Really? nostr:note1qj7z5xvy6gjh684st7wun76hqvxn62nn9zn5p0336vsuruhzxyeq5ruqum
Every mail provider can scan incoming unencrypted mail while in-traffic Protonmail is one if the few providers that encrypts it at rest. Email is shitty but it does not get better than that. No, they don't keep private keys. You can generate one yourself and import it with a FOSS client.
Depends on configuration. Email is insecure anyway because 90% people use gmail or similar ha. Here is a god write up https://freedom.press/training/protonmail-pro/