Glad to hear your concern!
I have a few things to clarify though. First of all I don't want your Patreon credentials, only the email. You need to enter an email which you used on patreon, but if you didn't know, that is public info and anyone can see it, as long as they request the whole campaign info on the Patreon API, which can be done quite easily by anyone. For the password it can be something completely different and I cannot even gather that info as it is processed by Google's Firebase system.
It is a fair concern and I see your point, but that is just how it works. I am putting the Patreon email restriction as a sort of protection against someone spamming bot accounts and overflowing the database.
So, yeah. Your patreon email is public and the password is managed through google, AND IS NOT NEEDED TO BE THE SAME AS THE PATREON ONE, with nothing going through me.
I know that just me saying this won't remove your concern, but I hope this gives some clarity on how things work. I can show source code if that still doesn't sound believable.