A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.
Not at all. Proton doesn’t require any personal info at all. But if you pay with a credit card… That has your personal info tied to it. It’s their fuck up paying with a credit card. Proton accepts other payment methods that aren’t tied to your identity.
Proton is required by law to provide information they have when the courts say so.
Not sure about Swiss laws regarding merchant payment card data retention… But they aren’t really going to matter with this situation either way. Even if Proton doesn’t keep any identifying information directly, the payment processor for sure is going to keep identifying data. Proton will have a confirmation number for the payment being processed, which can be correlated via the payment processor anyway.
So I’m not a criminal organization as far as I know, but if I did pay with a credit card originally can that be rectified without deleting and starting over?
Proton uses Chargebee for payments, which has its own data retention policy of essentially “as long as we want to”, but Proton does themselves keep limited data like the billing name, and last 4 digits.
Proton’s privacy policy says nothing about a pre-set time delay after which they’d delete that data. They only claim that they “reserve our right” to remove your payment information if they think it’s no longer valid. So theoretically, that might mean if your card’s expiry date has passed, but that’s not a confirmation.
The best way to reliably make sure Proton wouldn’t have any info on you is to not have ever tied any real information about yourself or your payment info to that account.
Yeah, exactly. They don’t make it hard to not tie personal data to them if you want, you just have to actually DO the thing to take advantage of it. These people seemed to think it was magic, which seems to be how a lot of people think Proton or Tuta works.
Not at all. Proton doesn’t require any personal info at all. But if you pay with a credit card… That has your personal info tied to it. It’s their fuck up paying with a credit card. Proton accepts other payment methods that aren’t tied to your identity.
Proton is required by law to provide information they have when the courts say so.
Are they required to keep the data?
Not sure about Swiss laws regarding merchant payment card data retention… But they aren’t really going to matter with this situation either way. Even if Proton doesn’t keep any identifying information directly, the payment processor for sure is going to keep identifying data. Proton will have a confirmation number for the payment being processed, which can be correlated via the payment processor anyway.
So I’m not a criminal organization as far as I know, but if I did pay with a credit card originally can that be rectified without deleting and starting over?
Proton uses Chargebee for payments, which has its own data retention policy of essentially “as long as we want to”, but Proton does themselves keep limited data like the billing name, and last 4 digits.
Proton’s privacy policy says nothing about a pre-set time delay after which they’d delete that data. They only claim that they “reserve our right” to remove your payment information if they think it’s no longer valid. So theoretically, that might mean if your card’s expiry date has passed, but that’s not a confirmation.
The best way to reliably make sure Proton wouldn’t have any info on you is to not have ever tied any real information about yourself or your payment info to that account.
Thank you for the information.
Yeah, exactly. They don’t make it hard to not tie personal data to them if you want, you just have to actually DO the thing to take advantage of it. These people seemed to think it was magic, which seems to be how a lot of people think Proton or Tuta works.