ph00lt0](#):
>
> Proton ignores foreign requests unless validated through MLAT procedures by Swiss authorities.

* * *

> [@ph00lt0](#):
>
> quad9 story is troubling

Good.

To me, what’s troubling is folks taking Proton’s marketing weasel and passing off as some gospel, yeah.

* * *

> [@ph00lt0](#):
>
> For criminal procedures also Quad9 lists the same argument as Proton btw

These are all first party sources you’re relying on. I’m not a lawyer but, Mutual Legal Assistance, in reality, seems to be ‘bypassed’ for cybercrime investigations ([ref](https://rm.coe.int/16802e726c)), as the _Budapest Convention_ (which Switzerland is a signatory to) takes over.

> Police-to-police cooperation for the sharing of data related to cybercrime and e-evidence is much more frequent than mutual legal assistance (the ratio seems to range from 10:1 to 50:1).
> 
> …
> 
> Data that can be obtained domestically by the police without compulsory measures and  
> thus without court order can be shared (by Australia, Belgium, Cyprus, Finland,  
> France, Japan, Serbia, Switzerland).

---

## Post 84 by @Expert4870 — 2026-03-08T14:21:17Z

You cannot buy proton mail from proxysto.re. I talked to their customer support and they said they asked proton about it but they weren’t communicating or stocking them.

---

## Post 85 by @Encounter5729 — 2026-03-08T14:26:59Z

> [@PurpleDime](#):
>
> Where is this law? Because it is likely we are not in the same location. Again, you may very well be right, but there is only one way to know for sure, and it’s to ask you bank and VCC provider. I want to be sure which is why I intend to ask.

Not going to share for obvious reasons, but this is the case in most places around the world, if not all.

---

## Post 86 by @PurpleDime — 2026-03-08T15:10:17Z

> [@Encounter5729](#):
>
> Not going to share for obvious reasons, but this is the case in most places around the world, if not all.

You may be right. But it should still be verified by asking and getting official confirmation.  
There are many countries that have privacy laws that are supposed to protect you, but when a citizen tries to have those laws enforced to protect their privacy, they realize they are not actually protected.

I want to stop my bank from requiring I share my location every time I want to make a transaction on mobile. I also want to stop them from scanning my face when I want to use said app. I want my privacy respected and intend to report them to my local data protection agency. So far, all indication show me that the data protection agency can’t or won’t compel my bank to stop invading my privacy, which just goes to show that the data protections laws they brag about are privacy and security theater.

---

## Post 87 by @zoooom — 2026-03-08T15:42:52Z

In my opinion, Proton is just a much better version of Google Suite, and it should not be seen as the “ultimate savior of privacy.” For what they do and offer, they are a good option, but other options also exist. Lastly they offer “Private Mail,” not “Anonymous Mail.”

---

## Post 88 by @PurpleDime — 2026-03-08T16:40:45Z

> [@zoooom](#):
>
> it should not be seen as the “ultimate savior of privacy.”

I agree. But I think it’s fair to say that Proton Mail wants to be the best private email service, and markets itself that way. Hence, they bear some responsibility for what people believe about their company and services.

> [@zoooom](#):
>
> For what they do and offer, they are a good option, but other options also exist. Lastly they offer “Private Mail,” not “Anonymous Mail.”

No one is saying Proton’s service is bad. Some of us are saying that they are not completely transparent about the type of data they retain and can be shared about you, and that they can do so much better to protect their users’ privacy, which is true.

> [@zoooom](#):
>
> Lastly they offer “Private Mail,” not “Anonymous Mail.”

[Proton claims to offer anonymous payments which is not true.](https://discuss.privacyguides.net/t/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protester/36007/52) They need to fix that. If their competition is able to offer anonymous payments and do it right, so should they.

---

## Post 89 by @Valynor — 2026-03-08T17:04:08Z

> [@PurpleDime](#):
>
> [_**B) Proton Cash Payments are not anonymous**_](https://proton.me/support/payment-options#cash)
> 
> **Proton cash payments require that you declare your Proton username, which compromises your privacy.**

How does sending some bills + your account name in an envelope with no return address compromise your privacy?

---

## Post 90 by @PurpleDime — 2026-03-08T17:36:30Z

> [@Valynor](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/purpledime/48/4885_2.png) PurpleDime:
> 
> > [_**B) Proton Cash Payments are not anonymous**_](https://proton.me/support/payment-options#cash)
> > 
> > **Proton cash payments require that you declare your Proton username, which compromises your privacy.**
> 
> How does sending some bills + your account name in an envelope with no return address compromise your privacy?

[I’ve discussed this before.](https://discuss.privacyguides.net/t/proton-pass-and-simplelogin-are-separate-services/30706/26)

> [@Proton Pass and SimpleLogin are separate services](https://discuss.privacyguides.net/t/proton-pass-and-simplelogin-are-separate-services/30706/26):
>
> _For many Proton Mail users, if not the overwhelming majority, your Proton username is linked to your real identity. It’s probably your real name. Even if you used any of your secondary pseudonymous Proton Mail addresses, they are still linked with the one with your real name, which reveals your identity._

This means that if my Proton username is: _**[jordan.smith@pm.me](mailto:jordan.smith@pm.me)**_, I am revealing my identity to Proton. Moreover, if I use any of my pseudonymous addresses that are linked to the same acccount (_**[fresh.cow@pm.me](mailto:fresh.cow@pm.me)**_), I am still revealing my identity to Proton because hey can see it is owned by **Jordan Smith**. That is not anonymous.

As I have explained, other privacy services do not require you declare your username for cash payments, so why can’t Proton follow that model? Why the need for them to manually link my cash payment to my account? Why the need for a real person to manually add the payment to my account? Why does a human person need to see my Proton profile? I don’t want that.

