Quick verdict

Proton Mail is built so it cannot read your email; Gmail is built so it can, and does, just not for ad targeting anymore. That's the entire architectural difference, and almost everything else in this comparison is downstream of it. Proton encrypts your mailbox with keys only you hold, so handing your inbox to a government would mean handing over unreadable ciphertext. Gmail holds the keys to your inbox itself, which is what lets it filter spam and phishing with genuinely best-in-class accuracy — and also what makes it legally capable of producing readable mail under a valid U.S. court order.

Neither fact makes one service simply "better." Proton's own transparency history shows that zero-knowledge encryption doesn't mean zero cooperation with law enforcement — in 2021 a Swiss court order forced Proton to log and hand over a French climate activist's IP address, something no amount of message encryption could prevent. Gmail's scanning, meanwhile, has already been the subject of a 2018 investigation that found actual humans at third-party companies reading real inboxes, not just algorithms. The rest of this page works through both records in detail.

How each one actually encrypts your mail

Proton Mail uses two distinct layers of encryption, and conflating them is the single most common mistake in lazier comparisons of the two services. End-to-end encryption (E2EE) scrambles a message on the sender's device before it ever leaves for Proton's servers, so Proton itself never has a readable copy. Zero-access encryption is what protects everything sitting in your mailbox at rest: once a message arrives, Proton immediately re-encrypts it with your public key, so even messages that arrived unencrypted become unreadable to Proton the moment they land.

The distinction matters because of a scenario that trips up almost every new Proton user: mail from a Gmail sender to a Proton Mail inbox is never end-to-end encrypted, because Gmail doesn't support E2EE on its end. Proton's servers briefly see that message in plaintext during delivery, then immediately apply zero-access encryption before it's stored. Only mail between two Proton accounts — or mail sent through Proton's password-protected email feature or OpenPGP — gets true end-to-end protection for its entire journey.

Gmail has no equivalent to either layer. Messages are protected with TLS in transit (which every major provider, including Proton, also uses) and with standard server-side encryption at rest, meaning Google holds the decryption keys and can access message content whenever its own systems, or a valid legal process, require it.

Who can actually read your email

Nobody at Google reads Gmail for advertising anymore — that changed in 2017 — but the scanning itself never stopped, and the list of what it's used for has grown, not shrunk. Google ended content-based ad personalization in June 2017 while explicitly keeping automated scanning for spam filtering, phishing and malware detection, and features like Smart Reply and Smart Compose, which by definition require reading the text you're writing to suggest completions for it. In 2026, Gmail's Gemini AI features add another layer of processing on top of that, governed by a separate settings toggle from the original scanning.

The more revealing episode is one most comparison articles skip entirely: in 2018, a Wall Street Journal investigation found that third-party developers granted Gmail API access through OAuth permissions weren't just running algorithms against user inboxes — their employees were reading messages directly. Return Path, an email analytics firm, scanned roughly 100 million messages a day and had staff manually read about 8,000 of them to train its software, and Edison Software staff separately reviewed hundreds of user emails while building an app feature. Google's defense was that users had technically consented via the OAuth permission screen when they installed the app — a screen that says nothing about the possibility of a human employee, at a company most users have never heard of, reading their mail.

Why this matters more than the 2017 headline

The ad-scanning story gets repeated because it's simple. The OAuth story is the one that actually describes a live, ongoing risk: any Gmail user who has ever granted a calendar app, email client, or productivity tool access to their inbox has potentially given a company they can't audit standing access to read their mail, independent of anything Google itself does.

Proton Mail's answer to "who can read this" is architectural rather than policy-based: with zero-access encryption applied by default and no advertising business model built on message content, there's no equivalent internal incentive or mechanism for Proton to scan inbox content at all. That's a genuinely different guarantee than "we promise not to look."

Encryption protects message content. It does not protect metadata, and it does not exempt a company from the law it's incorporated under — a distinction Proton learned publicly in September 2021.

