Why we never ask for your email address
An email address is a permanent cross-service identifier. Here is what refusing to collect one costs us — and why we do it anyway.
August 13, 2026 · 7 min read
TL;DR — Your email address is the key that links your accounts to each other and to your name. Collecting one would make our product easier to run and easier to sell to you. It would also create the single record most capable of identifying you — so the signup form does not have a field for it, and this article is the argument for why that trade is worth making.
There is a line at the bottom of every page on this site: we don’t know who you are, and that’s by design. It is easy to write and expensive to mean. This is the part where we show the receipt.
What an email address actually is
Not a contact detail. A permanent identifier that you have already given to your bank, your employer, your social accounts and several hundred companies that have since been breached. It changes rarely, it is unique to you, and it is the field data brokers use to join separate records into one profile.
So when a privacy product asks for an email address, it is asking for the one piece of information most capable of connecting its records to everything else about you. Collected in the name of protecting your privacy, and stored in a database that is exactly as breachable as everyone else’s.
What having it would give us
Be suspicious of a company that pretends collecting data would be useless to it. It would be extremely useful, which is the whole point of not doing it:
A join key
Any record we hold could be linked to any other, and to any external dataset with the same address in it. Every separate thing we know becomes one thing we know.
A marketing channel
Renewal reminders, win-back campaigns, upgrade nudges. Measurably effective, and a permanent claim on your attention that you would then have to withdraw.
A subpoena target
The single most identifying field in the database is also the first one named in a legal request. You cannot be compelled to produce a column that does not exist.
An asset in a sale
Companies change hands. Subscriber lists are valued in those transactions, and the privacy policy that protected you is written by whoever owns the company next.
What refusing it costs us
This is the section most companies would leave out. Not collecting an email address is not free, and the costs are real:
- No password resets There is no password, and no address to send a reset link to. Lose your 16-digit account number and we cannot recover it for you, because we have no way to establish that it was yours.
- No marketing list No newsletter, no re-engagement campaign, no way to tell existing subscribers that something they asked for shipped. We give up the cheapest acquisition channel in software.
- No churn intervention We cannot email someone whose subscription is lapsing. If the product stops being worth $2.50 a month, we find out when the payment stops.
- A harder support story Support has no account history to look up and no email thread to match you to. We answer the question in front of us, without a profile.
- No email-based abuse signals Most platforms use email reputation to catch abuse. We had to solve that with rate limits and network-level measures instead, which is more work.
We think the trade is worth it, but it is a trade, and pretending otherwise would be the kind of marketing this company exists to avoid.
What the account is instead
A random 16-digit number, generated at signup. It is not derived from anything about you. It is not tied to a device, a name or an address. You write it down or store it in a password manager, and it is the whole credential — there is nothing else to remember and nothing else to leak.
That number is what our systems know. Whether the subscription attached to it is active is what our billing knows. There is no third table. You can see the mechanics on the anonymous signup page, and the client code that implements it is open source, so the claim is checkable rather than merely stated.
Where we still had to compromise
Two places, and we would rather name them than have you find them:
Payments. If you pay by card or through an app store, that processor knows exactly who you are — that is what payment processors do. We receive a reference, not an identity, but the link exists on their side. Paying in Monero is the only path that removes it entirely, and we would rather say so than imply a card payment is anonymous.
Support. If you email us, we have your email address, because you sent it. That is your choice each time rather than a condition of using the product, which is the distinction that matters — but it is not nothing, and we delete those threads on a schedule.
It applies to the boring things too
The test of a principle is whether it survives the parts nobody would check. When we set up our free merch page — a t-shirt, a bottle, a sticker pack, shipped free anywhere in the US — the obvious move was an email field, for shipping confirmations and a list at the end of it. Every giveaway does this.
That form asks for a name and a street address, because a courier cannot deliver to a promise, and nothing else. No email, no account number, no payment step. It made the fulfilment harder and the marketing value lower, and it was not really a decision at all: the sentence at the bottom of the page either holds everywhere or it is advertising.
An account that is just a number
No email, no password, no name. Sixteen digits, and a subscription attached to them. That is the entire record.
Get LunoVPN See pricing