For example, say that an individual would face a death sentence for religious preaching activity in the country where they live. They are unconcerned about people discovering the content of their messages or whom is receiving them. But, if they are discovered to be the person responsible for them they would likely be killed. Their sending of the messages through ProtonMail would be protected from observation by ProtonMail's TLS w/ PFS HTTPS encryption. But, their local ISP or government could observe all of their traffic. They could then, through traffic correlation, determine that specific individual was sending encrypted packets to ProtonMail's servers at the exact time various messages were sent. Using Tor would protect this individual's identity. The observers could determine tor traffic and attempt to correlate that with messages if they suspected the individual. But, if he was generating additional tor traffic by running as a relay or browsing other sites with tor the correlation would be extremely difficult.
The reason that ProtonMail set up the .onion site is because accessing ProtonMail over congested exit nodes that may be far from ProtonMail's servers is very slow. The .onion site has dedicated bandwidth directly to ProtonMail's webservers and is located close by in Switzerland. It should be expected that it much faster for users to use the .onion site than exit nodes to access ProtonMail.