That’s just not true. At very least, BLF processes email addresses during registration. If my contact information doesn’t fit your definition of sensitive, what more do you want?

It’s not good practice, but I’m sure enough users also use a generic password for this site as well - that could definitely be considered ‘sensitive’, depending on what else it’s used for.