Privacy is another obvious challenge ... Google suggests that on-device processing and face authentication could help address those concerns
So create the misconception the data remains local (as the processing happens locally), while incentivizing them to using face authentication (enabling the 8-second selfie cam video clip upon unlock: used for heart rate estimation through skin changes), and the EULA roofying of course serving as the "explicit consent".