Lumo by Proton

Lumo by Proton

29/07/2025
Meet Lumo, the zero-access encrypted AI assistant by Proton that does not track or record your conversations. Ask me anything — it
lumo.proton.me

Overview

In an increasingly digital world where artificial intelligence has become indispensable, the convenience of AI often comes with a significant trade-off: privacy and data sovereignty. But what if you could harness the full power of artificial intelligence without sacrificing your personal data or compromising your digital confidentiality? Enter Lumo, the revolutionary zero-access encrypted AI assistant by Proton, officially launched on July 23, 2025. Designed from the ground up with your confidentiality as the paramount concern, Lumo ensures that your conversations are never tracked, recorded, stored on servers, or used for training future AI models.

Built by the same Swiss-based team behind Proton Mail, Proton VPN, and other privacy-focused services trusted by over 100 million users worldwide, Lumo represents a fundamental shift in how AI assistants operate. Unlike conventional AI platforms that treat user data as a valuable commodity, Lumo operates under a strict no-logging policy and employs battle-tested zero-access encryption technology, ensuring that even Proton itself cannot read your conversations. It’s AI that truly respects your privacy, offering powerful assistance without requiring extensive personal information or compromising your data sovereignty.

Key Features

Lumo stands out with a comprehensive set of features meticulously crafted to prioritize user privacy while delivering sophisticated AI assistance capabilities:

  • Zero-access encryption with client-side processing: Your conversations are encrypted using advanced cryptographic protocols directly on your device before transmission, meaning only you possess the encryption keys necessary to decrypt and access your chat history. This architecture ensures that not even Proton can read your conversations, providing unprecedented privacy protection.
  • Comprehensive no-logging policy with data minimization: Lumo operates under a strict no-logging infrastructure that doesn’t retain conversation logs on servers, doesn’t track user behavior patterns, and doesn’t store personal metadata beyond what’s essential for basic functionality, ensuring your interactions remain completely private and untraceable.
  • Ghost mode for ephemeral conversations: For ultimate privacy protection, ghost mode ensures your conversations leave absolutely no trace on any device or server, automatically deleting all interaction data immediately upon session closure, perfect for highly sensitive discussions or confidential business matters.
  • Secure file upload and analysis capabilities: Upload and analyze documents, PDFs, images, and other files with complete confidentiality, as Lumo processes your files without storing their contents on servers or using them for model training, making it ideal for handling sensitive legal documents, business reports, or personal information.
  • Advanced code generation and programming assistance: Receive comprehensive coding help, debug assistance, and programming guidance while maintaining complete privacy of your project details, source code, and proprietary algorithms, ensuring your intellectual property remains protected throughout the development process.
  • Privacy-respecting web search integration: When enabled, Lumo can perform web searches through privacy-friendly search engines like DuckDuckGo, providing up-to-date information without compromising your browsing habits, search history, or creating detailed user profiles for advertising purposes.
  • Open-source foundation with community transparency: Built on trusted open-source AI models including Mistral Nemo, Mistral Small 3, OpenHands 32B, and Allen Institute for AI’s OLMO 2 32B, allowing independent security audits, community scrutiny, and verification of privacy claims through publicly available source code.

How It Works

Getting started with Lumo represents a paradigm shift in AI interaction, prioritizing privacy and user control while maintaining sophisticated functionality and ease of use.

Users can access Lumo through multiple channels including the web interface at lumo.proton.me, dedicated mobile applications for Android and iOS, or browser integration without requiring account creation for basic usage. The platform operates on a tiered access model: guest users receive limited weekly usage without any account requirements, free Proton account holders gain access to expanded functionality and encrypted chat history, while Lumo Plus subscribers enjoy unlimited conversations and premium features.

The technical architecture behind Lumo employs a sophisticated multi-model AI system that automatically selects the most appropriate open-source language model for each query type. Programming-related questions are processed by OpenHands which specializes in coding tasks, while general queries utilize models like Mistral Nemo or OLMO 2 32B based on complexity and context requirements. This intelligent routing ensures optimal performance while maintaining the privacy-first architecture.

