

you ask the user for it if they want to recover the account and hash it. if the hash matches your previously stored hash then you send the email
other providers that position themselves as secure for activists or journalists do exactly that and they cannot handle that information
I’m convinced that is a generated metric that is far away from reality. the objective is too make their product seem better than it is