proton.me privacy policy — score 88/100 (low risk)

Dernière analyse

Le contenu du rapport (résumé, constats, citations) a été généré en anglais et n'est pas localisé.

Lancer une nouvelle analyse sur une autre politique

Proton AG · proton.me

Détails du rapport

low risque

Proton offers strong privacy by default with end-to-end encryption, minimal data collection, and no ad tracking, though some user data does flow to US-based processors for support and payments.

Proton's privacy policy demonstrates a strong commitment to data minimization and user privacy, anchored by end-to-end encryption and Swiss legal jurisdiction. The policy is transparent about its limited data collection and explicitly prohibits using user content for AI training. However, there are notable exceptions regarding IP logging for abuse prevention, and several third-party processors operate outside the EU/EEA (specifically in the US, Taiwan, and Macedonia), relying on Standard Contractual Clauses for legal cover. The policy also lacks specificity on data retention periods for temporary logs.

Dernière analyse
SourceURL
Longueur25,585 caractères

Évaluation par catégorie

Répartition de la politique selon les principaux domaines de conformité. Bon = solide, moyen = mitigé, faible = préoccupant.

Data Minimizationgood

Proton requires no personal information for account creation, uses self-hosted analytics without retaining IPs, and accepts anonymous payment methods like cash and Bitcoin.

Transparencygood

The policy is detailed and specific about what is collected, the legal bases used, and the circumstances under which data might be retained or disclosed.

Third-party Sharingfair

While core service data is processed internally, support and payment data is shared with US-based processors like Zendesk, Stripe, and Chargebee, and internal processors exist in Macedonia and Taiwan.

International Transfersfair

Data is transferred to the US, Singapore, Taiwan, and Macedonia using Standard Contractual Clauses, but the policy lacks detail on supplementary measures addressing Schrems II risks for US transfers.

AI/Model Traininggood

Proton Scribe runs locally by default and explicitly does not use any user data for model training, providing a clear opt-in for server-side processing.

User Rightsgood

Users can access, edit, delete, or export personal data directly through the Account interface, and the policy mentions the right to lodge a complaint with a supervisory authority.

Constats clés

Clauses notables, problèmes ou bonnes pratiques identifiées (critiques en premier)

Avertissement

Conditional IP Logging Undermines No-Log Claim

IP addresses are not permanently logged by default, but can be retained temporarily for abuse prevention or permanently if Terms of Service are breached, which is a significant exception to the no-logging claim.

Avertissement

International Transfers to US Processors via SCCs

Several third-party processors operate outside the EU/EEA, specifically in the United States and Taiwan, relying on Standard Contractual Clauses for data transfers, which poses a risk under Schrems II.

Avertissement

Vague Retention Periods for Temporary Data

The policy allows for permanent retention of IP addresses and hashed verification data without specifying a maximum retention period, relying on vague determinations of 'legitimate interests' and 'applicable Swiss legal requirements'.

Info

Strong Data Minimization and Encryption by Default

Proton explicitly states it cannot access end-to-end encrypted content and collects minimal personal data, not even requiring personal information for account creation.

Info

AI Feature Respects Privacy by Default

Proton Scribe's AI feature operates locally by default and explicitly does not use user data for model training, which is a strong privacy-positive stance.

Synthèse pour l'utilisateur

Proton is one of the stronger privacy-focused services available, genuinely minimizing the data it can access and refusing to train AI on your content, but you should be aware that using customer support or payment features exposes some data to US companies, and your IP can be logged if you violate their terms.

Posture de conformité

Proton aligns well with GDPR principles, particularly regarding data minimization, encryption by default, and user rights. The appointment of an EU representative (Proton Europe sàrl in Luxembourg) and explicit mention of GDPR compliance reinforce this posture. The main compliance risks stem from international data transfers to third-party processors in the US and Taiwan, which rely on SCCs without detailed mention of supplementary technical measures post-Schrems II.

Transferts UE

Data transfers to the US (Zendesk, Stripe, Chargebee, PayPal) and Taiwan (ProtonLabs Taiwan) rely on Standard Contractual Clauses. While the policy lists these guarantees, it is silent on supplementary technical measures (such as strong encryption in transit/at rest controlled by Proton) that are often required to make these transfers lawful under the Schrems II ruling. Transfers to Macedonia (ProtonLabs DOOEL) are not covered by an EU adequacy decision and lack specified transfer mechanisms in the policy.

Signaux détectés

Données et pratiques spécifiques identifiées dans le texte

Données collectées
Email addressIP address (temporary)Phone number (temporary for verification)Payment data (name, last 4 digits of card)Support communication dataCrash reports and app statisticsAccount authentication logs (if opted in)
Finalités du traitement
Service provision and account managementAnti-spam and human verificationPayment processingCustomer supportAbuse and fraud preventionAI writing assistance (Proton Scribe)
Partage avec des tiers
Payment data shared with Chargebee, Stripe, PayPalSupport data shared with Zendesk and AtlassianSales inquiries shared with HubspotNetwork traffic potentially routed through third-party networks for anti-censorship
Transferts internationaux
United States (Zendesk, Stripe, Chargebee, PayPal, Atlassian)Singapore (PayPal)Taiwan (ProtonLabs Taiwan Co., Ltd)Macedonia (ProtonLabs DOOEL Skopje)
IA / Entraînement de modèles
AI training explicitly excluded for Proton Scribe

Extraits probants

Citations directes de la politique à l'appui de ces constats

We do not have the technical means to access the content of your encrypted emails, files, calendar events, passwords, or notes.

By default, we do not keep permanent IP logs in relation with your Account. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our Terms of Service

Proton Scribe does not use content data or any of your data to train its models.

We will only disclose the limited user data we possess if we are legally obligated to do so by a binding request coming from the competent Swiss authorities.

Manquant ou flou

  • No specific data retention periods for temporary IP logs or hashed verification data
  • No mention of supplementary technical measures for US data transfers post-Schrems II
  • No mention of a Data Protection Impact Assessment (DPIA)
  • No specific details on the right to data portability format
  • No mention of transfer mechanisms for data sent to Macedonia

Questions à poser

  • What are the exact maximum retention periods for temporarily stored IP logs and hashed verification data (phone numbers, emails) used for anti-spam?
  • What supplementary technical measures (e.g., encryption, pseudonymization) are applied to data transferred to US-based processors like Zendesk and Stripe under Standard Contractual Clauses?
  • How does Proton ensure that third-party processors like Zendesk and Atlassian delete support data upon request when a user exercises their right to deletion?
  • Under what specific criteria is a user determined to be 'engaged in activities that breach our Terms of Service' triggering permanent IP logging, and is there an appeals process?
  • What transfer mechanism is used for data sent to the processor in Macedonia, which lacks an EU adequacy decision?
Cette analyse est générée par IA et ne constitue pas un avis juridique. Consultez toujours un professionnel du droit qualifié pour les décisions de conformité.

Partager cette analyse

Toute personne disposant de ce lien peut consulter le résultat ci-dessus.

Conçu par DentroChat

Chat IA 100 % européen pour tous

Discutez avec l'IA, travaillez avec des fichiers, générez des images et cherchez sur le web. Les données restent en Europe.

Infrastructure hébergée dans l'UETexte, fichiers, images et recherche webModes Rapide, Réflexion et CréatifConfidentialité par défautAucune donnée ne quitte l'Europe
Essayer gratuitement →