• Latest
  • Trending
  • All
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Monday, September 21, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

Proton Lumo 2.0 review: how private is it, really?

by stephane
3 September 2026
in Security
0
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.
524
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Proton shipped Lumo 2.0 on June 30, and the headline writes itself: a private ChatGPT alternative, built in Europe, that got a lot smarter overnight. The interesting question is the one the launch posts skip. Private how, exactly? The honest answer has two halves. Your saved chats are genuinely locked, encrypted so that not even Proton can read them. But the prompt you send is decrypted in the clear on Proton's servers to answer it, then forgotten. So Lumo is far more private than a mainstream chatbot, and not the same thing as running a model on your own machine. Here’s what 2.0 actually changed, what its privacy protects, what it doesn’t, and who should switch.

The short answer

Lumo 2.0 is the update that makes Proton’s private assistant genuinely usable: image generation, reasoning modes, sourced web search, memory, and a big capability jump. Its privacy is real but specific. Your saved history is locked so even Proton can’t read it, while your prompt is decrypted on a Proton EU server to answer it, then forgotten. More private than a mainstream chatbot, not the same as running a model yourself.

index 51Lumo 2.0 Max (was 15)
EU + Swissservers and law
$0free tier to try
Answer card: Proton Lumo 2.0 is private by policy, not by locality; saved history is locked from Proton, but the prompt is decrypted on a Proton EU server to answer it.
The honest one-liner: more private than a mainstream chatbot, not as private as local.

What Lumo 2.0 actually changed

Proton’s first Lumo was easy to file under “nice idea, come back later.” Private, yes, but limited enough that you kept a mainstream chatbot tab open anyway. Lumo 2.0, out June 30, is the version that closes that tab for a lot of tasks. It went multimodal: it generates images from a prompt, edits them, reads charts and documents you upload, and turns a rough sketch into a finished picture, all in one conversation. It picked up two reasoning modes, Fast for quick answers and Thinking for multi-step problems. Web search now returns live results with source citations, so it can pull current news, financial data and weather instead of guessing. And it gained memory: Projects are encrypted workspaces that hold your chats, files and instructions together and recall your preferences across sessions.

The capability numbers back the vibe shift. On the Artificial Analysis Intelligence Index, Lumo 2.0 Lite scores 34 against the old 1.4’s 15, and the flagship Lumo 2.0 Max hits 51. That’s a 240 percent jump on the top tier, and everyday answers come back up to 76 percent faster. This isn’t a point release. It’s the release where a privacy-first assistant became one you’d actually reach for.

Bar chart of the Artificial Analysis Intelligence Index: Lumo 1.4 scores 15, Lumo 2.0 Lite 34, Lumo 2.0 Max 51.
A real generation jump. Frontier flagships still score higher, so read it as capable, not smartest.

The privacy, honestly: what zero-access encryption covers

Here’s where Proton’s marketing and a security engineer’s reading start to diverge, and it’s worth getting right. Lumo’s privacy has two separate layers, and they’re not equally absolute.

Your stored history is genuinely locked. Saved chats, uploaded files and generated images use zero-access encryption, the same design as Proton Mail and Drive: the data is encrypted so that only your device, unlocked by your account password, can read it. Proton can’t. An independent teardown of the traffic confirmed the encrypted flags and the two-way protection, so this part holds up. Not even Proton can open your saved conversations.

The prompt in flight is a different story. To actually answer you, Proton’s GPU server has to decrypt your message in the clear, feed it to the model, and generate a reply. There’s no trick that lets a model reason over text it can’t read. Proton’s own security model says the plaintext lives only in memory during the request and is “forgotten as soon as the response is generated,” with no logs kept. That’s a real and meaningful promise. It’s also a promise, backed by Swiss law and a no-logs policy, rather than a mathematical guarantee. Proton calls this “user-to-Lumo encryption” precisely because it’s not classic end-to-end: the AI decrypts your message, not a human, but decrypt it does.

Diagram: while answering, your prompt is decrypted on Proton's EU GPU server with no logs; at rest, saved chats, files and images use zero-access encryption only your device can open.
Two layers, not equally absolute: your history is locked from Proton, your live prompt isn’t.

