you CAN actually use the secure enclave/android keystore for this and make users sign their post using their biometrics. no biometric data ever leaves the device. still anonymous and still fully verifiable. it's the perfect use case