Slightly OT, but I didn't see an important question being asked: What is the motivating threat model of ProtonMail? If I just want to access my email securely, that's done by HTTPS. If I want an end-to-end encrypted solution, ProtonMail can provide that, though only for emails between ProtonMail users. For e2e outside of ProtonMail, I can use PGP. From what I understand, ProtonMail makes all the PGP stuff easier by b…
Are they encrypting incoming mail with recipient keys and throwing away the original?
Yes we do. This mainly protects against service level requests for data in the future.
Can I get similar security properties by periodically downloading my email and deleting it off the server (assuming the deletion is actually happening)?
Yup, assuming you want to deal with that. ProtonMail is designed to give you a privacy focused option for email.