Why mental health apps ask for your email (and why we don't)
The email box looks like the most harmless field on a sign-up screen. In an app like this, it's the most consequential one.
Nearly every app you've ever installed has opened with the same small ritual: enter your email to continue. It's so universal that typing it in barely registers as a decision. And in most apps it barely is one — the stakes of your email being attached to a to-do list are close to zero.
A mental health app is not most apps. What you put into it, if it's working, is the least sayable stuff you're carrying. So it's worth slowing down on that harmless-looking box and asking what it's actually for — because the honest answer is more interesting than either the marketing or the paranoia.
What an email address actually is
Technically, an email address is just a way to reach you. Structurally, it's something much bigger: it is the join key of your digital life. It's the same string across your bank, your shopping, your social accounts, your CV. Data brokers organise what they know about you around it. Breach databases are searchable by it. Advertising systems use it — hashed, supposedly — to recognise you across companies.
Which means that the moment an app stores your email next to its own records, everything in those records is one join away from being about you, by name, to anyone who obtains both sides. Not because anyone intended harm. Just because that's what a shared key does: it connects.
In a recipe app, fine. In an app that holds a year of your worst Tuesdays, that single field quietly changes what the database is. Without it, the database is words. With it, it's a dossier.
The fair reasons apps ask
Let's steelman it properly, because app makers aren't villains and the email box does real work.
Account recovery is the big one. Phones get lost, dropped and upgraded, and "email us and we'll get you back in" is the recovery mechanism everyone already understands. Receipts and billing often want an address. Safety and abuse prevention is easier when accounts cost something to create. Research consent, for apps running studies, needs a contact route. And — said plainly — re-engagement: the business wants a channel to bring you back, because subscription economics reward it. That last one isn't sinister either. It's just marketing. Every "we miss you 💚" you've ever received is that line item.
These are real reasons. Our argument has never been that asking is corrupt — it's that in this one category, the price of the convenience is wrong.
What it costs in this category
Three things, in ascending order of seriousness.
First, the small indignity: mental health marketing arriving in your inbox. An inbox is not always a private place — it's open on work laptops, glanced at by family, synced to shared tablets. "Your weekly depression check-in is waiting" as a subject line is a disclosure, however gentle its font.
Second, the chilling effect. You behave differently in a room with your name on the door. When people know their words are attached to their identity, they round the truth toward respectable — and the whole value of a companion like this lives in the gap between what's respectable and what's real. We've written about why anonymity is the load-bearing feature of this category; the email field is where it's usually lost, at second zero, before the first word is typed.
Third, the structural risk. Databases leak, companies get acquired, policies get revised, and lawful demands arrive. In 2023 the US FTC settled with BetterHelp over the sharing of users' emails and health-questionnaire answers with ad platforms — the email address was precisely what made that data joinable to real people. No policy promise survives every future. The only email address that can't end up somewhere it shouldn't is the one that was never collected.
How recovery works without one
The standard objection is practical, and it's a good one: if you know nothing about me, how do I get my account back when I drop my phone in a canal?
Our answer in Nagi is a recovery code — the Nagi code. When you start, the app gives you a code that only you hold; we store nothing that links it to a person. New phone, same code, and your history is yours again. It's the same principle password managers and private messengers settled on: recovery through something you keep, rather than something they know about you.
And here is the honest cost, stated as plainly as we can: if you lose the code and your signed-in devices, nobody can get your history back — including us. There is no "click the link we emailed you," because there is no you, anywhere in our systems, to email. We think that trade is right for this category, and we'd rather you make it with open eyes: write the code down somewhere that isn't your phone. The mechanics of how your words stay unconnected to your name are laid out in this piece and, in full, in our privacy policy.
If you're using an app that does ask
None of this means you should abandon an app that's helping you. But you can narrow the join. Most email providers now offer alias or "hide my email" addresses — a per-app address that forwards to you without revealing your real one, and can be switched off. Use one for anything health-shaped. Check the app's settings for marketing toggles, and its privacy policy for an erasure promise with an actual number of days in it. And prefer apps that let you export your data — whatever else is true of them, that one respects whose record it is.
The email box will stay on most sign-up screens, because for most software it's the right call. We just think that when the software's job is to hold the things you can't say anywhere else, the kindest thing an app can know about you is nothing.
— The Nagi team
Nagi is a mental health companion, not a medical device, and nothing here is medical advice. If you're struggling, please reach out to a professional or someone you trust.