Unless I'm misunderstanding something, if someone has access to my email they can just login right?
That doesn't sound very safe. Does this use some form of OTP that's passed via a special URL that only works with the mobile app? If so that sounds better than what I'm thinking.