That said, we treat our data as if it were PHI. We have a Business Associates Agreement signed with AWS, and take all of the precautions they require for an app that would claim it is HIPAA compliant. Technically, we could claim that we are HIPAA compliant, as we don't store PHI. But we didn't want to say that just for the sake of saying that.
The bigger question, in my mind, is about whether or not a situation would arise as you mention. The FDA recently provided a little more clarity on some of this (http://mobihealthnews.com/39775/fda-clarifies-the-line-betwe...). Specifically, Pacifica seems to fall outside regulation as it "Claims to promote relaxation or manage stress when there is no reference to anxiety disorders or other reference to a disease or condition." We try to be pretty careful about the language that we use. We don't mention things like Generalized Anxiety Disorder, Panic Disorder, OCD, etc.
The truth is that it still seems like a grey area. That same article mentions that we should not claim that we treat anxiety if we want to stay unregulated. I think that we're on the fence here. In the future, we will go after FDA clearance in any case. We just need the means to do so.