EDIT: "some provider like Proton" -> "some provider", never wanted to imply Proton specifically did or does this.
[1] https://signal.org/blog/looking-back-as-the-world-moves-forw...
So they must have the ability to look at all that encrypted data anyway?
"Loads" of private data? When has this allegedly happened or how would it technically even be possible?
So that probably has happened. Whether they've even provided other private data I don't know, but
> how would it technically even be possible
Well, it's not possible if you trust their claims about E2EE, but that is just a claim. How's that any different from a non-encrypted email provider saying they won't provide your emails to others? It all comes down to trust in the end.
Edit: A reply to your misunderstanding and accusation below:
What do you mean? By "provide your emails to others" I obviously mean the email *contents*, not the email *address*. (Which I also clarified with "the storage of your emails on their servers"). You know, the very thing that is almost the whole selling point of Proton: that they keep the contents of your emails encrypted so "only you" can access them.
> Proton Mail protects the contents of all your messages with zero-access encryption, meaning no one can read them except you and your recipients. Messages you send to other Proton Mail accounts are always end-to-end encrypted, as are emails sent to non-Proton Mail accounts when you use Password-protected Emails.
https://proton.me/security/end-to-end-encryption
Also, what in the SMTP protocol requires Proton to *store* that metadata? Could they not simply delete it after using it (or, crazy idea, encrypt it in the same way the message contents are encrypted in storage), so they would be unable to respond to law enforcement requests the next week, say? They did also previously claim that they didn't log user's IP addresses. Why would they claim something like that, if it's "obvious to anyone who knows" that it's a false claim? Marketing aimed towards their not so technically savvy userbase?
https://www.theregister.com/2021/09/07/protonmail_hands_user...
Let me also remind you that I was replying to a question about "how would it technically even be possible" to "offer loads of your private data when ordered". My reply was, it's easily possible for them to offer your metadata, and you still need to trust their claims about heir implementation of E2EE to believe they won't offer your message contents.
You're very quick to accuse people of spreading misinformation. Let me hit back with an accusation of my own, which is that Proton's PR team have a habit of regularly trying to discredit any critique as "misinformation". Perhaps you've just read too many of their rebuttals?
https://proton.me/mail/privacy-policy
> Account Activity: Due to limitations of the SMTP protocol, we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times.
This would be obvious to anyone knows how email works. It would be very silly for them to claim otherwise.
It's quite hypocritical of Proton to claim that they protect against government surveillance when they do things like this though [0]. Their legal team has probably ensured they don't claim anything strictly false, but the implication and the reality are wildly different.
[0] https://freedom.press/digisec/blog/proton-mail-is-not-for-an...
Proton has always-on end-to-end encryption and zero‑access encryption, meaning even we do not have access to your data.
[...]
Based in Europe, Proton ensures your data is protected by some of the world’s strongest privacy laws. Because Proton isn’t a US‑based company, we can’t be compelled by laws such as the US CLOUD Act to hand over your data to the US government or terminate your services. [1]
[1] https://proton.me/business/blog/proton-workspace
Obviously as we have seen, they 100% can and will hand over your data to the US government. Yes, it's in the privacy policy/ToS & they're compiling with local laws. But that's clearly not how that reads.
[In 2021, the Switzerland-based vendor provided local police with the IP address and device details of a netizen the cops were trying to identify. That individual – a French climate activist who was already known to police – was later arrested.
Shortly after that kerfuffle, Proton removed the claim that it didn't track user IP addresses from its website. Proton has also previously been accused of offering real-time surveillance of users to authorities.] [2]
[2] https://www.theregister.com/2024/05/13/infosec_in_brief/
See also: ProtonMail filters this into its junk folder: New claim it goes out of its way to help cops spy https://www.theregister.com/2019/05/29/protonmail_dismisses_...
A search on your favorite search engine of 'instances where proton has turned over user info to the government' will provide further reading.