**There is value in hiding in plain sight, in a sea of millions of people, undistinguished.**

If I desposit cash in my bank account via an ATM, no person who works at the bank knows that I made a payment that day. The bank’s system knows, but no actual human being knows that Jordan Smith deposited $100 into their account. Especially when millions of people make ATM deposits eveyr day.

That is very different from me physically going to the bank, speaking to a teller, and telling them I want to desposite $100 in my account. At that point, the bank teller, who is a real person, is aware that I, Jordan Smith, made a payment that day.

And when the teller performs this transaction for me, they can see my bank profile. Maybe they see that I received $20 000 from abroad and want to ask me about it. Maybe they see that they haven’t verified my address in 5 years and want to confirm it’s still the same. Maybe they see that I have $100 000 sitting in my savings account and am not making much profit from it, and they want to advise me on how to invest it. I don’t care. That is not why I came to the bank and I don’t want them snooping around.

Can you see the difference between the two? It’s the same with Proton.

> [@Proton Pass and SimpleLogin are separate services](https://discuss.privacyguides.net/t/proton-pass-and-simplelogin-are-separate-services/30706/26):
>
> _Moreover, you can’t make a Proton cash payment for a third party (friend, family, stranger) without them sharing their username with you and compromising their privacy._

In addition, when Proton receives you mail they will know which country it came from. That is something you cannot hide. They can link that information with your username, which gives you even less privacy. Proton cash payments also require that you write the company’s name on the envelope. Given how widely known Proton is, that could one day trigger red flags at the post office.

---

## Post 91 by @phnx — 2026-03-08T18:42:31Z

> [@PurpleDime](#):
>
> This means that if my Proton username is: _**[jordan.smith@pm.me](mailto:jordan.smith@pm.me)**_, I am revealing my identity to Proton. Moreover, if I use any of my pseudonymous addresses that are linked to the same acccount (_**[fresh.cow@pm.me](mailto:fresh.cow@pm.me)**_), I am still revealing my identity to Proton because hey can see it is owned by **Jordan Smith**. That is not anonymous.

You do realise this has absolutely nothing to do with whether your payment is anonymous. Proton rather obviously needs to know which account the payment is going to, and if you go so far as to send an envelope with cash while using your SSN as your username, that’s frankly on you.

---

## Post 92 by @Valynor — 2026-03-08T18:44:02Z

> [@PurpleDime](#):
>
> if my Proton username is: _**[jordan.smith@pm.me](mailto:jordan.smith@pm.me)**_, I am revealing my identity to Proton.

You are revealing that information to PM the moment you are creating the account.  
If you want to go for max anonymity you surely wouldn’t use your actual name for this.

> [@PurpleDime](#):
>
> As I have explained, other privacy services do not require you declare your username for cash payments, so why can’t Proton follow that model?

In the end PM has to know that _this_ money goes into _that_ account. Even if they gave you a random number instead that still needs to be associated with your account and could be found out if they really wanted to.

> [@PurpleDime](#):
>
> when Proton receives you mail they will know which country it came from

True, but not really much of an identifier. This could be worked around obviously with some effort, e.g. I live close to a border and could easily send the letter from a different country in literally less than 15 minutes. Commercial remailing services do exist, too.

---

## Post 93 by @privacy.slouchy — 2026-03-08T19:17:42Z

You cite the Proxy Store & SL gift cards in the other post as an anonymous, preferrable alternative, though I believe this only obfuscates the _source_ of the funds, and does nothing to mask the beneficiary account:

> Anonymous payment (cash/monero) → proxy store gift card → SL account

Vs

> Anonymous payment (cash) → Proton account

So, the Proxy Store setup is no more anonymous than Proton’s cash payments, right? Both scenarios support an anonymous source of funds, and both demand a coupling to your account for the final transaction. Anonymity is broken if either account is associated with PII

Barring the introduction of blind signatures, Id believe all transactions will need to be coupled with a username or account UID. Users seeking anonymity will need to make sure this account is not associated with PII

---

## Post 94 by @Gopher — 2026-03-08T21:48:14Z

I found this Twitter post to be a well rounded critique of Proton Mail: [https://x.com/DoingFedTime/status/2030108076531995016](https://x.com/DoingFedTime/status/2030108076531995016)

A big problem that it highlights isn’t necessarily Proton’s technology or the company’s ethics itself. With Swiss laws now making it easier to send legal notices en masse Proton is unable to keep up and is forced to comply with a larger and larger amount.

This coupled with Proton’s marketing being somewhat misleading for a layman. When you make big sweeping claims of security and privacy without fully educating the user about the risks of certain ease of use features (e.g. credit card payments, password recovery, etc…), you’re putting less tech savvy users at risk of misunderstanding Proton’s strengths and limitations.

I think this particular case is pretty egregious with the background and dirty tricks being employed by the government in this Cop City stuff, Proton failing to take a big enough stand on this is a pretty embarrassing failure on their part imo.

I still feel safe using Proton for my day to day. I’m using it as my personal email rather than a pseudononymous identity, so the concerns raised by the Cop City incident don’t apply to me. However conceding to the FBI over the Cop City stuff in particular does leave a bad taste in my mouth around my own personal ethics, so I’ll probably move to a new provider when my subscription runs out.

---

## Post 95 by @TinFoilHat — 2026-03-08T22:05:49Z

> [@Gopher](#):
>
> When you make big sweeping claims of security and privacy without fully educating the user about the risks of certain ease of use features (e.g. credit card payments, password recovery, etc…), you’re putting less tech savvy users at risk of misunderstanding Proton’s strengths and limitations.

