Supposedly you can set the visibility of your email to non-friends or non-network users. The problem here is that I have my FB email setting on private (friends only), and yet somehow this site can see it.
Methinks they may be simply attempting to log in with that email as your username... maybe Facebook returns a different error depending on non-existent username vs. wrong password. Very dumb of FB in that case, and must be fixed.
Facebook permitting this app to operate will give it serious legal trouble in the EU.