Proton Mail vs HEY for Privacy: Encryption or Anti-Tracking?

The short answer
Neither wins outright. Proton Mail protects stored mail with zero-access encryption, so your provider cannot read it. HEY protects you from senders, stripping spy pixels and screening first contact, but holds your keys. Pick Proton if your adversary is anyone who reaches the mailbox; pick HEY if it is the sender.
Proton Mail vs HEY for privacy: zero-access encryption protects stored mail from your provider; HEY blocks spy pixels. Different threats, one honest verdict.
On this page
- 01The verdict up front
- 02Proton Mail vs HEY: the privacy claims at a glance
- 03Where Proton Mail wins: zero-access encryption, explained simply
- 04Where HEY wins: it treats the sender as the adversary
- 05Is HEY email private without encryption?
- 06The axis nobody compares them on: your protection ends at the app
- 07Pricing model: verify the shape on the vendor's page
- 08Who each one is genuinely for
- 09A third option, honestly — and where it does not apply
- 10How to decide in ten minutes
Proton Mail vs HEY for privacy is a comparison people lose because they never name the adversary. These two services solve different privacy problems, and each is close to useless against the other one's threat. Proton Mail encrypts your stored mail so that Proton itself cannot read it. HEY encrypts nothing end to end and says so openly — its privacy work is aimed at the sender, stripping the spy pixels and tracking that tell a marketer when, where and how long you read.
So the question is not which one is more private. It is which of those two things you are actually trying to stop. This post separates the claims, names a winner per threat model, and is honest about where a third kind of tool — including ours — does and does not belong in the conversation.
All vendor capabilities below were checked against Proton's and HEY's own live documentation in September 2026. Both companies ship changes often, so verify anything you are about to pay for on the vendor's page before you buy.

The verdict up front#
If your concern is who can read your mail once it has arrived — your provider, an employee with database access, an attacker who gets a backup, a government that subpoenas the host — Proton Mail wins, and it is not close. Zero-access encryption means the stored message body is encrypted with a key Proton does not hold. HEY states plainly that it still technically holds the key to all email, because there is no end-to-end encryption.
If your concern is surveillance by the people emailing you — open tracking, read receipts you never agreed to, location leaked through image loading, a stranger getting into your inbox at all — HEY wins on completeness, though by less than its marketing implies. HEY strips spy pixels and then tells you who planted them and which tool they used. Its Screener holds every first-time sender until you say yes or no. Proton blocks trackers too, and blocks them by default, but it has no equivalent of the Screener.
Here is the concession that matters, stated by name: on anti-tracking, Proton Mail is genuinely competitive, and anyone claiming HEY is the only inbox that stops spy pixels is out of date. Proton's tracking protection is on by default, removes spy pixels, and proxies remote images so the sender never sees your IP address — the same core mechanism HEY built its reputation on. HEY's advantage is the surrounding workflow, not the pixel blocking itself.
Proton Mail vs HEY: the privacy claims at a glance#
Every row below is a claim each vendor makes on its own site, not a score we assigned. Read it as a map of what each product is for.
| Privacy question | Proton Mail | HEY |
|---|---|---|
| Can the provider read your stored mail? | No — zero-access encryption on message bodies and attachments | Yes, technically — HEY states it holds the key and access is possible under an audited internal process |
| End-to-end encryption | Yes, automatically between Proton users; password-protected messages for outside recipients | No, and it argues against it — email cannot control what the recipient uses |
| Encryption that does exist | Zero-access at rest, plus TLS in transit | At rest, at work and in transit, per its security page |
| Spy pixel blocking | Yes, enabled by default on web, iOS, iPadOS and Android | Yes, and it names the sender and the tracking tool it detected |
| Remote image handling | Proxied through a generic IP and location rather than blocked | Proxied through HEY's own servers so your IP never leaks |
| Link tracking parameters | Stripped on the web app (UTM and other known trackers) | Not advertised as a separate feature |
| Screening unknown senders | Standard spam filtering; no approve-or-block gate | The Screener — every first-time sender is held until you decide |
| Unencrypted metadata | Subject lines, sender and recipient addresses are encrypted but not end-to-end encrypted | All metadata is readable by HEY, as is the mail itself |
| Third-party client access | IMAP/SMTP via Proton Mail Bridge on paid plans | None — no IMAP, no POP, HEY's own apps only |
| Jurisdiction and code | Switzerland; apps open source and independently audited | United States; closed source |
Where Proton Mail wins: zero-access encryption, explained simply#
Zero-access encryption means this: when a message lands on Proton's servers, it is encrypted with your public key before it is stored. The private key that unlocks it is derived from your password and lives on your device. Proton can hold the ciphertext for years and still not be able to open it.
