Why is this the case? I don't understand, can somebody explain the logic to me here?
Maybe used the email address as a primary key. Ask me how I know.
Well it does eliminate a whole list of problems related to account takeover, account recovery workflows, legal questions regarding which email owns the data, etc. Sometimes less is more. Secure, reliable, simple.