Protonmail is cop friendly. Any reasonable privacy aware email provider would hash the secondary email, not store it as cleartext. I implemented secondary email hashing for Riseup to prevent exactly this thing, over a decade ago.
https://restoreprivacy.com/protonmail-discloses-user-data-leading-to-arrest-in-spain/