That single design choice is what changes the threat model. A stolen backup is useless. An insider with production database access sees encrypted blobs. A legal demand to Proton for the contents of a mailbox cannot be satisfied by Proton handing over something it can read.
End-to-end encryption is the stricter sibling and only applies between two Proton users, where the message is encrypted on the sender's device and decrypted on yours — nothing readable exists anywhere in between. Mail to and from the rest of the internet still arrives over TLS in plaintext and is only then locked away with zero-access encryption.
Be precise about the limit, because Proton is. Subject lines, sender addresses and recipient addresses are encrypted but not end-to-end encrypted, because OpenPGP puts the subject in the header packet. Proton's own documentation says access to those would require a court order approved by a Swiss judge. That is a meaningfully high bar and it is not the same as impossible.
What zero-access encryption does not protect
Where HEY wins: it treats the sender as the adversary#
HEY's bet is that for most people, the realistic privacy violation is not a server breach. It is that every newsletter, recruiter and sales sequence they receive is instrumented, and they never consented to any of it.
The spy pixel blocker is the visible part. HEY strips the known tracking patterns, including one-by-one images and trackers hidden in markup, and then does something Proton does not: it tells you who tried to track you and which email tool they used. That turns an invisible problem into a legible one, and it changes behaviour — you start noticing which senders treat you as a metric.
Images are routed through HEY's own servers, so even a tracker it fails to classify never sees your IP address or your approximate location. Proton uses the same proxy idea with a generic IP and geolocation, so on this specific mechanism the two are close to level.
The Screener is where HEY is genuinely alone. Every first-time sender is parked outside your inbox until you approve or reject them, and a rejection means you never see that sender again. Proton has spam filtering and blocking, but spam filtering guesses; the Screener asks. If your privacy problem is 'strangers keep getting a channel to me', that is an architectural answer no amount of encryption provides.
HEY also splits arrivals into the Imbox for real correspondence, the Feed for newsletters and long reads, and Paper Trail for receipts. That is a productivity feature, but it has a privacy effect: bulk senders end up somewhere you read deliberately rather than somewhere that interrupts you.
Is HEY email private without encryption?#
Partly, and HEY is unusually straight about which part. Its security page says data is encrypted at rest, at work and in transit, and then says the quiet thing out loud: HEY still technically holds the key to all email, because there is no end-to-end encryption, and someone at HEY could access your data if they jumped through the right hoops.
HEY's argument is that end-to-end encryption is a poor fit for email, because you do not control what app or service the recipient uses — encrypt a message to someone on Gmail and Google reads it anyway. That is a fair critique of email as a protocol, and it explains why HEY spent its effort elsewhere.
It is also a real gap, not a marketing quibble. If your threat model includes the provider itself, a compelled disclosure, or a breach that reaches storage, HEY's design does not defend you and does not claim to. Proton's does.
Pick the adversary before the product
The axis nobody compares them on: your protection ends at the app#
Both privacy stories are enforced by the client, not by the mailbox, and both quietly stop working when you leave the vendor's own app. That is the part most comparisons skip, and it decides more real-world outcomes than the encryption argument does.
Proton's tracking protection is documented for web, iOS, iPadOS and Android, and the setting does not sync between devices — you enable it per device. Connect the same account to a desktop client through Proton Mail Bridge and you are back to that client's image handling. Your mail is still stored with zero-access encryption; your anti-tracking is not travelling with it.
HEY solves this by refusing to let you leave. There is no IMAP and no POP, so HEY mail can only be read in HEY's apps, which is exactly why its protections are never bypassed. It is a coherent design and a hard lock-in: no third-party client, no consolidating HEY with your work account elsewhere, and migration out means forwarding and exports rather than a sync.
So the honest framing is that both products protect the mail you read where they intend you to read it. Neither protects the other five accounts on your phone, and neither can protect a mailbox that another client is also opening.
