ChatGPT vs Proton Lumo: Capability or Zero-Access
ChatGPT trains on your chats by default and stores them readable. Lumo runs its own models and encrypts saved history the operator can't unlock.
Published October 2, 2026· Updated October 2, 2026· By Juan Martinez

Both products are AI chat assistants, and the gap between them (5.4 against 7.5) comes down to one thing: what the operator can read. ChatGPT runs the widest feature set in the category and stores your conversations in a form its own staff can decrypt; Lumo runs a narrow three-model lineup and stores saved history under zero-access encryption, where it cannot. Neither side comes out of this clean — ChatGPT trains on consumer chats by default, and Lumo’s “open source” positioning covers its apps but not its own models. This comparison sticks to what each product’s architecture and policies actually do, not which one writes better answers.
| ChatGPT | Lumo | |
|---|---|---|
| Rating | 5.4 | 7.5 |
| Account Required | required | optional |
| IP Anonymization | unknown | unknown |
| Storage Model | server-encrypted | zero-access-encrypted |
| Jurisdiction | United States | Switzerland |
| Free Tier | limited | limited |
| Platforms | Windows, macOS, Android, iOS | Android, iOS |
| Est. | 2022 | 2025 |
Account and architecture: guest mode versus a mandatory account
ChatGPT requires an account before the first message. There is no anonymous mode, no trial window, nothing you can type into without an identity attached — every conversation is tied to a registered user from the start, under OpenAI OpCo LLC in the United States (OpenAI Ireland Ltd for EEA, UK and Switzerland users).
Lumo makes the account optional. Its guest mode lets you use the assistant with no registration at all, and the conversation is erased when the session ends rather than stored anywhere. With an account, history is saved only if you explicitly choose to save it, and Proton AG sits in Switzerland.
Both products run their models on their own infrastructure rather than forwarding prompts to a third-party model provider, so neither depends on an IP-stripping proxy step — that mechanism simply doesn’t apply here. The difference is what happens to the text once it arrives. ChatGPT’s storage is server-encrypted: encrypted at rest, but with keys the operator holds, which means staff access is a policy boundary rather than a cryptographic one. Lumo wraps each Conversation Key under a Master Key, which is in turn wrapped by the user’s PGP keypair and unlocked by the account password — a zero-access encryption scheme where the operator cannot decrypt saved conversations even if asked to. Lumo’s documentation also claims it stores no metadata (timestamps, IP, chat context); that claim has not been independently verified.
Storage and training: who can read what you type
ChatGPT trains on consumer conversations by default. The opt-out is real and reachable — Settings, then Data controls — but it is an opt-out, which means the default state for every new free or paid consumer account is “included.” There is also a snag that survives the opt-out: using the thumbs-up or thumbs-down feedback button can send the whole conversation into training anyway. Business, Enterprise and Edu tiers are not trained on by default, so the protective default exists — it just isn’t the one ordinary users get.
Lumo’s stated policy is not to train on chats, with one narrow exception that is opt-in rather than default: pressing a feedback button may share an anonymized prompt/response pair with ETH Zurich and EPFL to improve the Apertus 1.5 model. Same button, opposite polarity — on ChatGPT it can override your opt-out, on Lumo it is the only path in.
The honest limit on both sides is verification. ChatGPT has a SOC 2 Type 2 report plus ISO 27001, 27017, 27018 and 27701 certifications, but the SOC 2 is not published — it is available on request through a sales-mediated trust portal. Lumo has no security audit at all; on Proton’s own open-source page every other product links a published audit report, and Lumo links only GitHub repositories. So ChatGPT’s deepest privacy claims are covered by a report you cannot read, and Lumo’s are covered by no report whatsoever. The architectures differ in what they make possible; the assurance layer is thin on both.
The openness claim: what’s actually open on each side
ChatGPT is closed source and does not pretend otherwise. No client code, no weights, no training data. That is a real limitation, and it is also a consistent position.