French police, investigating a climate activist collective called Youth for Climate that used a Proton Mail address, requested user information through Europol to Swiss authorities. Because Proton is legally domiciled in Switzerland, a Swiss court order compelled Proton to log and hand over the account holder's IP address and device fingerprint, which French police used to identify and arrest the activist. Proton's encryption held — the contents of the account's messages were never exposed — but the case exposed that Proton's "we don't log IP addresses" marketing claim was conditional on not receiving a binding Swiss legal order, and the company quietly rewrote its privacy policy and homepage copy within days of the story breaking.

Side-by-side comparison of Proton's privacy policy wording before and after the 2021 IP-logging disclosure, posted by security researcher @MuArF
Posted by security researcher @MuArF on X, Sept 1, 2021.

The wording change didn't come from a Proton announcement. A security researcher caught it independently, archiving the before-and-after copy while the story was still breaking — which is the only reason the discrepancy is documented at all rather than quietly forgotten.

The nuance most retellings of this story miss: a month later, Proton won a Swiss court ruling that email providers are not "telecommunications providers" under Swiss law, meaning they aren't subject to the same blanket data-retention obligations as ISPs and phone carriers. That ruling narrowed, though didn't eliminate, the circumstances under which a future request could force similar logging.

Gmail's exposure runs through an entirely different legal channel: the U.S. CLOUD Act. Because Google is a U.S. company, U.S. law enforcement can compel it to produce data stored on its servers regardless of the server's physical country — a jurisdictional reach Switzerland's courts don't have. This played out concretely in the Michael Cohen investigation, where federal prosecutors used a CLOUD Act warrant to obtain Cohen's Gmail messages, attachments, contacts, and Google Drive files after an earlier warrant attempt had been contested on jurisdictional grounds. Because none of it was end-to-end encrypted, Google could and did produce the content itself, not just metadata.

Legal exposureProton MailGmail
Governing jurisdictionSwitzerlandUnited States
Message content readable under a valid orderNo (E2EE/zero-access mail)Yes
Metadata/IP loggable under a valid orderYes — demonstrated 2021Yes
Cross-border reach of home jurisdictionNarrow — Swiss courts, no CLOUD Act equivalentBroad — CLOUD Act reaches data on any server
Publishes a transparency reportYesYes
Proton Mail
Want mail Google structurally can't scan? Proton Mail's free plan takes about two minutes to set up, no card required.
Try Proton Mail Free

Why the business models are the real divide

Gmail is free because Google's advertising business subsidizes it, and that shapes the product even after the 2017 ad-scanning change. Ads inside Gmail today rely on the same targeted advertising model, built from your broader Google account activity — search history, YouTube views, location history, and ad-personalization settings — rather than message content directly, but the underlying incentive to build a detailed profile of you across Google's ecosystem hasn't gone anywhere; email is just one input among many rather than the sole one.

Proton Mail runs on a pure subscription model with no advertising revenue stream at all, which removes the structural incentive to monetize inbox data, but it also means the free tier is deliberately limited: 1 GB of storage and a 150-message daily sending cap, compared to Gmail's much more generous free allowance. You're paying Proton directly for privacy instead of paying Google indirectly with your data — a trade worth being explicit about rather than treating as self-evidently good or bad.

Pricing and storage compared

Gmail's free tier gives you 15 GB of storage, but that allowance is shared across Gmail, Google Drive, and Google Photos combined — not 15 GB dedicated to email, which heavy users of Google's ecosystem burn through quickly. Proton Mail's free tier gives you 1 GB dedicated purely to mail, which sounds small by comparison but resets the framing: for someone who only wants private email and nothing else, storage isn't the constraint the raw numbers imply.

Once you move to paid tiers, the two stop being directly comparable products. Proton Mail Plus runs $4.99/month billed monthly, or $3.99/month billed annually, for 15 GB of storage, one custom domain, and unlimited messages. Proton Unlimited, at $12.99/month monthly or $9.99/month annually, bundles 500 GB of storage with Proton VPN, Proton Drive, Proton Pass, and Proton Calendar — effectively a full replacement for the Google ecosystem rather than just an email upgrade. Google One's cheapest paid storage tier starts near $1.99/month for 100 GB, but that's storage alone; it doesn't include Workspace's collaborative tools, which sit in a separate business-tier pricing structure entirely.

