All email is about trust. Remember there's a fair amount of metadata in the header of each email too.
Your second point there is about perspective. It is secure from a remote adversary.
They also clearly do state (as all providers do) that they will comply with the laws within Switzerland. https://protonmail.com/blog/transparency-report/
Hosting your own email doesn't protect you from this either, as they could easily turn up to your DC provider or covertly install bugs in your house too.