It would be difficult, but AI has suddenly made difficult things a lot easier.
With PassKeys and push notifications, there’s no way to do that.
It's unfortunate that passkeys have been such a disaster. Attestation should never have been part of the spec, it should never have been presented as a replacement for hardware U2F keys, and a private key file format should have been defined on day 1. But there is useful functionality buried under all the noise and confusion.
I suspect that many people's Passwords apps are littered with dead passkeys.
And that's another thing: if you use a 3rd party e-mail service then you have to trust a 3rd party not to abuse that. If they have control of that email address they can take over your account. If it's a temporary address, who's to say when that address gets reused?
If you don't use a 3rd party service then you have to have your own domain for that e-mail address, that domain name can then also be traced back to you.
If you want it to be anonymous, you shouldn't use e-mail at all and only allow passkeys.
The issue is that the demographic we Serve (recovering drug addicts) is a very privacy-sensitive one. Another demographic (that we don't serve) is non-hetero/cisgen folks. Both of these demographics can mean persecution, and even death, in some places, so we are not casual at all about the privacy of our end-users.
At the same time, too much security can render the app useless, so we need to find a balance. The issue with information, is that once it's out; it's not so easy to put back in the bottle, so we tread carefully.
The PassKey is a bit better, because there’s no need to go through a broker server, like you do with push notifications, but the key is still connected with an individual user and device, so an association can still be established, with some difficulty.
If you don’t have the key or the ID stored on a server, then even that is not an issue.