Do not put your nsec into apps. This has been a rule for 3.5 years. Always use always use a remote signing app or browser extension. Never put your nsec into apps. This hasn't changed since December 2022 whenever we had the major XSS event on the telegram clone that I can't remember it's name.