TBH I don’t think it is feasible for companies to “fully educate“ users on this aspect, because they will be basically slamming people with

1. Technical documentations on their infrastructure
2. Technical documentations of payment processors and banks / card issuers
3. Plenty of case laws (to cover different scenarios and justifications)
4. Their Terms and Conditions
5. Their Privacy notice
6. Even more not so basic basic education such as definitions of privacy, security and anonymity, threat modelling and risk assessment.

And they cannot simply say your data is safe with us, as long as you are not trying to do something illegal as we might be forced to hand out certain information to LE. Because 99% of the public won’t understand and the companies are simply asking for troubles (and / or losses)

---

## Post 96 by @Gopher — 2026-03-08T22:16:49Z

Yeah I agree there isn’t an easy way around without it just becoming another set of T&Cs that nobody will ever read. But potentially putting warnings/disclaimers on certain features like account recovery and payment services could be helpful.

---

## Post 97 by @anon4374141 — 2026-03-08T22:38:32Z

I don’t see the problem as significant as you’re making it out to be. If a client has sufficient knowledge and poses a high threat level, they will know perfectly well what information to provide and what not to. On the other hand, if the client is an ordinary everyday user looking for privacy rather than anonymity, they will pay by card and, in principle, authorities will not be able to access the contents of their email and so on. Another story is if they set up a Gmail recovery email or something like that, in which case it depends more on the user’s own knowledge. I don’t think a warning needs to be added for everything

---

## Post 98 by @anon77345381 — 2026-03-08T23:55:42Z

To say Proton “helped” is an injustice. If someone says Proton Mail “helped” FBI, it paints a mental imagery of Proton staff willingly going out of their way to try and uncover this person. That is not what happened. The wording in this headline is so unjust it seems borderline malicious.

---

## Post 99 by @Julie — 2026-03-09T01:09:46Z

Does this mean if the user had a free account, FBI would have failed ?

PS: Are you sure that they did not provide IP adress ?

---

## Post 100 by @PurpleDime — 2026-03-09T08:01:49Z

> [@phnx](#):
>
> You do realise this has absolutely nothing to do with whether your payment is anonymous.

It absolutely does.

> [@phnx](#):
>
> Proton rather obviously needs to know which account the payment is going to […]

Proton employees (humans) don’t need to know which account the payment is going to.

**How do you explain that neither cash payments for Posteo nor many other privacy services work that way?**

> [@phnx](#):
>
> […]if you go so far as to send an envelope with cash while using your SSN as your username, that’s frankly on you.

> [@Valynor](#):
>
> If you want to go for max anonymity you surely wouldn’t use your actual name for this.

Millions of people use their real name as their Proton username, including investigative journalists. And as I have already mentioned, even if I have a random username (_[fresh.cow@pm.me](mailto:fresh.cow@pm.me)_), if it is linked to the one that has my real name, my privacy is not protected by using it.

> [@Valynor](#):
>
> You are revealing that information to PM the moment you are creating the account.

It is not the same. I’ll explain why in a second.

> [@Valynor](#):
>
> In the end PM has to know that _this_ money goes into _that_ account.

Yes and no.

There is something you and @phnx fail to understand.

There is a difference between Proton, the company, which comprises the computational system that registers purchases, versus Proton’s employees, who are real people and can look into people’s profiles.

I don’t have a problem with my cash payments being registered by Proton’s computers when I credit my account. I have a problem with my cash payments being registered by Proton agents.

Let’s go back to the bank deposit analogy.

When I deposit $100 in my bank account via ATM, the bank’s computer system knows that a deposit was made into my account. But no bank employee knows. No bank employee’s attention has been drawn to my account. I am in an ocean of millions of bank customers, hiding in plain sight.

This is how cash payments work for many other privacy services.

On the flip side, when I physically go to the bank to deposit $100 into my account, I have to speak to a teller, and hence I am drawing a bank employee’s attention to my account. In fact, I have to present my ID to prove I am the owner of said account.

**Can you see how my privacy is being compromised?**

This is how Proton cash payments work, and I don’t want that.

> [@Valynor](#):
>
> Even if they gave you a random number instead that still needs to be associated with your account and could be found out if they really wanted to.

No, it doesn’t.

When I make a cash payment to purchase a Tuta gift card, I can credit it to any Tuta account.

I can send the cash payment with the intention to credit my account, but after the payment is sent, change my mind and credit my sister’s account instead.

Proton cash payments could work the same way, especially if they allowed their gift cards to be bought with cash, but even if they didn’t, it’s possible. It’s 100% possible, as it already exists with various privacy services like Posteo.

One thing you forget about the bank deposit analogy is that ATM cash deposits can be anonymous. I can deposit cash into anyone’s account, including my own, without the bank knowing who deposited the money.

The same should be possible with Proton.

> [@Valynor](#):
>
> True, but not really much of an identifier. This could be worked around obviously with some effort,

Yes, it can be worked around from most countries. But it would be better if we didn’t have to write Proton’s name as the recipient.

---

## Post 101 by @predict9320 — 2026-03-11T13:03:23Z

As I am relatively new to this topic, there seems to be one aspect I do not understand.

Follow-up question:

If I want to purchase a gift card for SimpleLogin or Proton Pass, for example, I can do so via Proxy Store, where I can pay with cash. My identity is not disclosed at any point.

If I now want to subscribe to Proton Mail with cash, I can send cash in an envelope to the required address with a note stating the account name.

It is relatively irrelevant whether a machine reads the cash payment, which is not possible, or whether an employee does so. The only information that the employee and Proton have is that someone has “topped up” this account with cash. This is not a risk, even in high-risk use.

