What happens when you install Proton VPN and press Connect?
You need a Proton Account before the app will do anything, and that means an email address. Proton does not offer anonymous signup, and our dataset records that next to the transparency score rather than leaving it implied. The account is the one identifier the provider holds regardless of what the tunnel does.
After signing in, Quick Connect picks a server by load and proximity and brings the tunnel up. Choosing a country from the list is for when you need a specific exit — a bank that expects you at home, a service that sells in one market only. Without such a requirement the automatic choice is the faster one, because it picks against live server load rather than your guess.
The protocol defaults to WireGuard, with OpenVPN and IKEv2 also shipped and Stealth available as the obfuscated mode for networks that block VPN traffic by signature. Stealth is what you reach for when the tunnel connects at home and refuses on a hotel or campus network. It is not a setting to leave on permanently, because obfuscation costs throughput.
Two things are worth doing on day one and almost nobody does them. Turn on the kill switch — Proton ships one on every platform, and the desktop apps offer a permanent mode that blocks traffic before the app has started, which covers the gap between boot and connect. Then verify the tunnel rather than trusting the green tick: address changed, DNS going to Proton’s resolver rather than your ISP’s, no IPv6 showing. Our guide on testing a VPN covers all four checks in order.
The paid plans cover ten devices on one account, and the clients are open source on every platform — the difference between a claim you take on trust and behaviour anyone can read.
How do you use Proton VPN for free, and what does the free plan hold back?
The same app, the same signup, and no card. Choose the free plan and you get a working VPN with no data cap — the unusual part. Nearly every other free tier meters you at 500MB or 10GB a month, and the ones that do not are generally funded by selling something about you. Proton’s free plan is paid for by its subscribers and runs on the same infrastructure covered by the same audits as the paid plans. That is why it is the only free tier this site lists; the free-VPN shortlist sets out that reasoning in full.
What the free plan holds back is choice and features, not volume. Server selection is limited to a small set of countries; we deliberately do not publish which ones, because the list changes and a stale list is worse than none. You get one device rather than ten. Speeds sit behind paying subscribers at busy times, which on a loaded server is noticeable. Secure Core, NetShield, P2P servers and port forwarding are all absent.
It is a real product rather than a trial, and it is also the honest way to test the client before paying — which matters here more than elsewhere, because Proton’s refunds are prorated against usage rather than returned in full. The 30-day window is real, but you are refunded what you have not used, not what you paid. Trying the free plan first avoids finding that out afterwards.
- No data cap — the free plan is metered by server access, not by gigabytes
- One device, against ten on the paid plans
- A restricted country list that changes, so check it in the app rather than in any article
- No Secure Core, no NetShield, no P2P servers, no port forwarding
- Same audited infrastructure as the paid plans, funded by subscribers rather than advertising
Can you download torrents with free Proton VPN?
Not properly, and the reason is structural rather than a policy you can talk your way around. Proton marks specific servers as P2P-enabled and carries peer-to-peer traffic only on those. The free plan does not include them. Point a torrent client at a free Proton server and it is on a server not carrying that traffic — which shows up as trackers that never respond and transfers stuck at zero, not as an error explaining itself.
The second half of the answer is the one that actually decides it. Port forwarding is a paid feature. Without an inbound port your client is passive: it can only reach peers that accept incoming connections, and every peer sitting behind their own NAT is invisible to you. On a heavily seeded torrent you may not notice. On anything sparse, passive is the difference between slow and nothing at all.
So the honest version of "how to download torrents with free Proton VPN" is: you can run the client through the tunnel, on a server not intended for it, passively, and it will perform badly. That is not a reason to reach for a different free VPN — a free service with no audit and no disclosed funding is the wrong place to put traffic you care about. It is a reason to either pay for the plan that includes P2P servers and port forwarding, or to treat the free plan as a browsing tool rather than a transfer one.
If you do move to a paid plan for this, bind the client to the tunnel adapter first. Interface binding stops the torrent client sending on any adapter other than the VPN, so a dropped tunnel stalls the transfer instead of leaking it — more reliable than a kill switch, because nothing has to detect the failure for it to work. Our qBittorrent binding guide covers the setting and how to verify it.
Avoid
- Assuming a P2P-capable client makes any server a P2P server — Proton routes that traffic only on the servers marked for it
- Reading zero-speed transfers as a broken client when the server simply is not carrying peer-to-peer traffic
- Switching to an unaudited free VPN to get around the restriction, which trades a performance problem for a trust problem
How do you turn on port forwarding, and why is there no port to type in?
Port forwarding is included on Proton’s paid plans at no extra cost, which is unusual — of the four providers we cover, PureVPN and FastestVPN both sell it as an add-on, and NordVPN does not offer it at all. What confuses people is not the price but the mechanism.
Proton hands the forwarded port out over NAT-PMP on a short lease that has to be renewed. There is no port number sitting in a dashboard for you to copy, and there is nothing to type into your torrent client. The client asks for a mapping, receives one, and renews it for as long as the session lasts. The port you get is not the port you had yesterday.
Which means the standard advice is backwards here, and we published the backwards version ourselves. Until August 2026 our qBittorrent guide told readers to turn UPnP/NAT-PMP off when using a forwarded port — correct for a provider that gives you a fixed port, and precisely wrong for Proton, where turning NAT-PMP off breaks the exact feature the page was recommending. That correction is logged with the others. Enable port forwarding in the Proton app, leave NAT-PMP enabled in the torrent client, and let the two negotiate.
Where the toggle appears has moved between client versions and platforms, so check the current app rather than a screenshot in any guide, this one included. The mechanism is stable; the menu is not.