Lumo is the more complicated case. Its client code — web, iOS, Android — is genuinely published, with a populated source tree you can read. The models are not: weights, training data and architecture for the in-house Lumo 2.0 Lite and Lumo 2.0 Max are unpublished. The independent European Open Source AI Index, in an analysis by Mark Dingemanse updated 1 September 2025 that quotes Proton’s own official response, called Lumo the least open “open” AI assistant it had indexed. Proton’s own comparison material does not draw the client/model distinction, marking the product as opening its source code to the public without saying which source code. The one component that is open in the fuller sense is Apertus 1.5, built by ETH Zurich, EPFL and CSCS — a third-party model, not evidence of Proton’s own openness.
Neither product earns the win here. ChatGPT is accurate about being closed. Lumo gives you something real that ChatGPT doesn’t — auditable client code — while describing it in terms that overstate what is open.
Features: ChatGPT’s bench is wider by a lot
This is where ChatGPT wins outright, 8.7 against 6.8, and the margin is not close.
ChatGPT offers several model generations side by side — GPT-5.6 Luna, GPT-5.6 Sol, GPT-6 Astra, GPT-6 Sol, GPT-6.1 Sol, with the lineup changing often — plus web search, file upload, image generation, voice, deep research, Projects, scheduled tasks, custom GPTs, a coding agent in Codex, and integrations with Excel, Word, PowerPoint and Google Sheets.
Lumo offers three models: Lumo 2.0 Lite, Lumo 2.0 Max and Apertus 1.5, two of which come from the same family, switchable in-chat, with Fast and Thinking reasoning modes. Web search is available but optional and off-switchable, and when enabled it sends only a simplified query to the partner search API rather than the full prompt. File upload handles up to 200 files per project and documents up to 4,000 pages, though via chunked retrieval rather than full context.
Lumo’s narrow model range is a genuine product limitation, not a privacy trade-off that happens to look like one. If the work needs image generation, voice, a coding agent or office-suite integration, Lumo does not have it.
Price and platforms
The paid tiers land in the same ballpark and buy different things. ChatGPT Plus is $20/mo, with a $6/mo Go tier that OpenAI’s own page says may include ads, and Pro from $100/mo across three usage tiers. Lumo AI Plus is $9.99/mo billed yearly ($119.88, a 23% discount) or $12.99/mo without the annual commitment, with a 30-day money-back guarantee. The two products are priced within the same order of magnitude; the rating gap between them tracks architecture and transparency, not cost.
Both free tiers are usable rather than demos, but they fail in opposite directions. ChatGPT’s free tier gives unlimited text chats on the base model with uploads, image generation, voice, deep research, memory and Codex all capped — and free users get the worst privacy defaults. Lumo’s free tier includes every model, Max included, but publishes no numeric limits on messages, history or image generation, so you find the ceiling by hitting it.
Platform coverage favors ChatGPT: Windows, macOS, Android, iOS, a Chrome extension and web, with no Linux client, and two similarly named desktop apps (ChatGPT and ChatGPT Classic) shipping in parallel. Lumo is narrower — native Android and iOS plus a web client, no desktop app at all. Lumo’s own friction is that the parts worth having, saved history and Projects, require the account that guest mode lets you skip.
What we didn’t compare, and why
ChatGPT’s Business, Enterprise and Edu tiers are out of scope. They operate under a different data policy — no training by default — and comparing them to a consumer subscription would compare two different products. Both reviews, and this comparison, cover the consumer tiers.
Answer quality is also out of scope. Neither review scores how well either assistant reasons, writes or codes, so nothing here should be read as a claim that one gives better answers. The comparison is about account requirements, storage architecture, training policy, verifiability, feature breadth and price.
Bottom line
If the work depends on breadth — multiple model generations, voice, image generation, a coding agent, office-suite integration — ChatGPT is the product that has it, and the price of that breadth is a mandatory account, operator-readable storage and training that is on until you turn it off. Turn it off on day one, and treat the feedback buttons as something that can undo that choice.
If what you type matters more than what the assistant can do with it, Lumo is the better-architected option: guest mode with no account and no retained session, zero-access encryption on saved history, Swiss jurisdiction, no breach history, and training only through a button you have to press. Accept in exchange a three-model lineup, no desktop app, no published audit, and an openness claim that holds for the apps but not for the models — read it as “the client is open,” because that is the part that is.