Use Z on your phone and your desktop at the same time, on one identity, with no server-side account to make it work.
Each device has its own keys and its own session with each of your contacts' devices — there is no shared key copied around, and the relay learns nothing about which mailboxes belong to the same person. Messages you send and receive are mirrored to your own devices over those same encrypted sessions.
The safety number is anchored to your account rather than to whichever device is in your hand, so linking a laptop does not make you look like a different person, and a genuine key substitution still stands out.
Remove a lost or retired device and your app publishes a new signed device list. Your contacts stop sending to it as soon as they receive that, and their apps flag a device that tries to speak for you afterwards. Removals are distributed so that a device cannot suppress the notice of its own removal.