Learning with User-Level Local Differential Privacy