I think the distinction here between "handing over your data" and "letting a model train on the data on your device" may be more subtle than you might think. There is still no guarantee of privacy - it is trivial to construct objective functions which probe data from your device.