The honest comparison isn't "which is cheaper" — it's "which thing are you actually buying." Gmail's paid tiers buy storage and collaboration. Proton's paid tiers buy an entire privacy-first ecosystem, priced accordingly.

Security features beyond encryption

Encryption model aside, the two services solve genuinely different security problems well, and pretending one wins on every axis undersells both.

Where Gmail has a real, defensible edge

Google's scale gives its spam and phishing filtering a training dataset no smaller provider can match: Gmail blocks more than 99.9% of spam, phishing, and malware, processing over 15 billion unwanted messages a day. Its Advanced Protection Program, aimed at high-risk accounts like journalists and activists, enforces hardware security keys and stricter app-access review — a threat model Proton doesn't offer an equivalent dedicated tier for.

Where Proton Mail has a real, defensible edge

Proton's clients are fully open source and have undergone independent third-party security audits, meaning its zero-access and E2EE claims can be, and have been, externally verified rather than taken on faith. Native OpenPGP support lets you send genuine end-to-end encrypted mail to non-Proton users who also use PGP, and the password-protected email feature extends E2EE to any recipient, encrypted or not — something Gmail has no built-in equivalent for.

Which one you should actually use

If your threat model is "I don't want my provider building an ad profile from my inbox and I want message content encrypted end to end whenever possible," Proton Mail is the architecturally correct choice, with the caveat that Swiss legal process can still compel metadata disclosure in serious criminal cases — it's not a shield against every kind of legal request, only against content being handed over readable.

If your priority is deep integration with a productivity ecosystem, best-in-class spam/phishing filtering at massive scale, and you're not routinely handling content you'd need protected from a U.S. legal order, Gmail remains a genuinely competent, well-engineered product — its privacy trade-offs are simply different in kind, not just degree, from Proton's.

A workable middle path many privacy-conscious users land on: keep Gmail for its filtering strength and ecosystem convenience on low-sensitivity mail, and route anything sensitive — legal, financial, activism-related, or journalistic communication — through a Proton Mail account instead of trying to force one provider to do both jobs.

Frequently asked questions

Does Proton Mail encrypt mail sent from Gmail users?

Not end-to-end. When a Gmail user emails a Proton Mail address, Proton's servers briefly see the message in plaintext during delivery, because Gmail doesn't support E2EE, then immediately apply zero-access encryption before storing it. Only Proton-to-Proton mail, or mail sent via Proton's password-protected email or OpenPGP, is end-to-end encrypted for its full journey.

Can Proton Mail be forced to hand over my data?

Message content, no — zero-access encryption means Proton doesn't hold the keys to decrypt it, even under a Swiss court order. Metadata like your IP address and device fingerprint, yes, in specific circumstances: a 2021 Swiss court order compelled exactly this in a French criminal investigation.

Does Gmail still read my email in 2026?

Not for ad targeting, and not by a human in the ordinary course of using the product. Automated systems do still process every message for spam filtering, phishing detection, and features like Smart Compose and Gemini AI suggestions, and a 2018 investigation found human employees at third-party apps with OAuth access to Gmail accounts reading messages directly.

Is switching from Gmail to Proton Mail difficult?

Proton offers an Easy Switch tool that imports existing mail and contacts and can set up automatic forwarding from a Gmail account during the transition, which covers the mechanical part of migration. The harder part is updating your address everywhere it's registered — banks, subscriptions, logins — which no migration tool automates for you.

Sources

  • Proton — Zero-access encryption documentation
  • Proton — How Proton Mail messages are encrypted
  • Engadget — ProtonMail and the 2021 French activist IP disclosure
  • Proton — Official clarification and the subsequent Swiss court ruling
  • Privacy International — Google ends Gmail ad-targeting scans (2017)
  • Tom's Hardware — Third-party developer access to Gmail content (2018)
  • Reclaim The Net — CLOUD Act warrant used against Google in the Cohen case
  • Google Safety Center — Gmail spam/phishing block rate and Advanced Protection Program
PrivacyTestLab logo

Written by PrivacyTestLab

This comparison reflects each provider's current encryption architecture, documented legal history, and published pricing as of July 2026. Links to Proton Mail on this page are affiliate links; our comparisons and conclusions are not influenced by that relationship.