What is the problen which I don’t understand?

---

## Post 102 by @Encounter5729 — 2026-03-11T16:26:34Z

> [@predict9320](#):
>
> It is relatively irrelevant whether a machine reads the cash payment, which is not possible, or whether an employee does so. The only information that the employee and Proton have is that someone has “topped up” this account with cash. This is not a risk, even in high-risk use.
> 
> What is the problen which I don’t understand?

You are assuming secret of corespondence (ie the state not reading your letters) is upheld. Third-party intercepting the letters is probably the biggest risk. It can be a proof if you did bad OPSEC (ie, fingerprint and/or banknotes you took from an ATM\*)

\*it is possible that some ATMs register the notes with your bank card number or something.

---

## Post 103 by @predict9320 — 2026-03-11T16:53:23Z

Okay, so would it be possible to do this just by using fingerprints or traceable banknotes? These are two aspects that can be prevented, albeit at great expense and easy to overlook.

If these two aspects do not apply, would it be impossible to do anything with the information contained in an intercepted and opened letter?

---

## Post 104 by @jonah — 2026-03-11T18:24:52Z

> [@Encounter5729](#):
>
> some ATMs register the notes

It’s a bit embarrassing I’ve never really considered this before (probably because I don’t use ATMs lol) but yeah it seems so obvious.

> The company Wincor Nixdorf, today: Diebold Nixdorf (DN), has already presented a [cash box for ATMs](https://www.atmmarketplace.com/articles/it-all-comes-back-to-the-cash-cassette-that-is/) in 2010, which records serial numbers [of](https://www.atmmarketplace.com/articles/it-all-comes-back-to-the-cash-cassette-that-is/) the bills in it. The cassette also logs when and where the bills are accessed, and sends the data to a server. DN writes on request: “Any implementation, storage and reuse of the banknote serial numbers is at the discretion of the respective financial institution and must comply with local legal provisions.” _[Translated quote]_

> **[Reise eines Zwannis: Diese Geräte tracken deine Geldscheine](https://netzpolitik.org/2025/reise-eines-zwannis-diese-geraete-tracken-deine-geldscheine/)**
>
> Immer wieder lesen Maschinen die Seriennummern unserer Banknoten aus. Für diese Recherche begleiten wir einen Zwanzig-Euro-Schein durch den Bargeldkreislauf und sehen, wie das Tracking zunehmend anonyme Zahlungen gefährdet.

---

## Post 105 by @ph00lt0 — 2026-03-11T18:33:31Z

I think maybe this should be it’s own thread but yeah it is even public data here:

[https://en.eurobilltracker.com/](https://en.eurobilltracker.com/)

---

## Post 106 by @Valynor — 2026-03-11T18:38:20Z

There’s also fingerprints (as mentioned above) and DNA traces, identification via your handwriting or even the type of pen&paper or envelope you bought (could be something special that’s only sold in a couple places etc.).

And paranoia :wink: as the authorities won’t pull the full forensic analysis on just everyone.

---

## Post 107 by @jonah — 2026-03-11T18:51:12Z

> [@ph00lt0](#):
>
> it is even public data here

I think this is quite different from automatic data collection, but funny nonetheless.

---

## Post 108 by @PurpleDime — 2026-03-11T21:40:29Z

> [@predict9320](#):
>
> If I now want to subscribe to Proton Mail with cash, I can send cash in an envelope to the required address with a note stating the account name.
> 
> It is relatively irrelevant whether a machine reads the cash payment, which is not possible, or whether an employee does so.

**Did you read my comments when I used the bank deposit analogy?**

> [@PurpleDime](#):
>
> _When I deposit $100 in my bank account via ATM, the bank’s computer system knows that a deposit was made into my account. But no bank employee knows. No bank employee’s attention has been drawn to my account. I am in an ocean of millions of bank customers, hiding in plain sight._

> [@PurpleDime](#):
>
> _That is very different from me physically going to the bank, speaking to a teller, and telling them I want to desposit $100 in my account. At that point, the bank teller, who is a real person, is aware that I, Jordan Smith, made a payment that day._
> 
> _And when the teller performs this transaction for me, they can see my bank profile. Maybe they see that I received $20 000 from abroad and want to ask me about it. Maybe they see that they haven’t verified my address in 5 years and want to confirm it’s still the same. Maybe they see that I have $100 000 sitting in my savings account and am not making much profit from it, and they want to advise me on how to invest it. I don’t care. That is not why I came to the bank and I don’t want them snooping around._

Something tells me that you have never experienced a customer service agent commenting or asking you about things that have nothing to do with the reason you contacted them. Or worse, you’ve never experienced a customer service agent making a change to your account without your consent because they noticed something “odd”. Or maybe you have, and it doesn’t bother you. This has happened to me multiple times with online services, including Proton, and with physical businesses too. The most recent was a month ago, and it was with an online service. I was not happy.

[This is why one of my personal golden rules of privacy is to always contact customer service anonymously.](https://discuss.privacyguides.net/t/what-are-your-not-so-mainstream-privacy-hacks/30536/30) That means that unless it is absolutely necessary to identify myself, I never contact customer support with the email address that is linked to my account with them. I don’t want them to know my account info if they don’t need to answer my question.

---

## Post 109 by @PurpleDime — 2026-03-11T22:09:47Z

> [@PurpleDime](#):
>
> _There’s a bonus reason I won’t mention because I have been preparing a post about it since last year, and I’d rather share it when I have all the info I need. But I suspect someone will hit my bingo card._

> [@predict9320](#):
>
> If I want to purchase a gift card for SimpleLogin or Proton Pass, for example, I can do so via Proxy Store, where I can pay with cash. My identity is not disclosed at any point.

