Lumo wins on brand and on heritage. Proton has built the strongest privacy brand in Europe over a decade across Mail, VPN, Drive, and Calendar, the recognition is real, the security audits are public, the operational record under hostile regulatory pressure is documented, and a buyer who lands on Lumo lands on a product made by a team whose track record on privacy engineering is in the top tier worldwide. VoltageGPU is younger, has less name recognition, and is asking the reader to extend trust to a French sole proprietorship that does not yet have Proton's decade of public proof. For a buyer for whom brand trust is the dominant factor, and that is a perfectly legitimate factor, Lumo is the right answer and we recommend trying Lumo first.
Lumo wins on price. Lumo Plus is €9.99/month, roughly $11 in USD; Personal Agent is $20/month flat. For a single individual user buying a private AI assistant out of personal budget, that is a real difference, and a free tier exists for users who want to try Lumo before paying. Personal Agent has no free tier today, the $20 covers TDX hardware time on a 32B-class model, French operator costs, the Telegram bot infrastructure, and the attestation pipeline, and there is no margin to give away free usage at this price point. If the constraint is pure personal price, Lumo wins on the spreadsheet line. We do not have a counter-argument and we are not going to invent one.
Lumo wins on ecosystem integration for users already inside Proton. If your email is on Proton Mail, your files are on Proton Drive, and your calendar is on Proton Calendar, then Lumo plugs into a workflow that already exists, the assistant can reference your Proton-stored context through the same authentication boundary that already holds your other data. Personal Agent is standalone: it lives on Telegram, it does not know about your email or your files unless you paste them into the chat, and integrating it into a Proton-native workflow requires manual copy-paste. For users whose document gravity is on Proton, that ecosystem advantage is real and we are not going to argue with it.
Lumo wins on open-source verifiability of the client. Proton publishes the Lumo client code on GitHub, the cryptographic design has been documented in public papers, and the zero-access encryption pattern has been independently audited multiple times across the Proton product line. The VoltageGPU stack is partly closed-source, the orchestration layer and the TDX deployment pipeline are not public, the attestation verification endpoint is public, and the protocol-level interaction with the TDX guest is auditable through the DCAP quote chain. For a buyer for whom open-source verifiability of every line of code is a hard requirement, Lumo wins that property and Personal Agent does not.
Where the architecture difference matters is the moment of processing. Zero-access encryption protects the stored conversation and the network transport, the ciphertext sits at rest under client-side keys, the TLS tunnel carries the request to the server under transport encryption, and the operator cannot read either. What the operator does see, by the structural nature of how an LLM works, is the cleartext prompt at the moment the model is generating the response, the prompt has to be in cleartext for the model to process it, and that decryption happens inside Proton's infrastructure. Proton's operational controls around that processing moment are strong and the design minimises the exposure window, but the cleartext moment exists. Intel TDX is the architecture that extends the cryptographic boundary into that processing moment, the prompt enters the TDX guest still encrypted at the memory layer, the model processes it inside silicon-enforced encrypted memory, and the operator running the host cannot read workload memory even with full administrative access to the hypervisor. For workloads where the threat model assumes the operator is part of the attack surface, and that is the standard threat model for client files under bar-association secrecy, for patient records under HDS, and for any data subject to a foreign sovereign's extraterritorial discovery powers, TDX is the architectural primitive that closes the processing-moment gap and zero-access encryption is not. The honest summary: if your threat model ends at "the operator could be subpoenaed for stored data", Lumo handles it. If your threat model also covers "the operator could be subpoenaed or compromised at the moment of processing", Personal Agent is the architecture that addresses it.