@Like blackberriesIt's not ideal but there are options, however cumbersome they may be. Obviously this depends on how you paid for the token - if you used your real name and your own credit card then the risk only becomes apparent if you then send the same token to be reset while using a different email address; therein lies the opportunity for correlation.
CS do make an effort to not keep logs in order to avoid such correlation from happening. Having said that though, the person who purchases the token is not guaranteed to be the person who uses it. We as members can help this along by using a consistent channel of communication when dealing with token issues and keeping the emails as clean as possible - simply saying "Please reset this token" is more than enough; there's no need to refer to any thread on the forums, especially one you have started. :p
As for the mail, CS staff do use PGP so you can send them an encrypted mail from an burner address, just remember to include your public key with your email.

You could also look at using Bitmessage over Tor as an option.