> [@Blackbird](#):
>
> Why is everyone upset when you can just buy it from Proxystore?

> [@iHateKYC2](#):
>
> They only accept Monero for their “password manager” which just proves they are scared to add it to protonmail for legal reasons.

> [@Expert4870](#):
>
> You cannot buy proton mail from [proxysto.re](http://proxysto.re). I talked to their customer support and they said they asked proton about it but they weren’t communicating or stocking them.

**BINGO!** :bullseye:

**D) PROTON’S ANONYMOUS PAYMENT OPTIONS VIA RESELLERS ARE EXTREMELY LIMITED.**

Tuta. Addy. SMS Pool. SimpleLogin. They all allow their gift cards to be purchased anonymously via resellers like the Proxy Store, which accepts cash and Monero.

Not Proton.

The Proxy Store is a popular digital store in the privacy community that is supported by many privacy companies.

_**a) Proton doesn’t sell their gift cards in the Proxy Store.**_

Proton sells subscription vouchers that can only be used to buy a _subscription_ and nothing else. You cannot credit your account with them like you would with Tuta, Addy, SMSPool, or even SimpleLogin. This is a huge limitation

_**b) Proton’s Proxy Store vouchers are exclusive to new users.**_

An existing Proton subscriber cannot use them to renew their subscription. If they want to use them, they have to cancel their current subscription, which means losing any discount if you’re on a lifetime discount.

Even if you are a new user and you purchase a subscription anonymously via the Proxy Store, you cannot renew it via the Proxy Store. You will always have to cancel your current subscription or wait for it to expire in order to purchase another one the same way. That is not practical at all.

Any existing Proton subscriber should be able to renew their current subscription anonymously and automatically. And any new subscriber should be able to do the same.

_**c) Proton vouchers in the Proxy Store are not widely available**_

Some services that Proton supported (Proton Mail) are not supported anymore, and it seems that Proton is deliberately withholding those vouchers from the Proxy Store. I know this because I spoke directly to both Proton and the Proxy store about it.

Via their competition, Proton has plenty of great examples of services that support anonymous payments directly and via resellers. And yet, Proton refuses to follow that model. They refuse to follow the model of SimpleLogin, their own company. None of their direct payments are anonymous, and their indirect payment methods are deliberately limited so that only first time users can benefit from them, and only for the first year.

**PROTON DOESN’T WANT TO SUPPORT ANONYMOUS PAYMENTS**

**It’s the only conclusion one can come to when you look at their deliberately poor implementation. They need to do better because they are outshined by their competition in this department.**

**If Proton truly supported anonymous payments, they would allow direct cash payments for _gift cards_ and also sell those gift cards via privacy friendly resellers like the Proxy Store. They don’t. In addition, they would not require you declare your username for cash payments.**

**If Proton truly supported anonymous payments and were completely transparent about their data retention policy, many of their public controversies would have been avoided.**

---

## Post 110 by @Julie — 2026-03-12T00:02:11Z

You own text cited, indicate that the Lugano convention is for civil and commercial matters.

The curent case was a criminal one, so it would not apply.

PS: Unless an update is available, ProtonMail is force to keep some data on users:

> **[Swiss Court Says ProtonMail Isn't A Telecom, Isn't Obligated To Retain Data...](https://www.techdirt.com/2021/10/29/swiss-court-says-protonmail-isnt-telecom-isnt-obligated-to-retain-data-users/)**
>
> ProtonMail offers encrypted email, something that suggests it’s more privacy conscious than others operating in the same arena. But, being located in Switzerland, it’s subject to that c…

I guess this explain why they did comply with law enforecement Orders 8,313 times in 2025 !

---

## Post 111 by @Julie — 2026-03-12T00:21:54Z

ProtonMail also gave backup email and IP adress in the past.

For the payment method, sorry I don’t know.

---

## Post 112 by @ignoramous — 2026-03-12T00:27:02Z

> [@Julie](#):
>
> The curent case was a criminal one, so it would not apply.

Sure. For criminal cases, the Budapest Convention applies, the latest (more privacy invasive) iteration of which was put out for signatories to join pretty recently. Regardless, whatever marketing claims Proton and Quad9 are making fall flat.

> [@Julie](#):
>
> You own text cited, indicate that the Lugano convention is for civil and commercial matters.

I know? I cited Lugano to make it clear that Proton’s marketing that Swiss laws (as far as LEA is concerned) are some kind of a shield is a farcical claim at best.

---

## Post 113 by @predict9320 — 2026-03-12T10:22:05Z

> PurpleDime:
> 
> Did you read my comments when I used the bank deposit analogy?

I don’t understand the problem with a Proton employee knowing that this account has been subscribed to and is using Premium. This information is completely useless and is almost certainly accessible to employees at any time. But whatever.

Please take a look at my other thread, ‘[Help with my email setup](https://discuss.privacyguides.net/t/help-with-my-email-setup/36150/23)’. I may soon be facing a high-risk scenario (political) and therefore need completely anonymous email access.

The plan was originally to pay Addy anonymously with Proxy Store and use free Proton, but this could be a thread. So I could just create, lets say five free Proton accounts and use them anonymously.

But maybe you can look there into my generel email setup, because you seem more knowledgeable than me.

---

## Post 114 by @PurpleDime — 2026-03-12T12:40:08Z

> [@predict9320](#):
>
> I don’t understand the problem with a Proton employee knowing that this account has been subscribed to and is using Premium.

The issue is not just that a Proton employee will see that you have a premium account. It’s that the Proton employee will see and know so much more about you because they can see your whole profile.

