You use email+password for login. Does this mean that on every login attempt, you iterate through every row in the database to check for a hash match?
To do it any more securely would require pulling up every single record for its salt, and hashing the login with that salt and checking it. It's virtually impossible at any real scale.
I suppose the goal here is privacy, not information security, so it's okay.
Shard it into multiple machines for higher QPS.