Who can read your emails? With most providers, the honest answer is: the provider itself. Encrypted mailboxes promise something different. Here is what they deliver and where the limits are, using Proton as an example.
Regular mailbox: the provider holds the key
Even with a regular mailbox, emails are usually stored encrypted on the server. But the provider manages the key. It can technically read and search your emails, for search, spam filters or extra features. And when an authority arrives with a valid order, it can hand them over.

With a regular mailbox, the provider holds the key. It can read the emails and hand them over when ordered.
Encrypted mailbox: the key stays with you
Encrypted mailboxes turn this around. The key is protected by your password, and only you know the password. The server only holds scrambled data. Proton calls this zero-access encryption: even the provider can’t get to the content.
When two Proton users write to each other, it goes one step further. The email is then end-to-end encrypted, from the sender’s device to the recipient’s device. Nobody can read it in transit or on the server.
Simplified: behind the “key”, Proton uses a private key based on the OpenPGP standard and the password that protects it.

Same diagram, roles reversed: the key is protected by your password, and the server only sees encrypted data.
What stays visible anyway
Not everything is protected. According to Proton, subject lines, sender and recipient addresses are encrypted, but not end-to-end encrypted. Who writes to whom, when and about what is therefore not protected to the same degree as the content.
Emails to regular addresses, such as Gmail or Outlook, are not end-to-end encrypted either. The exception: you protect the email with a password that the recipient receives through another channel.

The content is protected; sender, recipient and subject are not end-to-end encrypted.
Based in Switzerland: protection, not a free pass
Proton is based in Geneva and subject to Swiss law. Foreign authorities cannot force Proton to hand over data directly; Article 271 of the Swiss Criminal Code prohibits passing data directly to foreign authorities. They have to go through Swiss mutual legal assistance.
When a binding order under Swiss law arrives, Proton still has to provide data. The 2021 case shows this: French police sent their request via Europol to the Swiss authorities, who then required Proton to log the IP address of a French activist. Proton had to comply. The content of the emails stayed encrypted.
How often this happens is in Proton’s transparency report: in 2025, there were 9,301 orders for Proton Mail, of which 8,313 were complied with and 988 contested. Proton can hand over things like account details and activity logs, but no encrypted content.

Foreign authorities have to go through Swiss mutual legal assistance. Proton then has to hand over metadata such as an IP address, but no encrypted content.
Switzerland is changing too: the VÜPF revision
The Swiss ordinance on the surveillance of postal and telecommunications traffic (VÜPF) defines which providers have to assist with surveillance and how. The federal government wanted to tighten it. The draft failed in the 2025 consultation: the Greens, SP, GLP, FDP and SVP rejected it, as did industry associations and providers such as Threema and Proton.
Proton has already responded by moving parts of its infrastructure abroad. First, in 2025, its AI assistant Lumo moved to servers in Germany; further locations are being set up in Norway.
As of 2 October 2026: the revision is not in force. On 11 February 2026, the Federal Council took note of the consultation results, commissioned a regulatory impact assessment and announced a second consultation once the revised version is ready.

The revision is not yet in force. Proton has already responded anyway.
Three questions for your mailbox
- Who holds the key? You or the provider?
- What is end-to-end encrypted? Only the content, or also subject and recipients? And does it apply to emails sent outside the service?
- Which law is the provider subject to? And how does it handle orders, is there a transparency report?
My view
This is my personal assessment, not a recommendation for every case.
I’ve been using Proton for years, mainly for email, plus other services from the bundle. Not because it’s perfect: metadata stays visible, and Switzerland can change its rules too. But because the provider can’t read my content. For me, that is digital sovereignty in everyday life: not complete independence, but deciding consciously who holds the key.
And you?
Who holds the key to your mailbox?
Frequently asked questions
Can Proton read my emails?
Not the content. Proton stores emails with zero-access encryption: the key is protected by your password, and the server only holds encrypted data. Subject lines, sender and recipient addresses are encrypted, but not end-to-end encrypted.
Is an email from Proton to a Gmail address end-to-end encrypted?
No. Emails between two Proton accounts are end-to-end encrypted. Emails to regular addresses are only end-to-end encrypted if you protect them with a password that the recipient receives through another channel.
Does Proton have to hand data over to authorities?
Yes, when it receives a binding order under Swiss law, but not the content of encrypted emails, because Proton cannot decrypt it. It can hand over things like account details and activity logs. Foreign authorities have to go through Swiss mutual legal assistance. In 2021, such an order required Proton to log the IP address of a French activist.
Sources
- Proton: Proton Mail encryption explained (support)
- Proton: Transparency Report (updated 6 January 2026)
- TechCrunch: ProtonMail logged IP address of French activist after order by Swiss authorities (6 September 2021)
- WeLiveSecurity: ProtonMail forced to log user’s IP address (7 September 2021)
- heise: Proton relocates parts of its infrastructure from Switzerland (2025)
- Swiss Federal Council: telecommunications surveillance, results of the consultation (11 February 2026, German)
- inside-it: VÜPF revision fails completely in consultation (7 May 2025, German)
Reuse


