Last updated: September 27, 2026
1. Our approach
Proton is designed around data minimization. We do not propose recording browsing history, DNS queries, traffic content, or the IP addresses of websites visited through the VPN.
2. Account information
A production account may require an email address, account identifier, encrypted credentials, plan status, and limited security events needed to prevent abuse.
3. Connection operations
Servers may process transient technical data to establish and maintain a connection. This data should be discarded after the operational need ends and should not be used to build activity profiles.
4. Payments
Payments would be handled by a specialist processor. Proton should retain transaction references, plan status, and records required by tax or accounting law, not full card details.
5. Cookies and website analytics
The site should use essential cookies for security and preferences. Optional analytics should be privacy-preserving, aggregated, and subject to consent where required.
6. Retention and security
Personal data should be kept only as long as needed for its stated purpose, legal obligations, dispute handling, or security. Encryption, access controls, and review procedures should protect retained data.
7. Your choices and rights
Depending on local law, you may request access, correction, deletion, restriction, portability, or objection. Contact privacy@Proton.com.
8. International processing
A real service must publish its legal entity, operating locations, transfer safeguards, and applicable supervisory authority before collecting personal data.
9. Contact
Privacy questions: privacy@Proton.com. Corporate address and data-protection representative must be added before launch.