Proton Lumo: what privacy-friendly AI looks like
Open models, its own servers, encrypted chats: Lumo 2.0 shows what confidential AI looks like. Two catches remain.
Analysis · Published 9 Jul 2026 · Updated 24 Aug 2026 · Joel Barmettler
What is Lumo?
Lumo is the AI assistant you can entrust with confidential material without it reaching the provider. The Geneva company Proton, known for Proton Mail, runs open models such as GLM-5.2 exclusively on its own servers in Europe and encrypts chats so that not even Proton can read them. Two limits remain: web search queries go to external search engines, and an API for your own processes is missing.
In brief
- You can adopt the pattern behind Lumo for your own AI: open models, self-operated, in Europe.
- You no longer need to accept the usual objection to private AI. The model behind it sits ahead of Google’s Gemini 3.5 Flash on the intelligence index.
- If you are researching sensitive topics, switch off web search. The queries go to external search engines that Proton does not name.
- Lumo cannot yet be used for your own tools and business processes, because the API is missing (as of July 2026, announced).
At the end of June, Proton released version 2.0, with a reasoning mode, image generation, memory, a doubled context window and markedly better web search. More important than any single feature, though, is the new model underneath: Lumo had been exemplary on confidentiality but too weak for daily use. GLM-5.2 closes most of that gap.
In advisory mandates, we rarely recommend specific products. With Lumo, we make an exception: no other service currently demonstrates as visibly that capable AI without data leaving your control is possible.
This is the final part of our series “Provider Data-Protection Check”, and it shows the counter-model to the four large providers before it.
Who is behind Lumo
Proton was founded in Geneva in 2014 by CERN researchers and financed by crowdfunding; the company became known for the encrypted Proton Mail. Since 2024, the majority of Proton AG has belonged to a non-profit Swiss foundation whose board includes web inventor Tim Berners-Lee, among others. An acquisition against the foundation’s purpose is therefore practically ruled out.
The ownership structure is part of the security question. You entrust an AI assistant with more intimate matters than any search engine; whether the provider still holds the same values in five years therefore matters too. A non-profit foundation as majority owner is one of the few answers to that which actually holds up.
What Lumo gets right
The architecture is documented and consistent. Under the hood run open models, among others GLM-5.2 and Qwen 3.5, exclusively on servers that Proton itself controls, in Europe. No prompt lands with a third-party provider; the one exception, web search, comes further below. The chat history is encrypted zero-access: only your device can read it, not Proton. According to Proton, requests are deleted after the response, metadata such as IP addresses or timestamps are not stored in the first place, and your chats are not used for training either.
If you know our article on LLM costs, you will recognise the principle: open models, including Chinese ones, are not a risk as long as you control where they run. Proton buys in the intelligence and keeps the operation. Companies can do exactly the same.
How strong is the model?
The usual objection to private AI is: nice, but weak. With Lumo, it no longer holds.
Key figure
51 pointsSource: Artificial Analysis, Intelligence Index v4.1, July 2026
Here is how GLM-5.2 ranks among the best-known models:
The gap downward is notable too: Mistral Medium 3.5, the strongest model developed in Europe, sits 21 points behind GLM-5.2. The comparison is only half fair, because Mistral trains its own models, while Proton downloads and operates a model trained in China. That, though, is exactly the point: open models make top-tier performance available to anyone who can operate them sovereignly. Europe does not need to train the best model to offer confidential AI at world level.
The same approach already exists in Switzerland: Infomaniak, the Geneva provider behind the Euria assistant, offers Kimi K2.6 through its AI API, level with DeepSeek in the chart. Here too: open model, Swiss operation.
The first catch: web search
At one point, the system necessarily leaves the encrypted world: web search. When switched on, search queries go to external search engines. Proton states that it selected the providers for privacy, performance and reliability, but does not name them.
From an advisory perspective, that is not enough. On sensitive topics, search queries reveal almost as much as the chat itself. If the index behind the search is Google’s or Bing’s, part of your question travels straight to the very corporations you were trying to avoid with Lumo. Until Proton discloses the providers, the rule for confidential topics is: web search off. It can be switched off per conversation.
The second catch: still no API
Lumo is available as a web app and for iOS and Android, and recently also as a business version for teams. What is missing is an interface: Proton has announced an official API for 2026; as of July, it does not exist yet.
For business use, that means concretely: Lumo cannot be integrated into coding tools such as OpenCode, nor into your own business processes, products or agentic applications. It is an assistant for people, not a building block for systems. The unofficial API wrappers circulating in the community are off-limits for sensitive data: they sit outside the guarantees you choose Lumo for in the first place.
Once the API arrives, its pricing model will decide. For agentic tools, prompt caching matters more than the token price, because coding assistants send the same context hundreds of times; without discounted cache hits, that becomes expensive fast (the maths is in our article on LLM costs). If both hold, Lumo also becomes interesting as a component: for coding tools such as OpenCode, with GLM-5.2 as the engine, entirely on sovereign infrastructure.
What this means for your company
For individuals, Lumo is today a clear recommendation. For companies, it is two things: a good tool for employees who need a confidential assistant, and above all, proof. The pattern behind Lumo, top-tier open models on controlled European infrastructure, is one you can adopt for your own AI: with your own data, your own tools and an API that belongs to you.
That closes the provider series. The four parts before it review OpenAI, Anthropic, Google and Microsoft against the same grid.
Frequently asked questions
- What is Lumo?
- Lumo is the private AI assistant from Proton, the Geneva company behind Proton Mail. Version 2.0, released at the end of June 2026, added reasoning, image generation, memory and better web search. Lumo runs exclusively open models on its own servers in Europe; chats are encrypted zero-access, are not logged and are not used for training.
- How privacy-friendly is Lumo, really?
- The architecture is built for confidentiality: its own European servers, zero-access-encrypted chats, no logs, no training on user data, and a non-profit foundation as majority owner. The documented exception is web search: when it is switched on, search queries go to external search engines that Proton does not name.
- Which AI model powers Lumo?
- Proton documents the models openly: among others GLM-5.2 and Qwen 3.5, both open models that run exclusively on Proton's servers. GLM-5.2 scores 51 points on the Artificial Analysis Intelligence Index (as of July 2026), placing it ahead of Google's Gemini 3.5 Flash.
- Does Lumo have an API?
- No, as of July 2026 there is no official interface; Proton has announced a Lumo API on its roadmap. Until it appears, Lumo cannot be integrated into your own applications, coding tools or business processes, and can only be used through the apps and the browser.
Share this article
Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.
Suggested post
Looking for an AI assistant your people can trust with confidential material too? The usual objection is that private AI is the weaker AI. That assumption no longer holds. GLM-5.2, the model behind Proton's Lumo, scores 51 points on the Artificial Analysis Intelligence Index v4.1 (as of July 2026), ahead of Google's Gemini 3.5 Flash and nine points behind the flagship. It runs on Proton's own servers in Europe: chats encrypted zero-access, no logs, no training on user data, majority owned by a non-profit Swiss foundation. Two limits remain. With web search switched on, queries go to external search engines that Proton does not name. And an official API is still missing, so Lumo is an assistant for people, not a building block for systems. Our conclusion: the pattern matters more than the product. Proton does not train its own model; it downloads an open one and keeps the operation. Swiss companies can do exactly the same, with their own data and an interface that belongs to them. Infomaniak shows how, with Kimi K2.6. The article covers the sovereignty grid for Lumo and six questions you should ask every assistant your team wants to use. Link in the comments. #AI #DataProtection #Proton #Switzerland