You left Gmail, or Chrome, or Google Drive because one company knowing everything about you felt wrong. So you picked a privacy-focused provider instead — encrypted mail, no ads, no tracking. Then their VPN was one click away and bundled at a discount, so you added it. Then their password manager showed up as an upgrade prompt. Then their cloud storage, because it was already included in the plan you were already paying for.
Nothing about any single step was a bad decision. But look at what you've built: one company now holds your identity, your browsing habits, your saved passwords, and your files. The lock on that basket is a lot better than Google's ever was. It's still one basket.
This isn't about whether the encryption works. Good privacy companies build real encryption, and that protects you against outsiders — hackers, opportunistic snooping, a stranger on the same Wi-Fi. What changes when everything sits under one provider is what happens when someone with legal standing asks that company, not an attacker, for something.
A breach exposes whatever that company holds — which, if it's your everything-provider, is no longer just an inbox. A legal order compels that company to hand over whatever it has and is legally required to hand over, and if your password vault, your VPN activity, your files, and your email are all one account, "whatever it has" now covers a lot more ground than it used to. None of that requires the company to be careless or dishonest. It just requires one request, aimed at one place, to matter more than it used to.
Proton is a useful, real example of this pattern — not because its security is weak (it isn't), but because its own product lineup shows exactly how a single-purpose privacy company becomes a full stack. Proton started as encrypted email in 2014. Since then it's added a VPN, a password manager, cloud storage with built-in document editing, a calendar, a Bitcoin wallet, a two-factor authenticator, video conferencing, and an AI assistant. In March 2026 it packaged most of that into "Proton Workspace" — one subscription covering Mail, Calendar, Drive, Docs, Sheets, Meet, VPN, and Pass — and Proton's own marketing for it draws the comparison directly, positioning it as the privacy-respecting alternative to Google Workspace and Microsoft 365.
That's the trade in plain sight: the pitch is genuinely appealing, and for a lot of people it's a real improvement over Google. It's also, structurally, the same one-company arrangement you were trying to get away from.
There's older evidence for why the structure matters even when the company is trustworthy. In 2021, a Swiss court order compelled Proton to log the IP address and device details tied to one Mail account, as part of a French criminal investigation. The email contents stayed encrypted and were never handed over — Proton's own account of the incident is clear on that point. What the order reached was the metadata Proton did hold: who logged in, from where, and when. That's the part worth sitting with. Excellent encryption protects content. It was never going to protect a company from a legally binding request for whatever it legitimately holds — and the more services live under one login, the more "whatever it holds" can mean.
Take this as a snapshot, not a permanent verdict. Product suites change, pricing changes, companies get acquired. The point isn't Proton specifically — it's the shape of the risk, and that shape applies to any provider that grows the same way.
As you get deeper into privacy — any topic, any provider, this site included — separate the documented risk from the marketing pitch. Learn the facts. Leave the fear at the door.
You don't need a plan to move everything tonight. You need five minutes and a list.
Write down every privacy or security tool you actually use — email, VPN, password manager, cloud storage, calendar, notes, two-factor authenticator, whatever applies to you. Next to each one, write which company runs it. Then look at the list. If one company's name shows up next to more than half of it, that's the basket. You don't have to empty it today. You just have to know it's there.
That list you just wrote is exactly what a privacy stack actually is — see every category mapped out, one at a time, including the one category on it that should never be part of any bundle.