> "Their account" is their account on your platform.
You mean, the Apple account on my platform? How does it get there? I don't have the Apple account of a user. I just have an email address.
> "Their device" is a device that they own and that you are collecting information about.
I don't collect information about their device. But you still didn't answer the question. What is "their device"? Is it a unique device ID? A fingerprint? What is it?
> Are you linking it to _ANYTHING_ else ? Yes or no ?
I use the email to create an account on my backend. Users can backup data to their account. But nothing ties to "identity". They could fake all of it. I don't care. I send transactional emails, such as a reset password email.
> Or are you collecting an email address (or hash of an email) as part of broader set of data you are collecting from the user ?
Not PII data, just stuff they enter in the app.
> Or are you collecting an email address (or hash of an email) and then sending it off to Facebook or other API in an attempt to build a picture ?
No.
But the details of your questions show, imho, that the concept of identity is non-trivial.
I can summarize it very simply: users sign up for an account, identified by an email adress (I don't care if it's real), as a service for the user to have an online backup and an easy way to sync data between devices or move them to Android. The goal is NOT to personally identify a user. But could a user be identified by the email address alone BY SOME ENTITY? Yes, probably. Do I do it? No. Do I share the data or offload it to a third party for data processing? No. Or does my rented self-managed VPS, where the backend runs, count as third party? I don't think so. But of course, I use a transactional email service to send emails to users. What about that? I do have a GDPR-compliant data processing agreement for that. But not sure what Apple wants from me in this case.
Thing is: It's not trivial and Apple's guide is insufficient. That's all I'm saying.
Edit: And to clarify – if it's complicated, data collecting entities such as Facebook could say "well, we did understand this differently" and simply don't tell the truth about the data they're collecting. I guess that is another point in this whole discussion: What if someone lies about their data collection practices? Any consequences? Are there downsides to lying about it?