Seems like if ProtonMail can encrypt them automatically, then they can potentially be decrypted by someone at ProtonMail.
Reasoning:
Are emails automatically encrypted with a hash of the user password when they are received?
If the user forgets the password, how do password resets work?
Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be needed to log in with in the first place) to unencrypt the older emails, and re-encrypt with the newer password?
If they really use your password to encrypt, they can also decrypt your emails. I doubt they would advertise this as encryption... I'm not sure what they do technically, but using the password doesnt sound like a good mechanism.
Reasoning:
Are emails automatically encrypted with a hash of the user password when they are received?
If the user forgets the password, how do password resets work?
Are the emails before the password reset "lost", or does ProtonMail keep a copy of the hashed password (which I suppose would be needed to log in with in the first place) to unencrypt the older emails, and re-encrypt with the newer password?