As mentioned in another comment, PHI is defined as something that originates from a healthcare provider. Some of the restrictions for what we can say the app does actually come from the FDA. We don't say that we treat specific anxiety disorders (we call it "stress and anxiety"), and we don't ask our users for that type of information. But it really is a bit of a grey area. It's something that we're acutely aware of though and are trying to follow all the guidelines we can find.
Emails are often trivially linked to identity. It doesn't matter that someone could have generated an "anonymous" email address (I've very skeptical that user-provided email addresses would pass muster as de-identified identifiers), if you can use that email to communicate with the person, it's definitely linked to their identity. If they link the email address to their identity elsewhere, the burden is still on you, not the user. You cannot demand that users protect the email address they use to sign up for your service the same way they would protect a social security or medical record number. That's ridiculous.
You should look into obtaining HIPAA/HITECH compliance training perhaps as an unaffiliated learner on https://www.citiprogram.org/ to understand why those of us that work in health care are expressing concern.