_ **ID at Liquor Store Analogy** _

Imagine you go to a liquor store, and they ask you to present your ID to prove that you’re over 18. When you present your ID, the cashier doesn’t just see that you’re over 18. They see your date of birth; hence, they know that you’re 25, not 50. They also see your gender, your full legal name, your address, your height, etc…

It’s the same with Proton. They don’t just see that Jordan Smith has a premium account. They know your name is Jordan Smith. Likewise, they know how many Proton addresses you have and what they are. They know that the last time you subscribed, it was with a credit card from Germany, but this time they noticed your cash payment came from Japan. There is a difference between a Proton’s computer system knowing that vs. a Proton employee.

_ **1Password example** _

Last year, I received an email from 1Password, telling me that they were going to start charging taxes to customers from certain countries, including the one they assume I am from based on my credit card info. That means I was going to pay more for the same subscription, which I didn’t like.

I also didn’t like that 1Password assumed I was in Germany just because my credit card is German. I could be living in India for all they know. So before the tax could be applied to me, I went into 1Password’s settings and manually changed my country of residence to one where I wouldn’t be taxed.

Suppose that within a month after doing that, I contact 1Password support for a completely different issue, a bug I am noticing in their app. As the customer agent is helping me, they notice that I changed my country of residence to India when it was Germany for 10 years. They could ask me:

_Hey, we noticed that you changed your country of residence to India. Do you actually live there?_

I did not contact them to answer questions about my country of residence. I contacted them to report a bug I noticed in the app.

**Do you see how this is invasive?**

_ **Proton example** _

A Proton agent could notice upon applying your cash payment that there are multiple websites for which you have 3 aliases (e.g., 3 Instagram accounts), [which is not allowed and against their ToS](https://discuss.privacyguides.net/t/anonaddy-vs-simplelogin/13162/34). You did not know that (most people don’t), and the Proton agent decides to reprimand you for it with or without warning.

All you did was send cash to renew your subscription, and instead of just applying the payment, a Proton agent took it upon themselves to look at your profile and make changes to it that you did not ask for.

**Can you see how your privacy was compromised?**

> [@predict9320](#):
>
> Please take a look at my other thread, ‘[Help with my email setup](https://discuss.privacyguides.net/t/help-with-my-email-setup/36150/23)’. I may soon be facing a high-risk scenario (political) and therefore need completely anonymous email access.

Took a look at it and [replied](https://discuss.privacyguides.net/t/help-with-my-email-setup/36150/25).

---

## Post 115 by @carbonated — 2026-03-12T13:50:45Z

> [@PurpleDime](#):
>
> Some services that Proton supported (Proton Mail) are not supported anymore, and it seems that Proton is deliberately withholding those vouchers from the Proxy Store. I know this because I spoke directly to both Proton and the Proxy store about it.

Thanks a lot for mentioning and checking this. I was desperately looking for an option or explanation of this and agree with your conclusion, that this seems very on purpose.

And to add to this, posteo has some mechanism that makes linking of payment and account impossible:

> Out of principle, we do not connect data that we receive during payment with email accounts. For this purpose, we developed our own Posteo payment system in 2009 with which we carry out all payment processes in a privacy-friendly way. In 2015, we expanded it once again so that all payments could continue to be processed without any connection to email accounts despite new legal requirements.

Explained here: [Email green, secure, simple and ad-free - posteo.de - Payment](https://posteo.de/en/site/payment)

---

## Post 116 by @Encounter5729 — 2026-03-12T15:17:25Z

> [@predict9320](#):
>
> These are two aspects that can be prevented, albeit at great expense and easy to overlook.

Banknotes is relatively easy. Just pay with cash, and use the change (also avoid shops who use automatic machines for handling cash obviously).

Fingerprint seems way harder, but also less likely to be an issue. They would bother only if you are a very high-value target, while noting the banknote number is relatively easy.

* * *

@PurpleDime I am pretty sure Proton employees don’t have access to the list of all your alliases. I would imagine they scope this access to a specific team working there.

---

## Post 117 by @PurpleDime — 2026-03-12T16:53:07Z

> [@Encounter5729](#):
>
> @PurpleDime I am pretty sure Proton employees don’t have access to the list of all your alliases. I would imagine they scope this access to a specific team working there.

That was just one example I gave of the type of info that the average Proton support employee can likely see. The point I was trying to make is that they have the ability to see beyond what you want them to see. Hence, why it’s better if you can avoid them seeing anything at all by dropping the requirement of usernames for cash payments.

That being said, you are correct. I can confirm from first-hand experience, that only certain teams of Proton employees can see your aliases, but there is no way for you to know which team the Proton agent who is registering your cash payment belongs to. I can also tell you that I have had my privacy and consent violated by general and senior Proton team members, and they apologized for it.

---

## Post 118 by @Encounter5729 — 2026-03-14T14:57:19Z

Look, please be specific. Look like a lot of accusations, but not much proofs or evidence.

---

## Post 119 by @PurpleDime — 2026-03-14T15:32:23Z

> [@Encounter5729](#):
>
> Look, please be specific.

There are plenty of indisputable examples of how Proton agents can see many details about your profile that you did not explicitly discuss with them. Much of the metadata about your account is visible to them. This is common knowledge and should not be news to you. As an example, if you have multiple Proton addresses under the same account, Proton agents can see all those addresses.

Suppose your default Proton address is _**[jordan.smith@pm.me](mailto:jordan.smith@pm.me),**_ but you have multiple addresses under the same account, including _**[fresh.cow@pm.me](mailto:fresh.cow@pm.me)**_, which serves as your anonymous address. You decide to email Proton support for an issue you’re having, and you deliberately do it from your anonymous Proton address. Guess what? Proton support will reply to your personal address, _**[jordan.smith@pm.me](mailto:jordan.smith@pm.me)**_ because it is your default Proton address.