Private by policy, not by locality

So the honest framing is a spectrum, not a yes or no. At one end, a mainstream chatbot: convenient, and your prompts sit on a big AI provider’s servers under terms that often include training. At the other end, a model running on your own machine, where the prompt never leaves your device, which is the strongest privacy there’s and the reason we wrote up running Qwen locally and offline. Lumo sits in a real and useful middle. Your prompt does leave your device, but it goes to open-weight models on Proton’s own European hardware, under Swiss privacy law, with no logs and no training on your data, and your history comes back locked so even Proton can’t mine it later.

For most people that middle is exactly right. You get far more capability than a laptop can run, and far more privacy than pasting the same text into a mainstream chatbot. You just have to be clear-eyed that “private” here means “processed by a company that has staked its whole brand on not looking,” not “never decrypted anywhere.”

The capability reality

Don’t let the privacy story oversell the brains. Lumo 2.0 Max at 51 on the intelligence index is a capable generalist: it drafts, summarizes, explains code, reads a document, makes a serviceable image. It’s not a frontier model. The flagships from the big labs still score higher and pull further ahead the harder the reasoning or the coding gets, which is the tradeoff you accept for keeping the whole thing in Europe on open weights. Match the task to the tool. Everyday private work, Lumo. A gnarly multi-file refactor or research-grade reasoning is still frontier territory, and our model comparisons cover that shelf.

Who should switch, and who shouldn’t

Switch if you’ve data you’d never paste into a mainstream chatbot: client material, health or legal questions, unreleased work, anything covered by a regulation with teeth. For that person, Lumo 2.0 is finally good enough to be a daily driver rather than a principled compromise, and the free tier is a genuine trial, capped on chats, uploads and images but fully functional. Lumo Plus runs about $12.99 a month, or nearer $9.99 billed annually, and lifts the caps while unlocking the most capable models; a Lumo Professional tier targets teams. One fair gripe from the community: Proton Unlimited subscribers expected Lumo to be bundled in and found Plus behind a separate paywall, which stings if you already pay for the suite.

Don’t switch expecting frontier intelligence, and don’t mistake it for local privacy. If your threat model says the prompt must never touch someone else’s server, the answer is a local model, not Lumo. For everyone between “I don’t care” and “nothing leaves this laptop,” Proton just made the most compelling case yet for the private middle.

Sources: Proton’s Lumo 2.0 announcement and Lumo security model documentation; feature and pricing coverage from TechCrunch and MacRumors; and an independent analysis of Lumo’s zero-access encryption by Race Dorsey. Intelligence Index figures are Proton’s own, June 30 2026.

Frequently asked questions

Is Proton Lumo actually private?

More than a mainstream chatbot, with an honest caveat. Your saved chats, files and images use zero-access encryption, so only you can decrypt them and Proton can’t read them. But to answer you, Proton's server decrypts your prompt in the clear, runs the model, and keeps no logs of it. So it’s private by policy, Swiss law and encryption, not private in the sense of never being decrypted anywhere.

Does Proton Lumo train on my conversations?

No. Proton states it doesn’t use your prompts or chats to train the models, and it runs open-weight models on its own European servers rather than sending your data to a third-party AI provider.

Is Lumo 2.0 as smart as ChatGPT or Claude?

Not at the top end. Lumo 2.0 Max scores 51 on the Artificial Analysis Intelligence Index, a big jump from Lumo 1.4's 15, which makes it a genuinely useful assistant. Frontier flagship models still score higher, so use Lumo for private everyday work, not for the hardest reasoning or coding.

How much does Proton Lumo cost?

There’s a free tier with caps on chats, uploads and images. Lumo Plus is about $12.99 a month, or nearer $9.99 a month billed annually, and removes the limits and unlocks the most capable models. A Lumo Professional tier targets teams.

Is Lumo more private than running a local AI model?

No. A model running on your own machine never sends the prompt anywhere, which is the strongest privacy there is. Lumo processes prompts on Proton's servers, so it’s a trusted-server model. If you want nothing to leave your device, run a local model; if you want more capability than a laptop can give while still avoiding the big AI providers, Lumo is the middle ground.

Tags: aiarticlellmprivacyprotonsecurity
Share210Tweet131
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.