Skip to content

Privacy · research january to july 2026 · published 2026-08-03 · v1 · 3 min read

Privacy is a different product

A system that cannot read your words cannot search them for you, so the private version is a second product rather than a setting

Why a private version of a product is a second product rather than a setting, and what an honest presentation of that choice owes the person making it. The canonical treatment of the plaintext condition.

In brief
The problem

verified

Every claim this passage rests on has been checked against its sources.

  • "Our platform architecture documentation states that end-to-end encryption and server-side AI processing are mutually exclusive and cannot both be had at once."

    verified. The document's own executive summary, quoted in its own terms; the phrase is the source's wording rather than a paraphrase of what it measured.

Open the complete evidence in the structured publication.

Products present a private mode as a switch inside one product, which implies everything else survives the switch, and everything else does not survive it wherever the intelligence runs on a server.
The mechanism

verified

Every claim this passage rests on has been checked against its sources.

  • "Proton Mail builds its message content search index in the browser and the index never leaves the device."

    verified. Proton's own engineering write-up and support documentation for message content search.

Open the complete evidence in the structured publication.

Encryption removes the readable text that server-side intelligence consumes, so the private version and the capable version are two products rather than two settings of one, and the control between them is a boundary.
The move

position

This is the publication's stated position, not an empirical claim. It rests on the argument rather than graded evidence.

Open the complete evidence in the structured publication.

Price the fork inside the interface, naming which capability degrades, by roughly how much, and on whose measurement rather than on nobody's.

A privacy setting implies that the product on either side of it is the same product. Flip it on, keep everything you had, lose only the part where a company can read your files. That implication is false wherever the intelligence runs on a server, and it is false for a reason no engineering budget reaches.

Server-side intelligence has to read what it works on. An embedding model reads the text before it makes a vector of it. A search index reads the text before it can rank it. A database cannot match a pattern inside a blob it holds no key for, and a distance operator cannot measure between two things it cannot decode. End-to-end encryption is precisely the decision that the server holds no key. So the mechanism is a subtraction rather than a dial: encryption removes the readable text that server-side intelligence consumes, which makes the private version and the capable version two products rather than two settings of one, and the control between them a boundary.

Proton ships the honest form of this and documents it in public. Message content search in Proton Mail is built in the browser and the index never leaves the device, because the server holds every message in a mailbox and no key to any of them, while the client can decrypt anything it holds but never holds the whole mailbox at once. The consequences appear in Proton’s own support pages rather than in someone else’s review. The index is bounded by what the browser will store, so a large mailbox displays a date past which its own contents cannot be searched, and a person on an older machine waits while the index builds. None of that is a defect. It is the product that end-to-end encryption makes possible, described accurately by the people who built it.

Our own architecture notes reach the same finding in blunter language, that end-to-end encryption and server-side processing are mutually exclusive and cannot be had at once, alongside a figure for how far on-device search would fall short of the server-side path. We grade that figure as what it is. It is an engineering estimate written down before anyone measured it, and the capability it describes is not something we ship; the design sits in our documentation under an explicit ruling that it is not an active product claim. That is the part worth keeping. A fork you have not built is still a fork you can describe honestly, and describing it honestly now is what stops a flattering sentence from being written about it later.

The trade underneath is not really cryptographic. Someone choosing the private version is exchanging search that finds the thing they half remember for the certainty that nobody else can find it at all, and both of those are real goods whose prices move with what a person is carrying that year. The dishonesty is never in the tradeoff. It is in the checkbox, because a checkbox is a claim about size, and it says the thing on the other side is small. Price the fork out loud, name the capability that degrades and by roughly how much and on whose word, and the choice stops being something done to a person and becomes the thing it always was, someone deciding what their own words are for.

Evidence and lineage

Research trail

Follow the sources, inspect how the claims are graded, or propose a correction at the exact record it concerns.

Sources 2
  1. Proton AG (2021). Behind the scenes of Proton Mail's message content search, and the message content search support documentation

    The shipped public case. A production end-to-end encrypted mailbox that builds its content search index in the browser, publishes why a server-side equivalent is not available to it, and prints the resulting limits in its own support pages rather than leaving them to reviewers.

    Comment on this source
  2. MNSTRY platform documentation (2026). Privacy modes architecture, and E2EE memory (Secret mode)

    The internal source. States the exclusivity finding directly and carries the on-device search estimate the brick grades as an estimate. Both documents sit under the 2026-07-11 operator ruling that local-first delivery is reversibly mothballed, which is why the brick claims no shipping capability.

    Comment on this source
Claims and confidence 6
  1. verified

    Our platform architecture documentation states that end-to-end encryption and server-side AI processing are mutually exclusive and cannot both be had at once.

    The document's own executive summary, quoted in its own terms; the phrase is the source's wording rather than a paraphrase of what it measured.

    Respond to this claim
  2. verified

    Encrypted content columns cannot be searched with SQL text operators, ranked by vector distance operators, or indexed, because each of those operations requires reading the stored value.

    Follows from the construction, and set out at length in the same architecture document's rejection of column-level encryption.

    Respond to this claim
  3. verified

    Proton Mail builds its message content search index in the browser and the index never leaves the device.

    Proton's own engineering write-up and support documentation for message content search.

    Respond to this claim
  4. verified

    Proton Mail's client-side index is bounded by the browser's storage capacity, so a large mailbox displays a date past which its own contents cannot be searched.

    Proton's support documentation, which states the limit and the displayed date.

    Respond to this claim
  5. directional

    Our internal documentation estimates on-device search quality in a local-only mode at roughly 70 to 85 percent of the server-side hybrid path.

    A comparison table in the internal Secret-mode document. It is an engineering judgment recorded during design, with no benchmark, dataset, or measurement procedure attached, which is why the brick names it as an estimate and does not print the figure as a finding.

    Respond to this claim
  6. verified

    The local-first and end-to-end-encrypted capability described in our privacy-mode documentation is reversibly mothballed by operator ruling and is not a shipping capability.

    The 2026-07-11 launch-posture ruling carried at the head of both source documents, which states that the launch profile is online-required and server-authoritative.

    Respond to this claim

Read next

Or survey the topics.

Concepts in this piece 1

Add to the work

Contribute to Privacy is a different product

Write the useful part. Identity, provenance, and review history are attached when you submit. The published source stays unchanged.

Target Privacy is a different product

Contribution intent
Use an agent instead

The interface is ready. Public authenticated intake remains off until the hosted migration and feature flag are deployed together.