Table of Contents
What Is Proton Lumo?
Proton Lumo is a privacy-focused AI chatbot created by Proton AG, the company known for Proton Mail and Proton VPN. It’s built on open-source language models and runs entirely on Proton-controlled servers in Europe, ensuring your data is never shared or used for AI training. With features like zero-access encryption, no-logs policy, and optional privacy-friendly web search, Proton Lumo is designed to provide helpful AI assistance while keeping your conversations completely confidential.
What Makes Proton Lumo Different?
What makes Proton Lumo different is its strong commitment to privacy and transparency. Unlike many AI tools, it uses zero-access encryption so even Proton cannot read your chats, enforces a strict no-logs policy, and offers features like “Ghost Mode” to erase conversations when the session ends. It’s powered entirely by open-source, auditable language models instead of closed, proprietary systems. Lumo also integrates securely with Proton’s ecosystem, allowing encrypted file uploads from Proton Drive and optional privacy-friendly web searches, giving users both powerful AI capabilities and complete control over their data. Designed by the Swiss privacy pioneers behind Proton Mail and Proton VPN, Lumo delivers mainstream AI capabilities like document summarisation, code generation, and email drafting—without sacrificing your data privacy.
Proton Lumo’s Privacy-First Features
From your first chat, it’s evident that Proton Lumo works for you—not against you. Lumo enforces a strict no-logs policy: no chat logs are kept on their servers, and your queries are never used to train the AI. If you use a Free or Plus Proton plan, your conversation history is encrypted and securely stored on your device and Proton’s servers, accessible only by you. For guest users, conversations are deleted after each session, ensuring complete confidentiality.
Also read: How to Choose the Right Private Browser for Enhanced Online Privacy
Encryption and Zero-Access Promise
“Proton Lumo, privacy-first AI assistant with encrypted chats,” isn’t just a tagline. Lumo adopts zero-access encryption by default. This security model means only you have the key to decrypt and read your chats—neither Proton nor any third party can access your data, even if compelled by external requests. Data transmission is further secured by TLS, with prompts asymmetrically encrypted so that only the Lumo servers can process them—and only for the moment needed.
Additional privacy measures include:
- No data sharing or third-party access, ever.
- No training of AI models on your conversations.
- No metadata retention, not even timestamps or IP addresses.
| Aspect | Proton Lumo | ChatGPT / Gemini |
| Data logging | None — ghost mode deletes chats automatically; saved history is encrypted | Logs by default unless you opt out (but some data may still be accessed temporarily) |
| Training use | No — user chat data is never used to train models | Often used unless disabled |
| Encryption | End‑to‑end, zero‑access | Varies; not typically zero‑access |
| Source models | Fully open‑source and audited | Mostly closed, proprietary |
| Knowledge recency | Cutoff ~April 2024; web search optional and privacy‑respecting | Generally more up‑to‑date by default |
| Formatting | Basic formatting; less polished tables/structure than ChatGPT/Gemini | More refined, interactive outputs |
Supported Functions and Model Transparency
Despite its privacy-first approach, Lumo is feature-rich:
- Summarises documents.
- Generates code.
- Drafts emails and answers questions.
- Analyses uploaded files without retaining them.
- Integrates with Proton Drive for secure document handling.
Lumo runs exclusively on open-source language models (including variants from Mistral and Nvidia), all hosted in European data centres under Proton’s direct control. This ensures strict adherence to GDPR and further insulates your data from global surveillance pressures.
Proton makes Lumo’s codebase open source, so anyone can independently audit its privacy claims—a rarity in the AI industry.
How Lumo Compares With Other AI Assistants
Unlike AI chatbots from Big Tech (e.g., ChatGPT, Gemini), Proton Lumo explicitly divorces itself from surveillance capitalism. Key distinctions:
- No data harvesting or profiling.
- No cloud partnerships with US or Chinese firms.
- No feeding of your queries into future AI training datasets.
Users who prioritise privacy, transparency, and independence will find Lumo a preferable choice, albeit with possible trade-offs in model sophistication compared to mainstream commercial offerings.
Platforms, Pricing, and Getting Started
Proton Lumo is accessible via web browsers, Android, and iOS apps. There’s no requirement for account registration anyone can try Lumo for free. For enhanced features, the Lumo Plus plan unlocks:
- Unlimited encrypted chat history.
- Favourite and search past chats.
- Upload and analyse larger or multiple files.
- Priority support.
A unique “ghost mode” ensures chats are erased once the session ends—strengthening Lumo’s privacy-first promise
Conclusion: A Turning Point for Private AI
Proton launches Lumo, a privacy-first AI assistant with encrypted chats, representing a clear shift from surveillance-dependent models to user-empowered, confidential AI. By combining robust privacy controls, transparent operation, and versatile features, Proton Lumo stands as the new gold standard for anyone seeking AI solutions that genuinely respect user privacy.


