If you have ever pasted a sensitive document into ChatGPT and then wondered, in the small hours, what happened to it, Proton’s pitch for Lumo 2.0 is built for you. On June 30, 2026, the Swiss company behind Proton Mail and Proton VPN shipped a full rewrite of its AI assistant, leaning hard on the language of encryption, European infrastructure, and a refusal to train on your chats. Per TechCrunch, the new version is also fast enough that the privacy case no longer has to come with an apology about quality.
For most readers who care about privacy, the obvious question is whether the claim is real or whether it is marketing that falls apart the moment a model has to look at your text. Lumo 2.0 is a useful test case for that question, because Proton publishes the parts that matter: what is encrypted, what is not, where the servers live, and whether the code can be inspected.
What’s Actually New
The headline numbers come straight from Proton. On the Artificial Analysis Intelligence Index, Lumo 2.0 Lite scores 127% higher than Lumo 1.4, and Lumo 2.0 Max scores 240% higher, per the Proton blog. Proton also says everyday queries are up to 76% faster than the prior generation. That last number matches what TechCrunch found in its hands-on, where the new Lumo was called out as feeling closer to ChatGPT and Gemini in speed.
The feature list is closer to a mainstream assistant than to the walled-off privacy niche. Lumo 2.0 now handles image generation and image editing, has a “Thinking” mode for harder reasoning, ships with a live web search that returns cited sources, and lets users pin persistent memory across sessions. There are three tiers: a free version, Lumo Plus for individuals, and Lumo Professional aimed at teams. Proton did not publish dollar prices on the launch page, only the tier descriptions.
What is genuinely different from the rest of the consumer chatbot market sits underneath those features. Proton says every conversation, uploaded image, generated image, Memory entry, and Project file is wrapped in zero-access encryption, the same scheme it uses for Proton Mail and Proton Drive. The promise is that Proton itself cannot read the contents, because the keys live on the user’s device. As Proton puts it: “Images you upload and the images Lumo generates are stored so that no one, not even Proton, can access them.”
The other structural claims are equally specific. Lumo runs on Proton’s own European infrastructure, governed by Swiss privacy law. The Lumo client is fully open source, so “anyone can inspect the code, verify the encryption, and confirm it works exactly as we say,” per Proton. Proton says it never logs conversations and never uses them to train future models.
Where the Privacy Promise Stops
A few honest caveats are worth flagging before readers swap ChatGPT for Lumo. The first is the architecture of large language models themselves. To generate a reply, an LLM has to read the prompt. Zero-access encryption protects the chat at rest, in transit, and from Proton employees. It does not, and cannot, hide the text from the model that is producing the answer at that moment. Proton acknowledges this implicitly in its own architecture: the data is encrypted in storage, but inference has to happen on hardware that sees the decrypted prompt. What you are trusting is that the hardware is in Switzerland, that logs are off, and that the model itself does not silently retain your input. None of those are cryptographic guarantees. They are operational ones.
The second caveat is provenance. Proton does not name the underlying model in its launch materials. Lumo 2.0 ships in Lite and Max variants with different reasoning modes, which suggests more than one base model, but Proton does not publish a model card or training-data lineage for either. Readers who care about privacy often also care about open weights, and on that score Lumo is not in the same category as a self-hostable model like Llama or Mistral. Proton’s privacy boundary is about who can read your chats, not about which weights are running them.
The third caveat is the open-source claim. The Lumo client is open source, which means the encryption code, the prompt handling, and the network calls can be audited. The model itself is not, and the server-side runtime is not. A reader who wants to verify the full stack end to end still has to take Proton’s word for parts of it.
None of those caveats invalidate the launch. They just narrow what Lumo 2.0 is. It is a hosted, encrypted, European-hosted chatbot that does not train on your data and does not log your sessions. It is not a self-hosted local model. The two are easy to confuse because they share a marketing vocabulary, and it helps to keep them separate.
What This Means
For most readers, the practical question is simpler than the architecture diagrams make it look. If you use AI for casual questions, Lumo 2.0’s privacy story is mostly upside compared with ChatGPT, Gemini, or Claude, with the usual loss in raw capability that a smaller lab has to accept. If you regularly paste in anything sensitive - medical notes, source code under NDA, internal documents, anything you would not want to surface in a future subpoena - Lumo is closer to the right tool than the default consumer assistants, especially given the Swiss jurisdiction and the no-training guarantee.
For privacy-focused users who want more, the local-AI path remains stronger. A self-hosted model on your own hardware does not need a Swiss data center at all; the data never leaves your desk. Lumo 2.0 is the right answer for people who want a polished chatbot with serious privacy defaults and do not want to run their own GPU.
For the broader market, the more interesting effect is competitive. Lumo 2.0 is now fast enough and capable enough that “privacy-first AI” no longer has to mean a degraded experience. That puts quiet pressure on the major U.S. labs, whose privacy postures mostly amount to toggles and trust-us copy. If Proton can run a competitive assistant on encrypted storage with European infrastructure and open-source clients, the argument that privacy and quality are in tension gets weaker every quarter.
The Bottom Line
Proton Lumo 2.0 is a real step forward for privacy-respecting AI, not a relaunch of the same product. The encryption story is concrete, the speed story is real, and the jurisdictional story is honest. It is also not a substitute for a self-hosted local model. For most readers, though, it is the most credible non-mainstream chatbot available today, and it is worth a serious try.