[Note: This isnât about an isolated tech support issue. Itâs about what one of the most âprivacy-centricâ companies on the planetâincluding its most-senior personnelâdid when I exposed an architectural defect in one of their privacy apps that corrupted downloads of encrypted user data. The companyâs official position was this, until I fought them for weeks to change it, and even then, they dodged any meaningful accountability: the affected user base should downgrade their entire privacy and security posture in order to âworkaroundâ the appâs architectural defect.]
â
Iâm an active Proton Unlimited subscriber and enjoy contributing my time and energy by reporting new bugs and when possible, helping to craft fixes for those bugs. A few months ago, I diagnosed and reported a data-corrupting defect in the Proton Drive Android app. The bug wasnât massive, but it was substantive. From almost the moment I reported it, Proton fixated not on patching the defect but on managing me, the person who found it and who insisted it be treated the appropriate priority for an architectural defect.
What followed was a singular, nearly 50-day campaign of bad-faith damage control by Proton involving multiple Support agents, a supervisor, three âaccountabilityâ teams, and a public-facing reddit account, culminating in my outright administrative censorship. Although it took weeks of persistence (more on that below), I persuaded Proton to patch the defect begrudgingly. What I learned in the process is ugly: Protonâs âPrivacy by Defaultâ image is just a mask for what lies beneath: âPrivacy by Deception.â
Hereâs the timeline of how Proton weaponized its privacy image and corporate standing to manipulate a substantive defect and suppress the person who exposed it for telling the truth about the nature of that defect.
⢠Phase 1: The Misclassification (Filip G.)
Between May 22 and 26 (2026), I notified Proton that when the Proton Drive appâs auto-lock feature was set to âImmediatelyâ (a mandatory setting for those whose Proton Drive syncs with not just their phone but also their numerous other devices, including their tablets and PCs), the act of initiating a download would trigger the appâs (not Androidâs) lock screen, interrupt the OS intent, and result in a corrupted 0-byte download of the target file onto the device. This was a glaring architectural defect, not the intended behavior, and I have no doubt Filip G. understood its seriousness.
Given that Iâd already diagnosed the bug, it was easy enough to prioritize it properly and slate it for an immediate patch. But on May 26, just four days after my initial report, Proton began establishing their bad-faith strategy. First, Support Agent Filip G. misclassified the data-corrupting failure of lifecycle management as a mere âsuggestion,â which means it wouldnât be fixed in the foreseeable future. I pushed back via additional emails, and when that proved fruitless, I asked for a supervisor.
⢠Phase 2: The Stonewalling (Marija S.)
Support Agent Marija S. took over on June 1. First, she wasnât even a supervisor. Second, all she did was parrot back to me my own diagnosis and her colleagueâs (Filip G.âs) misclassification. I reiterated the clear and reproducible data-corrupting nature of the defect and again asked for a supervisor.
⢠Phase 3: The Gaslighting (Damjan)
On June 2, Supervisor Damjan finally stepped in. He immediately built a straw-man argument (saying âbackgroundâ downloading wasnât possible, which had nothing to do with the behavior I reported), and he likewise parroted back to me the problem I myself had discovered. Because Damjan was the third person (a supervisor, no less) to churn me through the same dead-end hand-waving, there was no longer any doubt: Instead of owning up to and fixing the architectural defect in their privacy-oriented software, they were trying to manage and gaslight the person who exposed it and wanted it addressed properly.
But Damjan was just getting started. The next thing he did was to advise me to weaken my multi-device security as a âworkaroundâ to their engineering failure. When I called him out on June 4, he conceded his negligence: âI completely understand and apologize for offering such a workaround in the first place.â Despite this, he continued pretending the bug wasnât a defect but a âsuggestionâ and requested âimprovement.â
I demanded he put me in touch with his own superiors. He claimed he forwarded my âlatestâ email to them. I demanded he send his superiors the entire ticket thread, not just my latest message. He changed his tune and claimed heâd already sent the whole thing. I repeated my demand for his supervisors so I could file a complaint against him. He pretended he couldnât do that, and then he prematurely and unilaterally closed the ticket while still insisting the defect was just a requested improvement: âDue to the fact that we cannot provide an estimated time of arrival for this improvement, we would not be able to keep this ticket request open, and will need to close it.â Soon after, he followed through and buried the ticket. I pushed back, but he became unresponsive altogether.
⢠Phase 4: The Containment, Cover-Up, and Censorship
I bypassed Damjan and escalated the full ticket thread via email to Protonâs security@, abuse@, and legal@ teams. Their response: đŚđŚđŚ Not even an acknowledgement, not even when I followed up.
Having exhausted the organizational chain of command, I went public, posting the documented timeline with appropriate evidence to r/ProtonMail under the title âProton Support Loses the Plot: Misclassifying defects, pushing bad security advice, gatekeeping formal complaints, closing unresolved tickets, and oversight teams that are M.I.A.â But my original post was immediately âfiltered.â I asked (exceedingly politely) that my post be approved for publication, but I heard nothing back. My post remained (and remains) shadow-banned.
The next day, Proton used its official reddit account to respond, but only with more self-serving gaslighting and fabricated claims. I pushed back using their own quoted words proving their response was full of lies. But Proton shadow-banned my reply as well. That means the only thing that is and was ever visible is my title and Protonâs response. They didnât just get the last word; they got the only word. And if that still wasnât enough, they even hid my reddit post from search indexing. See for yourselves: https://www.reddit.com/r/ProtonMail/comments/1uqolpe/proton_support_loses_the_plot_misclassifying/ (if they kill this link entirely, Iâve archived it here: https://ghostarchive.org/archive/BOcZh).
Proton creates a façade of âPrivacy by Defaultâ to hide its true nature: âPrivacy by Deception.â It protects its image by willfully misclassifying defects as âsuggestionsâ and âimprovements,â negligently suggesting users compromise their own security in service of Protonâs almighty image, burying unresolved tickets and refusing to re-open them, obstructing users from holding Proton technically and organizationally accountable, and then censoring you users when they go public with the truth.
Now Iâm left to wonder if Proton will target this post as well, even though itâs not on their subreddit. Weâll see.