- Paid plans only — the free plan has no port forwarding at all
- Enable it in the Proton VPN app, on a P2P-marked server
- Leave UPnP/NAT-PMP switched ON in the torrent client so it can request the mapping
- Do not type a port number anywhere — there is none to type, and a hardcoded one will be wrong
- Expect the port to change between sessions; anything you configured against the old one will need re-checking
Does Proton VPN keep logs?
The evidence says no, and the reason to believe it is the repetition rather than any single report. Proton VPN has published five consecutive annual no-logs audits by Securitum, covering 2022 through 2026, with every full report published rather than summarised into a blog post.
The most recent has specifics worth quoting, because specifics are what separate an audit from a press release. Fieldwork ran 20–27 May 2026, on site at Proton AG in Zürich, with two senior consultants over six person-days, examining the no-logs policy against production infrastructure. The finding: no evidence that the examined infrastructure logs browsing activity, DNS queries, destination services, traffic contents or user-identifiable connection metadata, and no persistent records that would let Proton associate a user with activity on a reviewed server.
What that establishes is narrower than "Proton keeps no logs about you", and the gap is worth stating. An audit examines the infrastructure it was shown, at the time it was shown. It is a snapshot. Five snapshots in five years constrains a company in a way one snapshot never does, because the provider has to keep passing rather than tidy up once — which is why a single old report carries much less. FastestVPN has exactly one, from January 2023, never repeated.
Audits are not theatre, and the proof of that sits on another provider’s record: PureVPN’s 2023 KPMG engagement found origin IP addresses in the error logs of failed connections for users on manual configurations. Nobody would have known without an auditor with the access to look. When a firm with that access examines Proton’s production systems five years running and reports nothing equivalent, the absence means something.
What Proton necessarily does hold is your account: the signup email and whatever payment record your subscription generated. No audit removes that, because the service cannot function without it. If breaking the payment link matters, Proton accepts cash by post in CHF, USD or EUR — non-refundable, which is the trade. Jurisdiction helps as well: Switzerland sits outside the Fourteen Eyes agreement, and Proton AG is majority-held by the non-profit Proton Foundation.
How many California servers does Proton VPN have?
We do not publish that number, and you should distrust anyone who does. Per-city server counts change week to week as capacity is added and moved, so a figure in an article is stale by the time it ranks — and unlike a country count, nobody is publishing an authoritative live total per US state.
What we do record is that Proton states 148 countries across 191 locations, with the caveat Proton itself gives: industry country counts include virtual locations, so they cannot be compared between providers. A virtual location is an address registered to one country running on hardware somewhere else — fine for appearing in a place, but not a measure of physical footprint. Our own review said 110 countries until August 2026, when the provider’s figure turned out to be 148 and we corrected it. Counts go stale quietly.
The useful version of the question is not how many California servers exist but whether the one you are on is any good, and the app answers that live. Open the server list, expand United States, and you get city rows — Los Angeles, San Jose and the rest — each with a load percentage against it. Load and latency decide what your connection feels like; the total decides nothing. The same list carries the P2P, Secure Core and Tor labels, which is how you find the servers carrying peer-to-peer traffic rather than guessing. On the free plan you see a subset of it, so the number that matters to you depends on what you are paying.
Which Proton VPN features are not where you expect them?
Split tunnelling — routing some apps through the tunnel and letting others go direct — exists on Windows, Linux, Android and Android TV. It is experimental on macOS and absent on iOS. If your plan was to run a banking app outside the tunnel on an iPhone while everything else went through it, that plan does not exist on that platform, and no setting hunt will find it.
A dedicated IP is not a consumer option. Dedicated and static IPs are Proton VPN Professional and Workspace business products. We listed one as available on the review page until August 2026 and corrected it, because a feature table tick with no plan attached is exactly how people end up paying for the wrong thing.
NetShield is not antivirus, and the numbers matter before you rely on it. AV-TEST measured it over September–October 2024 against 3,209 malicious samples: 4.43% of malicious URLs blocked, against NordVPN’s 83.42%. Two disclosures belong with that. The test was commissioned by NordSec, NordVPN’s parent — the winner paid for the scoreboard. And NetShield blocks ads, trackers and known-malicious domains rather than catching executables, so it was measured against a job it is not built to do. That is a scope difference, not a defect; it is still a reason to run real malware protection separately.
Secure Core routes your traffic through a second hop in Switzerland, Iceland or Sweden before it exits. It is genuine protection against a compromised exit server, and it costs a significant amount of throughput. Turn it on when the threat justifies the speed, not by default.
One last thing about the price. Our dataset records $9.99 monthly and $4.49 a month on the two-year plan, and flags both as unverified: Proton renders pricing from client-side script, so we could not read the figures back from the page as we do for the other three. Check at checkout rather than trusting ours.
What using Proton VPN does not do for you
It does not make you anonymous. Your account email exists, the tunnel does nothing about it, and everything you log in to knows who you are regardless of which country the connection appears to come from. A VPN moves the network-layer observer; it does not remove the identity you hand over voluntarily.
It does not guarantee any particular streaming service will work. Blocking status changes weekly on both sides, and this site does not claim a named provider works with a named service — a promise made today is a liability next month.
It does not turn the free plan into a torrenting product. No P2P servers, no port forwarding, and no amount of client configuration substitutes for either.
And an audit is a statement about Proton, not about your machine. Five clean Securitum reports say nothing about malware on your laptop, tracking cookies in your browser, or the app on your phone reading GPS. What a well-audited VPN buys you is narrower and still worth having: a provider repeatedly checked on the one thing you cannot verify yourself, which is what it does with the traffic you hand it.