A phone number or secondary email should be an option for account recovery, not the default price of admission. Every added identifier creates another relationship a service can retain, correlate, or expose during a recovery attempt.
There is a reasonable local-only alternative: a printed recovery code, an encrypted file, or a hardware-backed backup key kept offline. NIST explicitly recognizes saved recovery codes, including printed copies, and hardware authenticators fit the backup model recommended for passkeys. These options are less convenient, and losing or exposing the bundle can mean permanent lockout or account takeover. Recovery also needs rate limits, single-use credentials, and notifications because scams are real.
My concern is that centralized recovery gets treated as mere convenience when it is also a privacy decision. Would you trust a carefully managed local recovery bundle, or would you rather have a verified human fallback?