If your sign-in flow stores sha256(lower(email)) and you call that "anonymised", it isn't. A hashed email is a stable, cross-site identifier: every service that hashes the same address gets the same string, and ad-tech "clean rooms" are built on exactly that join.
I'm building ClientN, so I've spent a lot of time on this question. Here is the short version for developers.
Why hashing doesn't help
-
Same input, same output.
alice@example.comhashes to the same value on your site, on a retailer's site and in a data broker's table. Matching is a plainJOIN. - The input space is small. Emails are guessable. Anyone with a list of addresses can hash them and look yours up — no "reversing" needed.
- Salting per site breaks the join, but you still hold the email. You collected it, so it can leak, be subpoenaed or be shared later.
What actually limits linkability: pairwise identifiers
Give each relying site a different identifier for the same person, derived so that sites cannot correlate them. In ClientN, a user signs in with a passkey (WebAuthn) and each integrated site receives its own anonymous CN- id. Site A's id for a user tells Site B nothing.
What the site gets:
- a stable id for that site only — enough for accounts, sessions, rate limits and bans on your own service;
- no email and no password to store, so nothing reusable to leak.
Where it fits (and where it doesn't)
- It only applies on sites that integrate it — it is not a fix for "all internet privacy".
- You still need your own abuse controls; a per-site id gives you a key to apply them to without collecting identity.
Try it
- Live demo: https://clientn.com/demo
- Node + PHP starter (MIT): https://github.com/clientn/clientn-session-starter
- Docs: https://clientn.com/docs · developer dashboard: https://clientn.com/dev
Websites are free up to 1,000 logins/month until 2027-03-31. People get a free account (email + passkey) at https://clientn.com/signup.
Verified Human. Still Anonymous. — Longer write-up on our blog: https://clientn.com/blog/hashed-emails-arent-anonymous-how-your-login-becomes-an-ad-id
Top comments (1)
solid explainer. honest question on pairwise ids: the email has to live somewhere for account recovery, so who holds it? if the identity provider keeps it, correlation didn't disappear, it moved.