Here's the dumb thing: the guy has a traceable recovery email.

Why do that if you're getting into govt stuff?? Seems dumb.

Also, are these people using VPNs?

Anyway, it's nothing any of us want to hear and I don't like that Proton doesn't have a better system in place to protect some of the peripheral data, but I'm not sure I'm ready to condemn them yet.

The emails are encrypted. But Other Things are not. You have to know how to manage your Other Things.