Imagine emailing Proton as _ **Fresh Cow** _, and they reply with _ **Hi Jordan!** _

This is unacceptable IMO. Proton should reply to the address you emailed them from. That has happened to me in the past, and is definitive proof that Proton agents can see details about your profile, even if you never discuss those details with them.

And to be clear, I was never under the illusion that if I emailed Proton from my anonymous Proton address, they would not see my personal address with my real name.

All this doesn’t alter the fact that Proton agents have access to your profile, and can see things you may not want them to see. And it’s not like Proton denies it. If you have Proton Unlimited or Proton Mail Plus and you email support with one address, ask them if they can see your other addresses, and they will tell you the truth.

> [@Encounter5729](#):
>
> Look like a lot of accusations, but not much proofs or evidence.

If you are referring to my mentioning that Proton violated my privacy and consent, it is not an accusation. It is a fact. I will tell that story in due time, once the matter is resolved. It is an important lesson people need to understand about privacy.

---

## Post 120 by @Encounter5729 — 2026-03-14T17:25:38Z

> [@PurpleDime](#):
>
> Suppose your default Proton address is _**[jordan.smith@pm.me](mailto:jordan.smith@pm.me),**_ but you have multiple addresses under the same account, including _**[fresh.cow@pm.me](mailto:fresh.cow@pm.me)**_, which serves as your anonymous address.

Are you reffering to this feature ?

 ![91bf6cfb-8b99-46db-a56c-1b148c9b09b6](https://forum-uploads.privacyguidesusercontent.com/original/3X/9/5/952d33cd7d077a3e85636fc08e3b23226c64f909.png)

---

## Post 121 by @PurpleDime — 2026-03-14T21:28:10Z

Yes.

---

## Post 122 by @Encounter5729 — 2026-03-14T22:43:10Z

How does it work with those adresses?

---

## Post 123 by @PurpleDime — 2026-03-14T22:48:38Z

How does what work?

The point I’m making is that Proton agents can see all the addresses you create under the same account. It’s common knowledge.

---

## Post 125 by @Shampoo — 2026-03-14T23:03:11Z

> [@PurpleDime](#):
>
> That has happened to me in the past, and is definitive proof that Proton agents can see details about your profile, even if you never discuss those details with them.

Please provide some form of proof of this. I have a hard time believing they’d take the time to find your alternate email and draft a response to it instead of letting whatever support system they use (zendesk?) take care of responses.

---

## Post 126 by @PurpleDime — 2026-03-14T23:55:44Z

> [@Shampoo](#):
>
> Do you have any proof of this? “It’s common knowledge” is not evidence.

The fact that you’re asking me this suggests that you didn’t know this and were under the assumption that Proton agents cannot see all the addresses that are linked to your account. I have to be honest, this astonishes me.

It’s like going to the bank to make a deposit into your checking account, and assuming that the bank teller cannot see from your profile all the other accounts you have with them. That they cannot see that you have a savings account, an investment account, and two credit card accounts. In my opinion, it’s very naive to make such an assumption.

> [@Shampoo](#):
>
> Please provide some form of proof of this. I have a hard time believing they’d take the time to find your alternate email and draft a response to it instead of letting whatever support system they use (zendesk?) take care of responses.

The specific anecdote I shared happened to me years ago. I don’t believe I still have the emails. And even if I did, the only way to prove it to you would be to share screenshots by revealing my Proton addresses, which I do not wish to do for privacy reasons. It’s also possible that Proton has since corrected this issue so that they always reply to the address that emailed them, even if it’s not the default.

The story I shared is not the point. It is just an illustration of my point.

If you do not believe Proton agents can see all the email addresses under your account, contact Proton Mail support and ask them. They will confirm it.

**Every time a Proton agents shares with you information about your account that you did not explicitly disclose to them in your request for support, they are confirming to you that they have access to significant metadata about your profile.**

---

## Post 127 by @Shampoo — 2026-03-15T00:43:34Z

> [@PurpleDime](#):
>
> It’s like going to the bank to make a deposit into your checking account, and assuming that the bank teller cannot see from your profile all the other accounts you have with them. That they cannot see that you have a savings account, an investment account, and two credit card accounts. In my opinion, it’s very naive to make such an assumption.

I think you’re confused as to what the issue is. You’re claiming that first level proton support agents have access to your entire account hierarchy. That is a completely different issue from higher level support at proton being able to see deeper levels of info about your account.

---

## Post 128 by @PurpleDime — 2026-03-15T02:51:30Z

> [@Shampoo](#):
>
> I think you’re confused as to what the issue is. You’re claiming that first level proton support agents have access to your entire account hierarchy. That is a completely different issue from higher level support at proton being able to see deeper levels of info about your account.

Does it really matter if it’s first level support, a different team, or senior level support?

This post is about a Proton user who was outed and identified via their payment information. My argument is that Proton cash payments should not require we disclose our usernames, or that a Proton agent manually add our payment for us. There are plenty of examples of privacy services that accepts cash payments and don’t have these requirements. SimpleLogin is one of them.

I do not wish to draw attention to certain things about my account when I interact with a Proton support agent. Especially when it is avoidable. And sharing my username when making a payment that is supposed to be anonymous is easily avoidable. It is also not necessary for a Proton agent to manually add cash payments for us.

Clearly, you have doubts about what first line Proton support agent can see about your account, and that is fair. You are entitled to those doubts. This is why I invite you to ask Proton yourself. The idea that a first line Proton agent cannot see anything about your account other than what you have explicitly shared with them in your email, is preposterous to me.

