Everyone just memory hole and forget about how they complied with a subpoena to turn over the IP and phone number of a French protestor to EUROPOL, leading to their arrest.
Yep, that happened while they were telling their users they do not log IPs and are secure and will protect your privacy, as they still are.
They don't log IP addresses, but some governments have laws where the court can compel them to start logging, which is what they did here. It was also a unique situation between France and Switzerland where the two countries have specific agreements when laws between them are the same, such that if you commit a crime in one country the other will help to catch you. With ProtonMail being based in Switzerland, where the court order was issued, there was far less room for them to do anything about it.
What they did was in line with what their terms and conditions stated at the time. Afterwards, they reworded the terms to make it more clear.
All businesses have to comply with court orders, and unfortunately a single user isn't a hill worth dying on. All users and fundamentally undermining encryption is, though.
They advertised that they dont log IP addresses while they were logging the IP address of at least one user.
Then they got caught doing this and did a PR campaign to explain why.
This is duplicitous, false advertising, and lying until they got caught.
Further, due to the nature of warrants, the tech involved, how investigations work, relevant laws blah blah... this means that potentially any user could be subpoenaed by the Swiss gov, and ProtonMail would give out their IP without ProtonMail telling said user. This means any user based in a country that has roughly friendly relations with the Swiss gov is at risk.
I thought a whole point of safe and secure email services is that they are also safe and secure from governments? Most of them are marketed that way.
I dont know about yall, but if they even have the organizational and technical capacity to provide the info they did, they are a piss poor 'private and secure' email provider.