← Feed
@dazo@infosec.exchange
Post #3897199
2026-07-17 22:48 UTC
@NetscapeNavigator@social.vivaldi.net @frankps@mastodon.babb.no @jon@social.vivaldi.net
In plain English, explained by Lumo
Here's what that clause means in plain English:
Where disputes get resolved
If you live in the U.S. and use this service:
In Switzerland: Any lawsuits filed there must use Swiss law and be handled by courts in Geneva.
In the U.S.: Any lawsuits filed there use the laws of whatever U.S. state you live in.
What this covers
This applies to basically any dispute related to the Terms of Service or your account—including:
• Contract issues
• Warranty claims
• Tort claims (like negligence)
• Violations of laws or regulations
• Communications with the company
Basically, any legal disagreement connected to using their service falls under this rule.
Arbitration
If the dispute goes to arbitration (instead of court), it follows:
• The U.S. Federal Arbitration Act
• American Arbitration Association's Consumer Rules
• Electronic documents
Digital versions of the Terms and notices count as valid evidence in court just like paper documents would.
Why this matters for you
This means you could potentially face litigation in Switzerland, but if a case is heard in the U.S., local state laws apply. It's a common clause in international companies' terms—they try to preserve some control over how disputes are handled while acknowledging they can't force U.S. residents into foreign courts beyond what U.S. law allows.
ChatGPT concluded quite similar, but added this clarification:
What this means in practice
The company is trying to cover multiple situations:
• Swiss courts + Swiss law if a case is brought in Switzerland.
• U.S. courts + your state's law if a case is properly brought in the United States.
• U.S. arbitration rules if the dispute is subject to arbitration.
The first sentence doesn't necessarily mean every dispute must be heard in Switzerland. It says you consent to the jurisdiction of Geneva's courts, meaning you agree those courts are an acceptable place to hear disputes. The later language also recognizes that some disputes may proceed in U.S. courts if those courts have jurisdiction.
So, despite the company being based in Switzerland, a U.S. consumer may still be able to bring certain claims in the U.S., depending on the nature of the dispute, the rest of the agreement (especially the arbitration clause), and applicable law. The key part to review is the referenced Section 13.1, because if it requires binding arbitration, that may prevent either side from filing most lawsuits in court except in limited circumstances.
Replies (1)
-
@NetscapeNavigator@social.vivaldi.net
To ease your mind a bit more. Almost everything in Proton is end-to-end encrypted. The exception is e-mail headers, which in most cases can't easily be encrypted to make the e-mail delivery work (SMTP protocol in practice). The Subject field does not have a formal standard for being encrypted, so that's the field to be cautious with.
Everything else is encrypted in a way which makes it impossible for Proton to extract data from your account. Unencrypted Incoming e-mails has a risk to be captured before Proton encrypts it when storing it to disk. Similar with sending unencrypted emails to non-Proton accounts. All mails between Proton users (and external domains supporting WKD) gets encrypted on your client side before it hits the network. Similar for contacts where you have added the recipient's public PGP key to the contact in the Proton Contacts register.
One risk factor is account recovery processes. If you use the passphrase and/or the file based recovery methods only, you're safe. If you have enabled e-mail or phone recovery, you have a potential break-in path this way.
Proton claims there is no need for it, but you can also enable a "second password". Without this, Proton will derive a passphrase used to unlock the encryption keys from your login password. Enabling "second password" mode adds a disconnect between the login password and the encryption key. When logging in with this enabled, you will have username/password auth, twon-factor auth and then the second password. Enabling this will also require creating a new recovery passphrase and/or recovery file.
But as always with these things, keep a good backup of these passwords, 2FA backup codes and recovery phrase/file. And don't store this inside Proton. If you can't access the Proton service storing it, you've locked yourself on the outside while keys being in the inside.
So even if US government decides to want to look into your Proton account, your still well protected until you porovide them access. That's where threat modelling comes intok play to have a plan for various scenarios applicable for you.
@frankps@mastodon.babb.no @jon@social.vivaldi.net
Open ##3897705