Also, I am confident that first line Proton agents have access to past tickets, and if you have interacted with senior support agents before, they likely can see what was shared.

---

## Post 129 by @Encounter5729 — 2026-03-15T17:29:47Z

> [@PurpleDime](#):
>
> How does what work?
> 
> The point I’m making is that Proton agents can see all the addresses you create under the same account. It’s common knowledge.

Yes, does it displays under a different mailbox or the same?

I think those mailboxes are different from an allias. The concerning thing would be if any support employeed had the list of all the SL aliases you created.

---

## Post 130 by @Shampoo — 2026-03-15T22:11:03Z

> [@PurpleDime](#):
>
> Does it really matter if it’s first level support, a different team, or senior level support?

Yes. I assume that a company that cares about privacy would minimize the amount of data employees can see. First level supports assign tickets and work off of a script (have you cleared the cache? Have you tried logging out and logging back in?) I can’t see a reason why they’d need in depth info on accounts to do that.

---

## Post 131 by @PurpleDime — 2026-03-15T22:41:28Z

> [@Encounter5729](#):
>
> Yes, does it displays under a different mailbox or the same?

I was specifically talking about Proton addresses (@pm.me) not aliases. If you have multiple addresses under the same account, Proton agents can see them.

> [@Encounter5729](#):
>
> I think those mailboxes are different from an allias. The concerning thing would be if any support employeed had the list of all the SL aliases you created.

Aliases are a different matter. I assumed that first line agents could see my aliases, but now I know from first-hand experience that only senior agents can.

In regard to your mailbox address it is unclear. You gotta remember that Proton support has different contact addresses for their different products (Proton Mail vs Proton Pass/SL). However, it is unclear if there is a dedicated support team for each, or if most first line agents, respond to tickets about multiple services. I contacted support enough times to notice recurring names, but I don’t remember if it was always for the same Proton service.

I would be surprised if a first line Simple Login support agent could not see your mailbox address, but I know for a fact that senior agents can.

> [@Shampoo](#):
>
> Yes. I assume that a company that cares about privacy would minimize the amount of data employees can see.

I agree. However, as I previously said, I am pretty confident that first line agents can see your past tickets. And if you had a discussion with a senior agent in a past ticket, where sensitive information was discussed, I believe a first line agent can read it. I say this based on the fact that I have been asked about passed tickets by first line agents.

> [@Shampoo](#):
>
> First level supports assign tickets and work off of a script (have you cleared the cache? Have you tried logging out and logging back in?)

I guess it depends on the kind of issue you are reporting and the type of questions you ask.

---

## Post 132 by @Oneorfun — 2026-03-16T07:20:15Z

> [@passkeys](#):
>
> Proton operates exclusively under Swiss law, and we only respond to legally binding orders from Swiss authorities

I may be wrong, but following quote from [Proton legal/tos](https://proton.me/legal/terms) seems to make an exception to Swiss law exclusivity:

If you are a consumer user residing in the United States of America, you consent to the extent permitted by law to the jurisdiction of the courts of the Canton of Geneva to settle any dispute or claim (including non-contractual disputes or claims) arising out of or relating in any way to these Terms or its subject matter or formation and agree that any such claim that is brought in Switzerland shall be governed in all respects by the substantive laws of Switzerland. You further agree that for any disputes, actions, claims, or other controversies arising out of or relating in any way to these Terms, your Account, the Services, your use of (or lack of use of) or access to (or lack of access to) your Account or the Services, or any advertising, promotion, or other communications between you and the Company, whether based in contract, warranty, tort, statute, regulation, ordinance, or any other legal or equitable basis, **if brought in the United States and found to have jurisdiction in the United States, shall be construed and enforced in accordance with the laws of the state where you reside** ; provided, however, that the arbitration provisions herein shall be governed by the Federal Arbitration Act and the American Arbitration Association (“AAA”) Consumer Arbitration Rules (the “AAA Rules”), as described more fully below in Section 13.1.

I was disappointed to find out that unencrypted messages are scanned,and the unecrypted and saved as I see from following quote from [Proton Privacy Policy](https://proton.me/mail/privacy-policy) :

We do NOT have access to encrypted message content, but **unencrypted messages sent from external providers to your Account, or from Proton Mail to external unencrypted email services, are scanned for spam and viruses to pursue the legitimate interest of protecting the integrity of our Services and users. Such inbound messages are scanned for spam in memory, and then encrypted and written to disk. We do not possess the technical ability to scan the content of the messages after they have been encrypted.** We also have access to the following records of Account activity: number of messages sent, amount of storage space used, total number of messages, last login time. User data is never used for advertising purposes.

It is not clear for what purposes encrypted correspondence is kept if its not accessible.

In addition to not being able to erase at least one plastic card data, that was used to pay for subscription without cancelling subscription or adding data of a different payment method, I could not figure out how to delete paid invoices from past. I also noticed that invoice for 2026 has more data, such as user id and billing address of card.

Suggestions of solid alternatives (only email, no bundled services are needed) are welcome. Tia

---

## Post 133 by @anon19752758 — 2026-03-16T07:45:18Z

The first thing is probably something you’re forced to do if you have customers in the US but I don’t get how it should be bad tbh. As far as I understand it only matters if you as a US customer start a dispute. So for US customers it’s probably a plus and for the rest it doesn’t matter as far as I can tell.

For the second thing: Where exactly is your problem here? Isn’t that like the best case? You’ll always have incoming mails that are unencrypted and by design of e-mail the provider is able to read that. Proton saves it to disk in such a way that the can’t technically read the contents and on top of that apply spam filters. That is a good engineering, not a downside.

Can’t speak about “plastic card data” but it seems to either be a very unfortunate bug or a error on your side.