All conversations undergo client-side encryption using Proton’s proven zero-access encryption technology before transmission to European-based servers operated directly by Proton. The system employs both TLS encryption for data transmission and asymmetric encryption for prompts, ensuring that only the GPU servers can decrypt queries during processing while maintaining complete privacy throughout the entire interaction lifecycle. Chat histories, when saved, are stored using the same encryption standards that protect Proton Mail and other Proton services, ensuring only the user can access their conversation history across devices.

Use Cases

Lumo’s unique combination of advanced AI capabilities and stringent privacy protection makes it exceptionally valuable across numerous sensitive and professional applications:

  • Confidential business strategy and competitive analysis: Develop business plans, analyze market opportunities, evaluate competitive positioning, and discuss sensitive corporate strategies without risk of data exposure to competitors or unauthorized parties, ensuring your proprietary business intelligence remains completely confidential.
  • Legal document analysis and professional consultation: Securely analyze contracts, legal briefs, regulatory compliance documents, and confidential client information while maintaining attorney-client privilege and professional confidentiality standards, with all document contents processed locally without server storage.
  • Healthcare and personal wellness discussions: Seek AI assistance for health-related questions, medical research, wellness planning, and personal health management without concerns about insurance implications, data brokers, or unauthorized access to sensitive health information.
  • Financial planning and investment analysis: Receive guidance on investment strategies, financial planning, tax optimization, and wealth management decisions while keeping your financial situation, assets, and investment plans completely private from data collection and profiling systems.
  • Creative and intellectual property development: Brainstorm creative projects, develop innovative concepts, write original content, and explore new ideas without fear of intellectual property theft, unauthorized usage, or your creative work being incorporated into training data for competing AI systems.
  • Academic research and scholarly work: Conduct sensitive research, analyze confidential data, prepare academic papers, and discuss preliminary findings while maintaining research integrity, protecting unpublished work, and ensuring compliance with institutional review board requirements and academic ethics standards.

Pros \& Cons

Lumo offers a compelling proposition for privacy-conscious users, but like any specialized tool, it comes with distinct advantages and considerations that users should understand:

Advantages

  • Industry-leading privacy architecture with proven technology: Unmatched zero-access encryption, comprehensive no-logging policy, and client-side processing ensure maximum privacy protection using battle-tested technology trusted by over 100 million users worldwide through Proton’s ecosystem of privacy-focused services.
  • Complete transparency through open-source development: Built on publicly auditable open-source AI models with fully transparent development processes, allowing independent security researchers, privacy advocates, and technical experts to verify privacy claims and identify potential vulnerabilities.
  • Flexible access options without mandatory registration: Immediate access without personal data disclosure, with optional account creation for enhanced features, ensuring users can maintain complete anonymity while still benefiting from advanced AI capabilities and optional feature upgrades.
  • Comprehensive file handling with enterprise-grade security: Secure document upload, analysis, and processing capabilities with Proton Drive integration, enabling professional and personal file analysis without data retention or unauthorized access risks.
  • European jurisdiction with robust legal protections: Operating under Swiss privacy laws and European data protection regulations, providing stronger legal safeguards against surveillance, data requests, and privacy violations compared to services based in other jurisdictions.

Disadvantages

  • Developing platform with evolving feature set: As a service launched in July 2025, Lumo continues expanding its capabilities and may lack some advanced features found in more established AI platforms, though this also means rapid innovation and user-focused development based on community feedback.
  • Usage limitations on free access tiers: Free and basic accounts include usage restrictions (25 queries weekly for guests, 100 for free accounts) that may not suit power users, though these limitations help maintain service quality while encouraging sustainable growth through optional subscriptions.
  • Limited integration ecosystem compared to established platforms: Unlike AI assistants from major technology companies, Lumo doesn’t integrate with extensive third-party services, productivity suites, or enterprise software ecosystems, focusing instead on privacy and core AI functionality.

How Does It Compare?

When evaluated against the current landscape of AI assistants in 2025, Lumo establishes a unique position through its uncompromising commitment to privacy and user data sovereignty, contrasting sharply with the data-dependent business models of major technology companies.