Pricing model: verify the shape on the vendor's page#
We do not print competitor prices, because they change and a stale number is worse than none. What is stable enough to plan around is the shape of each offer, as published in September 2026.
Proton Mail offers a free plan with limited storage and one address, then paid tiers — Mail Plus and the broader Proton Unlimited bundle — which add storage, extra addresses and custom domains. Bridge, and therefore IMAP/SMTP access from a desktop client, is a paid-plan feature.
HEY has no free plan. It sells HEY for You, a personal @hey.com address billed annually with a 30-day trial that does not ask for a card; HEY for Domains for a custom domain, billed monthly per user with no trial; and HEY for Families, which adds people to one annual account.
The practical difference is commitment. Proton lets you keep a free address indefinitely and upgrade later. HEY asks for a full year up front on the personal plan, which is a reasonable ask for a product whose whole value shows up in the first fortnight — and is exactly why the 30-day trial exists. Use it properly rather than skimming it.
Who each one is genuinely for#
- Choose Proton Mail if your risk is the host: journalists, activists, lawyers, founders handling deal documents, anyone whose stored archive is the sensitive asset. Also choose it if you want open-source, audited apps and a jurisdiction chosen for privacy law.
- Choose HEY if your risk is the sender: you are drowning in instrumented newsletters and cold outreach, you want strangers held at the door by default, and you want to see who tried to track you. Accept in exchange that HEY can technically read your mail.
- Choose Proton if you need a third-party client, a custom domain on a cheap tier, or any workflow that requires IMAP. HEY has no IMAP at all, and that is a design decision, not a roadmap gap.
- Choose HEY if you want one opinionated app on every platform including Linux, and you would rather change your habits than configure filters.
- Choose neither, yet, if your mail already lives in Gmail or Microsoft 365 for work. Neither product improves the privacy of an account you cannot move — see the next section for what does apply.
A third option, honestly — and where it does not apply#
We build AI Emaily, so treat this section as what it is: the makers explaining where their product sits. It is not a competitor to Proton on this question, and saying otherwise would be the easiest claim on this page to disprove.
AI Emaily is a client, not a mail host. It connects to Gmail, Outlook and IMAP accounts you already own. It cannot give you zero-access encryption of a Gmail mailbox, because Google holds that mail — no client can. If encryption at rest against your provider is the thing you need, move to Proton; that is the correct answer and we are not going to dress up a different one.
It also cannot connect to HEY, because HEY publishes no IMAP or POP access. Proton connects through Proton Mail Bridge on a paid plan, with the caveat above that Proton's own tracking protection stays in Proton's apps.
What does carry across is the sender-side protection, applied to the accounts most people actually cannot leave. AI Emaily blocks remote tracking pixels in the mail it renders, filters cold outreach by sender behaviour and domain rather than a single address, and treats message content as untrusted input to the agent so that instructions buried in an email cannot steer it. Every send goes through approval first, with undo and an audit trail, and your mail is never used to train models.
The voice side works the same way — from a Personal Context brain you write and per-client profiles you set, not from scraping your sent mail. Packaging is a 7-day free trial on Pro or Autopilot, card required, nothing charged if you cancel before day seven.
Short version: if the mailbox itself must be unreadable to its host, Proton. If strangers and trackers are the problem and you can move your address, HEY. If you are staying on Gmail or Outlook and want the sender-side half of that protection plus an agent that triages and drafts, that is the job we do.
How to decide in ten minutes#
- 1
Name the one thing you are stopping
Write a single sentence: 'I do not want X to be able to read or learn Y.' If X is a company or a court, you need encryption. If X is the person emailing you, you need anti-tracking.
- 2
Check whether you can move your address at all
If your mail is a work account on Google Workspace or Microsoft 365, neither Proton nor HEY is available to you for that address. Solve for the client and the filtering instead.
- 3
Test the thing that is hardest to reverse
For HEY, that is the no-IMAP lock-in and the annual personal plan — use the 30-day trial to confirm you can live inside one app. For Proton, it is whether Bridge fits the desktop workflow you actually use.
- 4
Re-read both vendors' pages before paying
Encryption claims and plan shapes here were verified in September 2026. Proton's support site and HEY's security page are the only authorities on their own current behaviour.
Frequently asked
See it in AI Emaily
Keep reading

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.