Skip to main content


Review of Proton's Lumo 2.0


This entry was edited (3 days ago)
in reply to

"Given that many of us use Proton services and are privacy conscious" ~ oxymoron
in reply to eremophila

This entry was edited (3 days ago)
in reply to

An email and vpn provider promoting themselves as privacy conscious, and then developing ai should set off alarm bells.
I was previously a customer of proton (email and vpn), you don't have to pay attention to their products, social media, and customer service for long to realise that marketing is their strong point.
Purple-washing may become a term for faux privacy companies in future.
in reply to

The best thing about Lumo is that it isn’t integrated with their core services. I hate seeing ✨bullshit everywhere.
in reply to PeculiarGoat

Hah, I dont mean integrated like Micro$hit. I mean "is aware and can communicate with your other Proton services".

I like Lumo too but right now it's just...a collection of open weight llms, with missing features, low context and poor utility (bad web app, poor integration with Proton drive, can't create artifacts etc).

If Proton's intention is to create a privacy-based alternative to chat GPT or Claude, they're going to be chewing off a hell of a lot more, and nothing in how Lumo is currently served offers any confidence in that.

On the other hand, if their intention is to offer a Proton based product, that could be tightened up and made much more useful in a short order. Without spending a lot more.

But I'm not doing Proton's homework for them. As an end user, Lumo isn't quite "there" for me as a product, so I will discontinue. YMMV.

This entry was edited (3 days ago)
in reply to

If Lumo had access to the contents of your mailbox, wouldn't that be breaking a core feature of the whole Proton stack? E2EE/zero knowledge is fundamentally incompatible with integrating a provider-operated chatbot that can access your data
in reply to floquant

Zero-access means Proton cannot independently read stored mail (*). It does not prevent users from authorising selected decrypted emails / folders for temporary Lumo processing.

A server-side AI would temporarily see plaintext (which Lumo does anyway when it uses Proton drive etc), so Proton would need strict opt-in, minimisation, no retention, and clear disclosure, but it would not necessarily break zero-access storage.

Again, we (users) shouldn't be the ones doing the homework on this. Let Proton work it out (or not). Given it's taken 4+ yrs to get Proton drive to work with Linux.... well....

This entry was edited (3 days ago)
in reply to

Are you new to corporate lies about privacy?

Proton is beholden to Swiss disclosure law, and swiss law caves to international requests pretty often.

Just assume your emails are being read by proton.

in reply to

I don't think Qwen 27B would make much sense. I'm pretty sure Deepseek is cheaper to serve at scale (because of the small active parameter set) and is "smarter." At least that's what is reflected by 3rd party provider pricing on Openrouter.

Reliable Proton Mail, Drive, Calendar and Contacts integration


I think this could cause major problems for privacy guarantees.

in reply to sobchak

how? aren't all of them already hosted on Proton's server. you are already trusting them for your data. how does Lumo make it worst?
in reply to ☭可爱小猫☭

Proton can't read your mail (big "*"); it's decrypted client-side. Feeding it to their LLM would violate that. I'm unsure about their other services.
in reply to sobchak

This entry was edited (3 days ago)
in reply to

I personally like Lumo. There aren't many other services that offer privacy out of the box. And it's not some integrated solution so that I don't have to worry about data being shared with other services.