ChatGPT (2025): OpenAI’s ChatGPT remains the most widely recognized AI assistant with sophisticated capabilities, extensive integrations, and continuous model improvements. However, ChatGPT’s privacy practices have come under increased scrutiny in 2025, with CEO Sam Altman publicly warning users that there’s “no legal confidentiality” when using ChatGPT for sensitive discussions. Current privacy challenges include indefinite data retention policies, ongoing legal battles requiring OpenAI to preserve deleted conversations, and the use of user data for model training unless explicitly disabled. While ChatGPT offers more advanced capabilities and broader integrations, Lumo provides superior privacy protection for users who prioritize data confidentiality over feature breadth.

Google Gemini (2025): Google’s Gemini has evolved significantly with integration across Google services, advanced multimodal capabilities, and enterprise features through Google Workspace. However, Gemini operates within Google’s advertising-driven business model, where user data remains valuable for targeting and service improvement. While Gemini Advanced offers some enhanced security features for enterprise customers, it lacks the zero-access encryption and comprehensive no-logging policies that Lumo provides. Gemini excels in integration and functionality but cannot match Lumo’s privacy-first architecture and European legal protections.

Claude by Anthropic (2025): Anthropic’s Claude emphasizes constitutional AI principles and responsible development practices, with better privacy practices than many competitors. Claude for Work offers enterprise-grade security features and doesn’t use customer data for model training by default. However, Claude still operates under traditional cloud AI architecture where Anthropic can technically access user conversations, lacks end-to-end encryption, and doesn’t provide the zero-access privacy guarantees that Lumo delivers. While Claude offers sophisticated reasoning capabilities and ethical AI practices, Lumo provides superior privacy protection for users requiring absolute confidentiality.

Privacy-Focused Alternatives (2025): The privacy-conscious AI landscape includes various solutions like on-device AI models, privacy-proxy services, and specialized secure AI platforms. However, most solutions involve trade-offs between privacy and capability, require significant technical expertise, or lack the comprehensive feature set that Lumo provides. Lumo uniquely combines enterprise-grade privacy protection with user-friendly accessibility and comprehensive AI capabilities, backed by Proton’s proven privacy infrastructure and legal protections.

Enterprise AI Solutions: Business-focused AI platforms often provide better privacy controls and security features than consumer services, but typically require complex enterprise agreements, significant financial commitments, and technical integration expertise. Lumo democratizes enterprise-level privacy protection, making it accessible to individual users, small businesses, and organizations without extensive IT resources or budget constraints.

Final Thoughts

Proton Lumo represents a pivotal moment in the evolution of artificial intelligence, demonstrating that sophisticated AI capabilities and uncompromising privacy protection are not mutually exclusive goals. By combining Proton’s proven privacy expertise with cutting-edge open-source AI models, Lumo offers a compelling alternative to the surveillance-capitalism model that dominates the current AI landscape.

The platform’s technical architecture, built on zero-access encryption and comprehensive no-logging policies, addresses growing concerns about AI privacy while maintaining the functionality users expect from modern AI assistants. The July 2025 launch timing positions Lumo well to capture growing demand for privacy-conscious AI solutions as users become increasingly aware of the privacy implications of their digital interactions.

While Lumo may be a newer platform with evolving capabilities compared to established AI giants, its foundational commitment to privacy and transparency creates a sustainable competitive advantage that larger platforms cannot easily replicate due to their existing business model dependencies on user data. The open-source foundation ensures long-term transparency and community-driven improvements that benefit user privacy and security.

For individuals, professionals, and organizations who value digital privacy, handle sensitive information, or operate in regulated industries, Lumo provides an invaluable service that enables AI-powered productivity without compromising confidentiality. The flexible pricing model, from free guest access to premium subscriptions, ensures that privacy-focused AI assistance remains accessible regardless of budget constraints.

As artificial intelligence becomes increasingly integral to personal and professional workflows, Lumo’s privacy-first approach represents not just an alternative to existing platforms, but a glimpse into a more sustainable and user-centric future for AI development. The platform’s success could influence broader industry practices and demonstrate that privacy-respecting AI is not only possible but preferable for users who understand the long-term implications of data sovereignty in the digital age.

Meet Lumo, the zero-access encrypted AI assistant by Proton that does not track or record your conversations. Ask me anything — it
lumo.proton.me